Online Safety Bill: Messaging apps 'forced to scan messages' for child abuse content in fresh amendment
Apps utilising end-to-end encryption would require backdoors or new mechanisms to allow user data to be scanned and passed on to authorities


A new amendment tabled for the upcoming Online Safety Bill would compel companies to identify child sexual exploitation and abuse (CSEA) content and take it down.
Previous versions of the bill have only compelled companies to use “accredited technology” to detect CSEA and terrorism content, but the July 6 amendment goes further in stating that companies should further seek to use “best endeavours to develop or source technology” to detect and remove CSEA content.
It is unclear whether the government has undertaken research into what form this technology could take, or whether the expectation is companies will fall back on “accredited technology” such as encryption backdoors.
The clarification within the bill that the requirement applies to messages “communicated publicly or privately” seeks to extend oversight to messages currently protected by end-to-end encryption messaging, in which messages are encrypted before being transmitted and thus are accessible only by the sender and recipient.
Under powers already established in earlier drafts of the bill, Ofcom would have the power to fine non-compliant companies up to £18 million or 10% of their worldwide revenue in the most recent complete accounting period.
The government argues that giving security and law enforcement services unfettered access to encrypted messages will improve safety at home and abroad, but critics have argued that once ways around message encryption are established, no messages can properly be considered private.
Companies such as Meta have committed to not only keeping WhatsApp direct messages encrypted but to eventually roll out end-to-end encryption to Messenger and Instagram, a move which has increasingly put them at odds with government ideology.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The last few cabinets have been particularly vocal in their opposition to encryption. Last year, Home Secretary Priti Patel responded to Meta’s commitment to providing end-to-end encryption across its messaging platforms in harsh terms, stating:
"The offending will continue, the images of children being abused will proliferate - but the company intends to blind itself to this problem through end-to-end encryption which prevents all access to messaging content.”
The bill was first published as a draft in May 2021, and since then has been subject to much criticism for providing the government with what is seen as overreaching powers over privacy. The digital rights and freedoms organisation The Open Rights Group has been a particularly vociferous critic of the bill, which is described on its website as “an Orwellian censorship machine.”
RELATED RESOURCE
Securing endpoints amid new threats
Ensuring employees have the flexibility and security to work remotely
“Dropping powers to ban encryption would be a major step forward if confirmed in the Bill. Ukrainians and Russian dissidents today are relying on encryption to protect themselves from real-world harm.
“We have repeatedly warned the Government that attacks on encryption would only help blackmailers, scammers and other criminals,” stated the Executive Director of the Open Rights Group, Jim Killock, in a blog post.
WhatsApp was first released in 2009, but it wasn’t until two years after Facebook’s (now Meta) 2014 acquisition of the company that end-to-end encryption was fully implemented across the app. The WhatsApp product page on security currently promises “only you and the person you're communicating with can read or listen to what is sent, and nobody in between, not even WhatsApp.”
IT Pro has approached Meta for comment on the bill.

Rory Bathgate is Features and Multimedia Editor at ITPro, overseeing all in-depth content and case studies. He can also be found co-hosting the ITPro Podcast with Jane McCallion, swapping a keyboard for a microphone to discuss the latest learnings with thought leaders from across the tech sector.
In his free time, Rory enjoys photography, video editing, and good science fiction. After graduating from the University of Kent with a BA in English and American Literature, Rory undertook an MA in Eighteenth-Century Studies at King’s College London. He joined ITPro in 2022 as a graduate, following four years in student journalism. You can contact Rory at rory.bathgate@futurenet.com or on LinkedIn.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd
-
The UK cybersecurity sector is worth over £13 billion, but experts say there’s huge untapped potential if it can overcome these hurdles
Analysis A new report released by the DSIT revealed the UK’s cybersecurity sector generated £13.2 billion over the last year
By Solomon Klappholz
-
"Thinly spread": Questions raised over UK government’s latest cyber funding scheme
The funding will go towards bolstering cyber skills, though some industry experts have questioned the size of the price tag
By George Fitzmaurice
-
Threat of cyber attacks to national security compared to that of chemical weapons
News The UK government has raised the threat level posed by cyber attacks, deeming it greater on average than an event such as the Salisbury poisoning
By Rory Bathgate
-
2022 Public Sector Identity Index Report
Whitepaper UK Report
By ITPro
-
UK and Japan strike digital partnership to collaborate on IoT security, semiconductors
News The two countries are also set to align their approaches to digital regulation to make it easier for companies to operate in each nation
By Zach Marzouk
-
Defra's legacy software problem 'threatens' UK gov cyber security until 2030
News The department spends over two-thirds of its digital budget on maintaining the risky applications, with no plan in place for a fix within the decade
By Rory Bathgate
-
Netherlands urges citizens to prepare survival kits in case hackers target critical infrastructure
News The latest campaign from the national coordinator for security echoes the growing concern in the UK government over serious cyber attacks
By Zach Marzouk
-
35 cyber startups join largest UK government-backed accelerator
News The startups will benefit from business masterclasses, mentoring and engineering support, and technical product development support
By Zach Marzouk