Field Guide to AI, Security and Cybercrime

Client-Side Scanning Explained: Checking Messages Before Encryption

A scanner on every device is a capability that can be widened, fooled and misused, which is why it breaks end-to-end encryption.

Field Guide to AI, Security and Cybercrime·Abdolmadjid Masoomi·4 October 2026·9 min read

Client-side scanning promises to find illegal material in encrypted messaging by checking content on your phone before it is encrypted. This essay explains how it works, why the scanner on every device is a capability that can be widened, fooled and misused, and why security engineers treat it as a break in end-to-end encryption rather than a feature of it.

You are told a messaging service offers end-to-end encryption. You assume this means your messages are private between you and the recipient. The common assumption is that encryption is a binary state: either it is on, and your data is secure, or it is off. The real risk is a third state, where encryption is technically present but a mandatory observer sits on your own device, watching everything before the lock is applied. This is the promise and peril of client-side scanning.

How client-side scanning works

Client-side scanning moves the inspection point from a central server to the edge device, your phone or computer. Before your message, photo or video is encrypted and sent, a scanning process runs locally on your device. This process does not hold a key to read the encrypted traffic later; it examines the plain, unencrypted content you are about to send.

The scanning typically uses two methods. The first is perceptual hash matching. The system holds a database of digital fingerprints, or hashes, of known illegal material, such as child sexual abuse material. When you take a photo, the app creates a hash of that image and checks it against this local database. If there is a match, the system flags the content. The second method uses machine learning classifiers. These are algorithms trained to recognise characteristics of certain types of content, like nudity or specific symbols, even if that exact image is not in a hash database. This aims to catch new, previously unseen material.

The critical architectural point is that the scanning logic and, in the case of hash matching, the database of prohibited material, must be present on your device. They are embedded within the messaging application you install. This transforms your personal device into a compliance checkpoint for a third party's rules.

The stated goal and its weight

The stated goal of this technology is serious and widely supported: to detect and report the most severe forms of illegal content, particularly child sexual abuse material, within encrypted environments. Proponents argue that end-to-end encryption has created a zone of absolute secrecy that abusers can exploit, and that society has a duty to find technical means to uphold laws within these spaces. The gravity of the harm this seeks to prevent is why the debate transcends typical privacy versus security trade-offs. It frames client-side scanning not as surveillance, but as a necessary duty of care for platform operators.

This framing is powerful. It positions anyone questioning the technical implementation as being indifferent to the goal itself. However, in security engineering, the weight of a goal does not immunise a proposed solution from critique. The question becomes whether the proposed mechanism reliably achieves only that goal, or if it creates a general-purpose surveillance system that is open to mission creep, error and attack. The integrity of choosing a private messaging app hinges on understanding this distinction.

False positives and the flagging cascade

No detection system is perfect. Hash databases can have errors, and machine learning classifiers generate false positives. A hash collision, where two different images produce the same hash, could cause an innocent family photo to match a hash of illegal material. A classifier might flag an image of a sculpture or a medical textbook diagram.

When a client-side scanner flags content, a cascade begins. The design varies, but typical proposals involve the device sending a cryptographically secured report to a human review team at the service provider. The original message may be blocked from sending. Your account could be suspended pending review. In some designs, law enforcement might be notified automatically. The essential point is that a decision made by software on your device, potentially in error, initiates a process that invades your privacy and could involve law enforcement. You become subject to an accusation by an algorithm you cannot interrogate, running on the device you own.

Who controls the list?

The hash database or the classifier parameters are the rulebook. Who writes this rulebook? In proposals, it is often a combination of the platform operator and an external organisation, such as a law enforcement agency or a non-governmental organisation dedicated to fighting child abuse. The database is then pushed to devices via application updates.

This is where capability widening occurs. The mechanism for scanning for one universally condemned type of content is a general-purpose mechanism for scanning for any content. Once the technical infrastructure is deployed on billions of devices, the political pressure to add other categories to the list becomes intense. Could it be used to scan for copyrighted material? For images of protest symbols? For text containing certain political phrases? The technology does not distinguish. The scanner becomes a content-control engine, and the definition of "illegal" or "prohibited" content is a policy decision that can change with a database update. This fundamentally alters who holds the key to your private communications; it is not a key for decryption, but a key to define what you are permitted to say.

Adversarial collisions and evasion

Attackers will probe and defeat the system. This is a certainty. If the system relies on hash matching, adversaries will use techniques to modify images just enough to change their perceptual hash while leaving the content visually identifiable to a human. This is trivial with basic image processing. If the system uses classifiers, researchers have shown they can be fooled by adversarial attacks—adding subtle noise to an image that causes the AI to misclassify it.

More insidiously, the presence of a scanner creates a new attack surface. What if an attacker finds a way to inject a hash of an innocent image into the local database, causing it to be flagged? What if they can manipulate the classifier to flag specific users? The scanner itself becomes a tool for harassment or for framing innocent individuals. The security of your device is no longer just about protecting your data from theft, but about preventing a mandated component from being weaponised against you. This moves far beyond the marketing claim of military-grade encryption means nothing if the fortress has a mandated spy within its walls.

Why it breaks the trust model

End-to-end encryption is not just a cryptographic protocol; it is a trust model. The model states that the service provider facilitates communication but is technically incapable of accessing the content. You only need to trust the mathematics and the correct implementation on your and your recipient's devices. Client-side scanning shatters this model.

It reintroduces the service provider, or a party they delegate to, as a mandatory observer of your plaintext. Your device is no longer a trusted agent working solely for you; it is an agent of the platform, compelled to examine your actions and report on them. The encryption becomes a tunnel that still exists, but with a mandated sentry at your end inspecting everything before it enters. This changes the system's fundamental properties. It creates a new category of metadata is the message—the fact that a report was sent, even if the content is not immediately decrypted by a third party, is a profound data point about your behaviour.

The policy debate in principle

The policy debate orbits a central tension. On one side is the legitimate demand for tools to combat serious crime in digital spaces. On the other is the principle that a general surveillance capability, once engineered into global communications infrastructure, will inevitably be expanded and abused. Security experts argue that you cannot create a backdoor or a scanning system that works only for the "good guys" under specific conditions. The capability is the vulnerability.

Legislative and regulatory proposals in various jurisdictions have grappled with this. They generally seek to mandate that platforms make encrypted services "safe", with client-side scanning presented as a solution that preserves encryption. The opposition contends that this is a semantic sleight of hand, that it fundamentally weakens security for everyone in order to potentially detect some illegal activity, and that it sets a precedent for automated mass surveillance at the device level. The debate is not about the gravity of the crimes, but about whether this specific tool is a proportionate, secure and contained response, or the first step towards a panopticon built into the hardware in your pocket.

Questions people ask

What is the difference between client-side scanning and server-side scanning?

Server-side scanning happens on a platform's servers after you upload data. This is how email providers scan for spam or social media platforms scan for policy violations. It requires the provider to have access to your unencrypted data. Client-side scanning happens on your device before the data is encrypted and sent. The key difference is that client-side scanning is the only way for a platform to inspect content that is otherwise protected by true end-to-end encryption, where the platform never sees the plaintext.

Can client-side scanning only detect images and videos?

The common focus is on visual media because hash databases and image classifiers are the most developed technologies. However, the same principle applies to any data. Text, audio files and documents could be scanned on-device using keyword lists or audio fingerprinting. The technical architecture for scanning one type of content establishes the precedent and infrastructure for scanning all content types on your device.

Is my phone already scanning my photos?

Yes, but for a different purpose. Your phone's operating system performs on-device scanning for features like facial recognition in your photo gallery, object detection for visual search, or filtering explicit images in children's accounts. The critical distinction is control and purpose. These are features you can generally disable, and the results do not leave your device without your consent. Mandated client-side scanning for messaging is a compelled, non-consensual process where the explicit purpose is to generate reports that leave your device to a third party.

Could this be implemented in an open-source, auditable way to ensure trust?

In theory, yes. The scanning code and hash databases could be made public for audit. However, this does not solve the core problems. Open source would reveal how to evade the scanners more easily. It would not prevent a government from legally compelling the addition of new hashes or classifiers to the database. Most importantly, it does not change the fact that your device is being turned into a mandatory reporting agent. Auditability increases transparency but does not alter the fundamental shift in the trust model.

Close

Client-side scanning is not an upgrade to encryption; it is an alternative design. It chooses a path where your device is no longer a private terminal but a border checkpoint. The gravity of the crimes it aims to detect demands serious solutions, but engineering a surveillance capability into every phone creates risks that are diffuse, systemic and permanent. It makes everyone's security conditional on the immutable goodness of a constantly updated list and the infallibility of an algorithm. Once the technical means for compelled, automated reporting is in place, the scope of what is reported is a matter of policy, not technology. The debate, therefore, is not merely technical but deeply political: what kind of tool do you want your own possession to be?

Questions people ask

What is the difference between client-side scanning and server-side scanning?

Server-side scanning happens on a platform's servers after you upload data. This is how email providers scan for spam or social media platforms scan for policy violations. It requires the provider to have access to your unencrypted data. Client-side scanning happens on your device before the data is encrypted and sent. The key difference is that client-side scanning is the only way for a platform to inspect content that is otherwise protected by true end-to-end encryption, where the platform never sees the plaintext.

Can client-side scanning only detect images and videos?

The common focus is on visual media because hash databases and image classifiers are the most developed technologies. However, the same principle applies to any data. Text, audio files and documents could be scanned on-device using keyword lists or audio fingerprinting. The technical architecture for scanning one type of content establishes the precedent and infrastructure for scanning all content types on your device.

Is my phone already scanning my photos?

Yes, but for a different purpose. Your phone's operating system performs on-device scanning for features like facial recognition in your photo gallery, object detection for visual search, or filtering explicit images in children's accounts. The critical distinction is control and purpose. These are features you can generally disable, and the results do not leave your device without your consent. Mandated client-side scanning for messaging is a compelled, non-consensual process where the explicit purpose is to generate reports that leave your device to a third party.

Could this be implemented in an open-source, auditable way to ensure trust?

In theory, yes. The scanning code and hash databases could be made public for audit. However, this does not solve the core problems. Open source would reveal how to evade the scanners more easily. It would not prevent a government from legally compelling the addition of new hashes or classifiers to the database. Most importantly, it does not change the fact that your device is being turned into a mandatory reporting agent. Auditability increases transparency but does not alter the fundamental shift in the trust model.

Ask NEXUS about this article

Get an AI-powered summary, key points, or follow-up questions about Client-Side Scanning Explained: Checking Messages Before Encryption, grounded in the essay content and the broader corpus.