Welcome back to the Centre for Democracy & Technology Europe’s Tech Policy Brief! This edition covers the most pressing technology and internet policy issues under debate in Europe and gives CDT’s perspective on the impact to digital rights. To sign up for CDT Europe’s AI newsletter, please visit our website. Do not hesitate to contact our team in Brussels.
👁️ Security and Surveillance
End of Chat Control 1.0
On 26 March, the European Parliament voted against extending “Chat Control 1.0,” a decision that effectively ends the voluntary, indiscriminate mass scanning of private communications across the EU. CDT Europe welcomed this outcome as the expiration of this temporary derogation removes a legally questionable framework that prioritised surveillance over fundamental privacy rights. While proponents argued its expiration would create a regulatory void, we highlighted that authorities still possess robust legal tools (such as targeted warrants and the Digital Services Act) to combat child sexual abuse material effectively. This vote now offers a window of opportunity for EU negotiators to reset their approach as they discuss the permanent Regulation. Moving forward, CDT Europe will continue to engage in dialogue to support co-legislators in prioritising a rights-respecting framework that protects children without compromising end-to-end encryption or the anonymity of online users.
Privacy Symposium 2026
Our Security & Surveillance Director Rand Hammoud participated in this year’s Privacy Symposium, speaking on a panel tackling the national security and privacy implications of commercially available information (CAI) in the age of AI, raising concerns on the disproportionate interference of national security frameworks governing the use of CAI with fundamental rights.
Recommended read: The Citizen Lab, Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors
💬 Online Expression & Civic Space
Protecting Human Rights Defenders in the Digital Age
In cooperation with CDT US, CDT Europe submitted a response to OHCHR call for input to support the drafting of the report of the UN High Commissioner for Human Rights pursuant to HRC resolution 58/23 on “Human rights defenders and new and emerging technologies: protecting human rights defenders, including women human rights defenders, in the digital age”.
CDT’s submission focused on the digital dimension of issues impacting on human rights defenders (HRDs). The submission highlights several phenomena, including the unintended consequences of policies such as social media bans and age verification, the continued implementation of internet shutdowns and digital transnational repression, the impact of gendered disinformation and tech-facilitated gender-based violence (TFGBV) on women HRDs, and the use of spyware technologies against HRDs.
Translating EU’s Frameworks on TFGBV for Frontline Organisations
In partnership with the Women Against Violence Europe (WAVE) Network, CDT Europe’s Secretary General Asha Allen and Online Expression and Civic Space’s team member Marie Seck participated to a webinar on how key EU legal frameworks can be translated into practical tools to support frontline work on technology-facilitated gender-based violence (TFGBV). The focus was set on translating the EU Directive on Violence against Women (VAW Directive) and the Digital Services Act (DSA) into avenues for redress that frontline professionals can use when supporting women experiencing technology-facilitated gender-based violence.

Recommended read: Tech Policy Press, The EU’s Age Verification Fix May Create More Problems Than it Solves
⚖️ Equity and Data
AI Omnibus Continues to Raise Concerns
In the context of negotiations on the AI omnibus, CDT Europe joined 32 other civil society organisations and individuals in a public letter raising concerns about proposed changes to Annex I of the AI Act. Raising key risks to fundamental rights as well as of increased fragmentation and legal uncertainty, the coalition called on the co-legislators to preserve the full integrity and scope of the AI Act. CDT Europe provided further feedback on the proposed amendments in a brief highlighting that regulating Annex I high-risk AI systems primarily under existing sectoral legislation risks omitting key fundamental rights, value chain and accountability obligations that are crucial to ensuring a responsible approach to AI in Europe. In addition to comments on Annex I, CDT Europe also published feedback on further omnibus provisions, amongst others reiterating concerns around the processing of sensitive data for bias identification and correction, the powers of fundamental rights authorities and the application date of obligations.
Calling for the Swift Establishment of a Robust Advisory Forum for AI
In an open letter signed by several civil society organisations, CDT Europe called for the pending establishment of the Advisory Forum, the only formal oversight body created by the AI Act enabling multi-stakeholder input. Seven months after applications closed, the final composition of the Advisory Forum is yet to be announced, preventing its participation in crucial implementation debates and the integration of cross-sectoral perspectives in key aspects of the omnibus.
Recommended listen: Heinrich-Böll-Stiftung, Empire of AI meets European democracy: Conversation with Karen Hao & MEP Alexandra Geese
🛡️ Online Protection of Minors
European Commission Verification App Cannot be a Standalone Solution
The European Commission announced the launch of the EU Age Verification App on 15 April, presented as a technically ready solution to address harms faced by minors online. Raising concerns about the implications for fundamental rights, including privacy, data protection, security, and freedom of expression, CDT Europe highlighted that a substantial body of research has documented the risks and limitations associated with wide-scale age verification systems. Moving forward with deployment without comprehensive independent scrutiny and safeguards risks undermining user trust and exposing individuals to unintended harms. In addition, CDT Europe underscores the potential disproportionate impact on vulnerable groups, including those who rely on anonymity online, and calls for greater transparency around data governance, cybersecurity measures, and access by public authorities. Within the broader context of the Digital Services Act, age verification tools are not a standalone solution. We urge the European Commission to ensure meaningful stakeholder engagement and the implementation of robust safeguards to protect fundamental rights.
📢 CDT Europe’s Team Keeps Expanding!
In April, we welcomed two new members to the CDT Europe’s team: Christian Cirhigiri, our new Online Expression & Civic Space Programme Director, and Lisa Beatrice Ferrari, our new Security, Surveillance & Human Rights Programme Policy & Research Officer.

Christian leads our EU-level policy advocacy around the implementation of the DSA and its related frameworks, and advocates for the protection and promotion of democratic values and fundamental rights online with a view to nurture a diverse, pluralistic and healthy civic space. He brings over a decade of experience at the intersection of tech policy, human rights, and peacebuilding, with a focus on privacy, platform accountability, transparency, and content moderation.
Lisa Beatrice will support our work on surveillance accountability, encryption, and the promotion of privacy and the rule of law in the digital space. She brings experience across the public and private sectors, where she worked on key tech files including AI, cloud, data protection, and cybersecurity. Before joining CDT Europe, she worked as a Public Policy Associate at Workday and, prior to that, as a Technology and Digital Economy Trainee at Burson.

⏫ Upcoming Events
BEUC’s Digital Omnibus Event: On 5 May, our Equity & Data Director Laura Lazaro Cabrera will speak on a panel on safeguarding consumers in the age of AI in the context of the “Upholding Consumers’ Digital Rights in the Omnibus Era” conference organised by BEUC – The European Consumer Organisation. You can register to attend the conference here.
CPDP 2026: From 19 May to 21 May, CDT Europe is participating in this year’s Computers, Privacy and Data Protection Conference (CDPD) in Brussels. On Wednesday 20 May, our Online Expression team is hosting a workshop on age verification, the online protection of minors and their rights. On the same day, our Equity & Data team is organising a panel discussion on sensitive data processing, fairness and non-discrimination in AI. You can find the full programme of the conference here.
🗞️📻 In the Press
- Tech Policy Press, EU’s AI Act Delays Let High-Risk Systems Dodge Oversight
- MLex, US trial evidence is likely to fuel EU enforcement, litigation against Big Tech
- POLITICO Europe, Online age checks are coming in Europe
- Tech Policy Press, EU Intensifies Child Safety Enforcement, Flags Gaps in Meta Age Checks
- Computer World, EU lawmakers fail to agree on watered-down AI Act, talks pushed to May