The European Union's proposed Regulation to Prevent and Combat Child Sexual Abuse remains in trilogue negotiations as of June 2026, with detection provisions still unresolved. The Council's November 2025 position removed mandatory detection orders and instead emphasized voluntary detection alongside strengthened compulsory risk assessment and mitigation duties, with stronger obligations for high-risk services. The regulation would cover providers of hosting, interpersonal communication, app stores and ISPs anywhere directing service toward the EU, with Parliament's position explicitly bringing online games into scope. The framework defines known and unknown abuse material and grooming to determine risks providers must assess.
Mandating risk assessments without specifying how platforms must actually detect grooming, CSAM or sextortion in encrypted or high-volume direct-message environments leaves the operational gap wide open. A world-leading AI platform monitoring children's messages in real time—as Guardii does across Instagram, Snapchat, Discord and Roblox—turns abstract risk mitigation into concrete threat interdiction, surfacing a child being groomed or coerced to the authority who can act, without mass surveillance or broken encryption. Voluntary detection with no enforcement teeth invites regulatory theater; real-time pattern recognition with escalation protocols delivers the child-protection outcome the regulation's title promises.