60 On 8 June 2026, Prime Minister Keir Starmer stood at London Tech Week and handed Apple and Google a three month ultimatum: implement OS-level, on-device scanning across every smartphone and tablet sold or operated in the United Kingdom. It was framed as child protection. I want to be clear about what is actually being proposed, what it would do technically, and why every credible security professional I know of would tell you the same thing. This policy does not make children safer. It makes every person in the country measurably less safe, and it lays the technical groundwork for something that should concern anyone who values a free society. What “On-Device Scanning” Means This is not a proposal to monitor network traffic, or to require reporting from platforms, or to improve law enforcement tooling. This is a proposal to embed scanning functionality at the operating system level meaning it runs on your device, below the application layer, before encryption has any opportunity to protect your data. It means a scanning process that runs when you take a photo on holiday with your kids, family, pets. When you send a document to a colleague. When you open a file from your GP. The scan happens on your hardware, in your home, before the content ever reaches any network. Proponents will argue that the scanning is hash-based comparing files against known content databases and therefore not “reading” your data in any meaningful sense. Hash-matching databases are not static. They are maintained and updated by whichever authority controls the infrastructure. What the database is told to look for is, by definition, a policy decision made by whoever is in power. Today it’s CSAM. Tomorrow? The Ministry of Defence. Next week? The Ministry of National Defence People’s Republic of China The moment you embed a scanning capability at OS level, you have created a persistent, privileged attack surface inside every device in the country. That is not a theoretical risk. That is a certainty, given enough time and enough motivated adversaries. The Security Case Against This In my professional life, I manage network security for a real organisation. We run our own RMM platform. Every day we block intrusion attempts, malware delivery, data exfiltration, and lateral movement by threat actors who are sophisticated, well-resourced, and persistent. I can tell you with professional confidence what a mandatory OS-level scanning system represents to those actors. That’s the single most attractive target in the history of UK digital infrastructure. You would be creating a centralised scanning capability, with a centralised update mechanism, embedded in tens of millions of devices. A successful compromise of that infrastructure, of the signing keys, the update pipeline, the hash database would give an attacker silent, privileged access to every one of those devices simultaneously for life. We are talking about nation-state actors. We are talking about criminal syndicates with the resources and patience to find and exploit exactly this kind of target. The UK government cannot protect its own procurement systems. It cannot protect its own NHS infrastructure. And it wants to mandate a backdoor into every phone in the country. This is not a backdoor only the good guys can use. A backdoor is a vulnerability. Full stop. This has been the consensus of the cryptographic and security research community for thirty years, and no politician has yet managed to legislate their way around mathematics. The Case Against This This policy will not work. Not because the intentions are wrong, but because the people it is designed to catch will simply not be caught by it. The tools to circumvent OS-level scanning are freely available, widely known, and trivial to deploy for anyone motivated enough to use them: Encrypted DNS bypasses government-level DNS filtering entirely for any user who knows to enable it.VPNs on non-standard ports route around network inspection with minimal technical knowledge.Alternative operating systems like GrapheneOS, CalyxOS, LineageOS, TailsOS can be installed on consumer hardware and bypass OS-level scanning completely. These are not obscure. They are well-documented and actively maintained.Peer-to-peer and decentralised networks are, by design, structurally resistant to centralised scanning. Determined bad actors already use these tools. They will not be inconvenienced by this legislation or policy for a single day. What the policy will achieve is pushing privacy-conscious, law-abiding people, journalists, lawyers, activists, abuse survivors who need private communications, people who simply do not want a government scanner in their bathroom into the same unregulated, unmoderated corners of the internet the government claims to be targeting. You do not reduce harm by driving it into spaces that are darker, less visible, and genuinely harder for law enforcement to operate in. You just make the problem harder to see. The proposal as announced is dangerously vague on one critical question. What are the legal limits on what a future government can instruct this infrastructure to scan for? A system designed today to detect illegal imagery is technically identical to a system capable of detecting political speech, trade union communications, encrypted journalism, or membership of any group a future government decides. The infrastructure does not care what it is pointed at. Only the political will of the day determines that and political will changes. China’s surveillance infrastructure did not begin as an instrument of oppression. It began as a series of individually justifiable safety measures. The result is a population-wide behavioural monitoring system that has been used to systematically persecute the Uyghur minority and suppress political dissent at scale. That outcome was not inevitable from day one. It was built incrementally, each step enabled by the infrastructure of the last. I am not suggesting the current government intends anything of the kind. I’m pointing out that the infrastructure being built now will be inherited by every government that follows. What Should Actually Happen The government’s stated goal protecting children from exploitation is legitimate and deserves serious resourcing. What does not deserve serious resourcing is a surveillance architecture that will fail to protect children while successfully surveilling everyone else. Properly funded digital literacy programmes in schools and communities Adequately resourced law enforcement with the training and tooling to pursue bad actors through existing legal mechanisms International cooperation on the production and distribution networks Targeted legal action against hosting infrastructure and distribution networks, rather than population-wide device scanning These approaches are harder to announce. They don’t have the clean narrative of “we put a scanner on every phone.” But they work, and they don’t require dismantling the privacy rights of sixty-seven million people. I carry my phone in my pocket, by my head when I sleep, and through every room of my home. The device being targeted by this policy is present for the most private moments of my life. The right to privacy is not the preserve of people with something to hide. It is a foundational condition of a free society. The ability to have private communications, private thoughts, private associations these are not luxuries. They are the preconditions for journalism, for political opposition, for legal advice, for intimate relationships, for dissent of any kind. Once this infrastructure exists, it will not be dismantled. The technical capability will persist, regardless of which party wins the next election or the one after that. That is the conversation we should be having, not whether we trust the current government with this capability, but whether we trust every government that will ever follow them with it. I don’t. And neither should you. Further Reading I’d encourage you to go further. The attached articles and the links below are worth your time they are not opinion pieces, they are documented evidence of where this road leads. The Bulletin of the Atomic Scientists on how China’s high-tech surveillance apparatus has been used to drive the oppression of the Uyghur population: read here. Human Rights Watch on China’s phone search programme and its systematic trampling of Uyghur rights: read here. The Electronic Frontier Foundation’s technical breakdown of why adding client-side scanning fundamentally breaks end-to-end encryption: read here. Bugs in our pockets: the risks of client-side scanning written by some of the world’s leading cryptographers: read here. Read them, share them, and send them to anyone who thinks this proposal is straightforward. Have any thoughts? Share your reaction or leave a quick response — we’d love to hear what you think! 0 1 0 0 0 0