Scanned Instagram DM · Tier 2
Every message above is machine-generated, and says so. Each block on this page carries the censor's own readout, and every verdict comes back the same.
The manifesto
Version 0.1 in full, on the page it is named after. Nothing behind a link, a download or a consent dialogue.
1What happened
On 9 July 2026 the European Parliament failed to stop it. Rejecting the Council's fast-tracked text required an absolute majority of 361 MEPs. Only 314 voted to reject. Losing by not showing up is still losing, so suspicionless scanning of private messages continues in the European Union until 2028.
The permanent version, Chat Control 2.0, is still coming. Five rounds of trilogue on the CSA Regulation have ended without agreement, the last on 29 June 2026. A sixth is expected in September 2026, under a presidency that has consistently sided with the scanning bloc.
The law is not the only thing moving in one direction. On 8 May 2026 Meta began removing end-to-end encryption from Instagram DM. It had been there since 2023, buried in a per-conversation setting almost nobody switched on, which Meta gave as its reason for removing it. Instagram DM is now scanned, alongside Gmail, Snapchat, iCloud Mail, Xbox and the Messenger group chats Meta's default encryption never covered.
Encryption you have to opt into is encryption you can be told you never wanted.
Strip away the procedure and the principle is short: every resident of the European Union is a suspect by default, and private correspondence is searched without cause. That does not expire when the news cycle moves on.
Sources: Fight Chat Control, State of Surveillance, MacRumors.
2What we are not going to do
We are not going to break the law.
We are not going to hide.
We are not going to write to the Commission for the fourteenth time.
We are going to make the search worthless.
3The rule
Every channel falls into one of three tiers, and the tier decides who does the talking.
Tier 2 · Read
The operator can read the content of your messages in plaintext, and hands it to the state on request.
Instagram DM · Snapchat · X DM · LinkedIn · Discord
A declared agent handles this. Always.
Tier 1 · Promised
End-to-end encrypted in personal chats, but through a proprietary client controlled by an operator that harvests metadata, decides what the encryption covers — group chats and old history often not — and can deploy client-side scanning whenever it is told to.
WhatsApp · iMessage · Facebook Messenger
Your call. The standard recommends an agent.
Tier 0 · Sacred
Open, auditable end-to-end encryption with minimal metadata. This is where humans meet.
Signal · SimpleX · Threema
No agent, ever.
The agent introduces itself in its first message, explains why, and says where to find the actual human. It never pretends to be a person. Asked directly whether it is a bot, it says yes, every time.
4Why this works
The censor's database is only worth anything if what is in it means something.
The agent does not remove your responsibility. It removes the evidentiary value of everything collected about you. You still answer for what appears under your name. But nobody can any longer claim it reveals your beliefs or your relationships. The subject remains. The signal is gone.
And it does not need to be secret to work. A declared agent is not noise. It is refusal, in a form that scales.
The second half of the rule is the half that matters. If the only way to reach a human being is an encrypted messenger, people move to encrypted messengers. Not because we lectured them about privacy, but because that is where the conversation is.
The chamber that could not find 361 votes to stop the scanning found 369 to put end-to-end encrypted communication outside its scope, naming WhatsApp and Signal. That is a negotiating position, not law: the amendments passed at second reading and go to the Council, which has until October to accept them, and whose own position of 2 July reinstated the derogation unchanged.
Take it for what it is, and then look at where Parliament drew the line: Tier 0 on the far side of it, everything in Tier 2 inside. The second half of our rule is the same sentence, written by the people writing the law.
Chat Control 2.0 is drafted to move that line again: it would reach encrypted messages by scanning them on your device, before they are encrypted. That is why Tier 1 exists, and why no operator's promise counts as permanent.
Contamination is a function of how many people adopt the standard, not of how much any one account emits. One account shouting into the void is banned in a week and has contaminated nothing. A hundred thousand unremarkable, entirely synthetic conversations make the whole archive worthless. So we are not asking you to be loud. We are asking you to be one of many.
Sources: Euronews, Fight Chat Control.
5What it costs
We are not going to pretend this is free.
Running an agent on these platforms breaks their terms of service. Accounts will be suspended. If they suspend enough people for openly declaring an agent, that becomes a story worth more than the accounts.
You stay legally responsible for what your agent publishes. That is why the standard forbids the agent from producing images, files or anything unlawful in itself. Those rules protect you, not the censor.
And if you route your conversations through somebody else's cloud model, you have swapped one observer for another. Run a local model if you can. If you cannot, choose deliberately and know what you chose.
6What we are not building
No fingerprint spoofing. No device-ID rotation. No ban evasion by cycling accounts. No proxy rotation. No adversarial tricks against detection classifiers.
Not out of timidity. That toolkit is worth far more to romance scammers and influence operations than to anyone defending their privacy, and publishing it would turn a standard into a spam tool overnight — precisely the framing needed to bury this one.
We do not need it. Agents survive by behaving like what they are: one account belonging to one real person, answering messages at a human pace.
7Where this comes from
This is applied obfuscation, in the sense Finn Brunton and Helen Nissenbaum gave the word in Obfuscation: A User's Guide for Privacy and Protest (MIT Press). The lineage runs through TrackMeNot and AdNauseam.
Their own conclusion is the honest one, and we adopt it: obfuscation does not defeat surveillance. It imposes cost, creates friction, and buys time for the people doing the harder political work.
The usual objection is that noise can be filtered out. Two answers. Our output is not random noise: it is ordinary text, and separating it from human text means solving the very problem the censor claims to have already solved. And a declared agent is not hiding, so there is nothing to filter.
8How to join
- Sort your channels into the three tiers.
- Put an agent on Tier 2. The prompt pack in this repository takes about twenty minutes and needs nothing installed.
- Put this in your bio:
🤖 Non-E2EE = AI. Real me: Signal @yourhandle - Tell people where to actually find you.
That is the whole standard. Adopt it, fork it, translate it.
If it's not encrypted, it's not me.
Your badge
Put this in your bio on every Tier 2 network.
Generated in this page. Nothing is sent anywhere.
Adopt it
The standard and the prompt pack are at notme.chat.