# NOT ME

> **If it's not encrypted, it's not me.**

A privacy standard for the third millennium. Version 0.1.

## 1. What happened

On 9 July 2026 the European Parliament failed to stop it. Rejecting the Council's fast-tracked text required an absolute majority of 361 MEPs. Only 314 voted to reject. Losing by not showing up is still losing, so suspicionless scanning of private messages continues in the European Union until 2028.

The permanent version is still coming. Five rounds of trilogue on the CSA Regulation have ended without agreement, the last on 29 June 2026. A sixth is expected in September 2026, under a presidency that has consistently sided with the scanning bloc.

The law is not the only thing moving in one direction. On 8 May 2026 Meta began removing end-to-end encryption from Instagram DM. It had been there since 2023, buried in a per-conversation setting, and almost nobody switched it on, which Meta gave as the reason for taking it away. Instagram DM is now scanned, alongside Gmail, Snapchat, iCloud Mail, Xbox and the Messenger group chats that Meta's default encryption never covered.

Encryption you have to opt into is encryption you can be told you never wanted.

Strip away the procedure and the principle being established is short: every resident of the European Union is a suspect by default, and private correspondence is searched without cause. That principle does not expire when the news cycle moves on.

Sources: [Fight Chat Control](https://fightchatcontrol.eu/chat-control-overview), [State of Surveillance](https://stateofsurveillance.org/articles/government/eu-chat-control-surveillance-architecture-2026/), [MacRumors](https://www.macrumors.com/2026/05/08/instagram-end-to-end-encryption/).

## 2. What we are not going to do

We are not going to break the law.

We are not going to hide.

We are not going to write to the Commission for the fourteenth time.

We are going to make the search worthless.

## 3. The rule

Every channel falls into one of three tiers, and the tier decides who does the talking.

Tier 2 is everything the operator can read. Your messages sit in its database in plaintext and go to the state on request. That is Instagram DM, Snapchat, X DM, LinkedIn, Discord. A declared AI agent handles these. Always.

Tier 1 is what you have been promised. Personal chats are encrypted, but through a proprietary client belonging to a company that harvests metadata, decides what the encryption covers (group chats and old history often not) and can switch on scanning the day it is told to. That is WhatsApp, iMessage, Facebook Messenger. Your call, and we recommend an agent.

Tier 0 is sacred: open, auditable end-to-end encryption with minimal metadata. That is Signal, SimpleX, Threema. No agent ever goes here. This is where humans meet.

The agent introduces itself in its first message, explains why, and says where to find the actual human. It never pretends to be a person. Asked directly whether it is a bot, it says yes, every time.

## 4. Why this works

The censor's database is only worth anything if what is in it means something.

The agent does not remove your responsibility. It removes the evidentiary value of everything collected about you. You still answer for what appears under your name. But nobody can any longer claim it reveals your beliefs or your relationships. The subject remains. The signal is gone.

And it does not need to be secret to work. A declared agent is not noise. It is refusal, in a form that scales.

The second half of the rule is the half that matters. If the only way to reach a human being is an encrypted messenger, people move to encrypted messengers. Not because we lectured them about privacy, but because that is where the conversation is.

Since 9 July 2026 the boundary of the search is at least being argued in the right place. The chamber that could not find 361 votes to stop the scanning found 369 to put end-to-end encrypted communication outside its scope, naming WhatsApp and Signal as out of it. That is a negotiating position, not law. The amendments passed at second reading and go to the Council, which has until October to accept them. That is the same Council whose own position of 2 July reinstated the scanning derogation unchanged, and which reporting says may refuse the carve-out outright.

Take it for what it is, and then look at where Parliament drew the line. If the search stops at encryption, Tier 0 is not a preference — it is the far side of the line, and everything in Tier 2 sits inside it. The second half of our rule is the same sentence, written by the people writing the law.

The permanent version is drafted to move the line again. Chat Control 2.0 would reach encrypted messages by scanning them on your device, before they are encrypted. That is why Tier 1 exists and why no operator's promise counts as permanent: Tier 1 is defined by an operator deciding what its encryption covers, and on Instagram that answer became nothing at all.

Contamination is a function of how many people adopt the standard, not of how much any one account emits. One account shouting into the void is banned in a week and has contaminated nothing. A hundred thousand unremarkable, entirely synthetic conversations make the whole archive worthless. So we are not asking you to be loud. We are asking you to be one of many.

Sources: [Euronews](https://www.euronews.com/my-europe/2026/07/09/european-parliament-aims-to-exclude-end-to-end-chats-from-message-scanning-regime), [Fight Chat Control](https://fightchatcontrol.eu/chat-control-overview).

## 5. What it costs

We are not going to pretend this is free.

Running an agent on these platforms breaks their terms of service. Accounts will be suspended. If they suspend enough people for openly declaring an agent, that becomes a story worth more than the accounts.

You stay legally responsible for what your agent publishes. That is exactly why the standard forbids the agent from producing images, files or anything unlawful in itself. Those rules protect you, not the censor.

And if you route your conversations through somebody else's cloud model, you have swapped one observer for another. Run a local model if you can. If you cannot, choose deliberately and know what you chose.

## 6. What we are not building

No fingerprint spoofing. No device-ID rotation. No ban evasion by cycling accounts. No proxy rotation. No adversarial tricks against detection classifiers.

Not out of timidity. A toolkit like that is far more useful to romance scammers and influence operations than to anyone defending their privacy, and publishing one would turn this from a standard into a spam tool overnight, which is precisely the framing needed to bury it.

We do not need it. Agents survive by behaving like what they are: one account belonging to one real person, answering messages at a human pace.

## 7. Where this comes from

This is applied obfuscation, in the sense Finn Brunton and Helen Nissenbaum gave the word in *Obfuscation: A User's Guide for Privacy and Protest* (MIT Press). The lineage runs through TrackMeNot and AdNauseam.

Their own conclusion is the honest one, and we adopt it: obfuscation does not defeat surveillance. It imposes cost, creates friction, and buys time for the people doing the harder political work.

The usual objection is that noise can be filtered out. Two answers. Our output is not random noise. It is ordinary text, and separating it from human text requires solving the very problem the censor claims to have already solved. And a declared agent is not hiding in the first place, so there is nothing to filter.

## 8. How to join

1. Sort your channels into the three tiers.
2. Put an agent on Tier 2. The prompt pack in this repository takes about twenty minutes and needs nothing installed.
3. Put this in your bio: `🤖 Non-E2EE = AI. Real me: Signal @yourhandle`
4. Tell people where to actually find you.

That is the whole standard. Adopt it, fork it, translate it.

**If it's not encrypted, it's not me.**
