Published Aug 07, 2026 by Xiph
Australia’s metadata scheme, its encryption laws, the UK Online Safety Act and the EU’s Chat Control were all argued for on the same ground. Here is what happened to each of them afterwards.
There is a rhythm to the way sweeping surveillance powers arrive in a democracy. They almost never begin with a plain claim that the state should be able to see inside everyone’s phone. They begin with the worst thing you can imagine happening to a child.
Once you notice the pattern, it is difficult to stop noticing it. Australia’s metadata retention scheme. Australia’s encryption laws. The UK’s Online Safety Act. The EU’s Chat Control proposal. Each was argued for, in part, on the same ground. And in each case, the power that ended up on the statute book was considerably broader than the problem used to justify it.
That is not an argument that the problem is invented. It isn’t. It is an argument about what happens to a law in the years after the press conference ends.
Start with what isn’t in dispute
Child sexual abuse is not a rhetorical device. The Australian Centre to Counter Child Exploitation receives tens of thousands of reports a year. Investigators working these cases deal with material that ends careers and wrecks health. They face a real technical problem too: when a suspect’s communications are end-to-end encrypted, a warrant that would once have produced evidence now produces nothing readable.
Anyone who waves that away is not arguing in good faith, and privacy advocates who do so damage their own case. The honest position is that the harm is real, the investigative difficulty is real, and neither of those facts settles the question of whether a particular law is a good idea. A power can be introduced for an urgent reason and still be badly designed, disproportionate, or quietly repurposed. Working out which is which is the whole job.
Australia, 2015: the metadata scheme
Australia’s mandatory data retention regime requires telcos and internet providers to keep two years of metadata on every customer — who you contacted, when, for how long, from roughly where. Not the content of the call, but the shape of your life.
When the bill was introduced in late 2014, the government’s public case leaned on national security and serious crime, including making it easier to identify suspected paedophiles. The then Attorney-General assured the public the regime was for the gravest offending only.
It is worth remembering what else was said in the same week. At the launch press conference, the then AFP Commissioner told reporters the scheme would help tackle illegal downloads and piracy — a use case some distance from child exploitation, and one the government subsequently scrambled to walk back.
What happened next is the part worth studying. The scheme formally limited warrantless access to a list of around twenty enforcement and security agencies. But separate provisions in telecommunications law allowed other bodies to obtain the same data anyway. By the time Parliament’s Joint Committee on Intelligence and Security reviewed the regime in 2020, it was documenting dozens of organisations outside the intended list making use of that loophole — local councils, the RSPCA, a state teaching regulator, an illegal dumping squad. Separately, it emerged that police had accessed a journalist’s metadata without the warrant the law required.
The committee delivered 22 unanimous, bipartisan recommendations. The government accepted most of them in 2023. Access to your metadata still does not require a warrant. The broader promise — to repeal the ageing interception act and replace the patchwork with a single, coherent, technology-neutral framework — has been in progress for years and is still not law.
Australia, 2018: the encryption laws
Three years later came the Assistance and Access Act, which lets agencies compel technology companies to help them get at protected communications, via three tiers of request and notice — including the power to require a provider to build a capability it does not currently have.
The politics of its passage are instructive. It went through Parliament in the final sitting days before Christmas. Labor dropped its own amendments to let it pass, having been publicly accused by a government minister of choosing to let “terrorists and paedophiles” continue their work. The opposition’s price was a promise: pass it now, fix it in the new year.
The fixes never really came. The Independent National Security Legislation Monitor reviewed the Act and concluded in 2020 that it could be proportionate and rights-respecting — but only if a substantial set of changes were made. Chief among them: take the power to issue compulsory notices away from the heads of the agencies that want to use them, and give it to an independent, technically informed decision-maker. Thirty-three recommendations in total. That central structural reform has still not been legislated. Agency heads still authorise their own notices, and the details are covered by secrecy provisions, so the public has almost no way to assess how the powers are being used.

Britain and Europe: same argument, newer technology
The UK’s Online Safety Act 2023 contains a provision — section 121 — that lets the regulator, Ofcom, require a service to deploy “accredited technology” to detect child sexual abuse material, including in private messages. Critics called it the spy clause, because the only way to scan an end-to-end encrypted message is to inspect it on the device before it is encrypted, which defeats the point of encrypting it.
The government’s response during debate was that the power would only be used where it was technically feasible to do so — an assurance that was reassuring only if you noticed it was conditional. Ofcom published its final guidance on these notices in May 2026. To date, no notice has been issued and no technology has been accredited. The power simply sits there, on the books, waiting for the feasibility question to change.
The EU’s version, the Child Sexual Abuse Regulation, is better known as Chat Control. In its original form it would have allowed authorities to order platforms to scan users’ messages for known abuse material, unknown material, and grooming behaviour. More than 500 cryptographers and security researchers from dozens of countries signed open letters describing it as technically infeasible and warning that scanning software installed on every device becomes an extremely attractive target — and one whose target list can be changed by a remote update.
The file has been contested for four years. Member states pulled back from mandatory detection orders in late 2025. A separate temporary regime permitting voluntary scanning lapsed in April 2026 and was then revived when the European Parliament fell short of the majority needed to block it. The permanent regulation is still in negotiation. The specifics move constantly; the justification never does.
The pattern
Strip away the jurisdictions and the same sequence appears:
-
Name the least defensible crime. Opposition becomes socially expensive rather than merely political.
-
Build general-purpose infrastructure. Retention databases, compulsion powers, and scanning mandates are not offence-specific. They are capabilities.
-
Skip the sunset clause. Almost none of these powers expire by default.
-
Widen the aperture quietly. Through secondary instruments, loopholes in adjacent law, or simply a new minister’s interpretation.
The term for step four is function creep, and it is not a conspiracy theory — it is the documented history of Australia’s own metadata scheme, recorded by a bipartisan parliamentary committee.
Where broad measures fail the children
Here is the uncomfortable part for advocates of mass detection: the evidence suggests scale is the enemy of accuracy, and inaccuracy consumes exactly the investigative capacity that finding real victims requires.
Figures reported from Germany’s Federal Criminal Police Office indicate that of the roughly 205,000 referrals it received in 2024 from the US clearinghouse NCMEC, close to half were not criminally relevant. In Ireland, civil liberties researchers found that of 4,192 referrals in 2020, only about a fifth were confirmed abuse material, with more than one in ten definitively cleared — holiday photos of kids at the beach, lawful adult content. NCMEC has disputed some national error-rate claims and argues its referrals are more useful than police statistics imply, which is a fair objection worth weighing. But even the contested numbers describe a system where investigators spend an enormous share of their time confirming that nothing happened.
There are second-order costs too. Teenagers exchanging images of themselves get swept into criminal systems designed for predators. Families and doctors get flagged for medical photos. And the same encryption these laws would weaken is what protects an abused child messaging a helpline from a house where the abuser controls the router — along with every journalist’s source, every domestic violence survivor, and every business’s payroll file.
Most child sexual abuse is committed by someone the child already knows. Detection of images is one lever among many, and often not the one that ends the abuse.
Four questions to ask about the next on
When the next proposal arrives — and it will — the useful questions are not about intent. Assume good intent. Ask about design:
-
Does using the power require independent authorisation, or can the agency that wants it approve it for itself?
-
Is the purpose fixed in the Act, or can it be widened by ministerial instrument without a fresh vote?
-
Does it expire? A sunset clause forces a government to re-argue its case with evidence rather than fear.
-
Can anyone check? Meaningful transparency reporting is the difference between oversight and trust.
None of these questions require you to be indifferent to children. They are the questions you ask precisely because the stakes are high enough that getting the mechanism wrong matters.
The strongest child protection agenda is boring and expensive: properly funded specialist police units, faster takedowns, prevention programs, therapeutic support for victims, and targeted investigation of actual suspects under actual warrants. It doesn’t scan anyone’s holiday photos. It just works
Xiph Cyber builds secure communications and privacy technology for Australian organisations. If you’d like to talk about how regulatory change affects your security posture, get in touch.
Further reading
-
Parliamentary Joint Committee on Intelligence and Security, Review of the Mandatory Data Retention Regime (2020) — https://www.aph.gov.au/Parliamentary_Business/Committees/Joint/Intelligence_and_Security/Completed_Inquiries_46th_Parliament/Dataretentionregime/Report
-
Independent National Security Legislation Monitor, report on the Assistance and Access Act (2020) — https://www.inslm.gov.au/reviews/tola-act
-
Ofcom, Statement: Technology Notices (May 2026) — https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/consultation-technology-notices
-
Open letter from cryptographers and security researchers on the CSA Regulation — https://csa-scientist-open-letter.org
-
Irish Council for Civil Liberties on NCMEC referral accuracy — https://www.iccl.ie
-
Department of Home Affairs, Reform of Australia’s electronic surveillance framework — https://www.homeaffairs.gov.au/about-us/our-portfolios/criminal-justice/electronic-surveillance/reform-of-australias-electronic-surveillance-framework
Posted in: Security