58 The UK government’s mandate for OS-level, on-device scanning of every smartphone and tablet in the country is framed as child protection. This article takes that seriously. It presents the strongest possible case for mandatory scanning. The documented industrial scale of CSAM distribution, the proven real-world effectiveness of hash-matching technology, the genuine limits of voluntary platform compliance, and the argument that the UK’s independent judiciary and democratic institutions provide sufficient safeguard against abuse. Then it explains, precisely, where that case still fails. The proportionality test. The difference between server-side deployment and OS-level device firmware. The false positive problem at population scale. And the foundational point that institutional protections are political arrangements, not permanent features a point recent history makes difficult to dismiss. This is Part 2 of a two part series. Part 1 makes the technical and civil liberties case against the policy from a network security perspective. Read that first, it sets the foundation and the further reading linked there is worth your time. The Case For It The serious argument for on-device scanning does not rest on naive faith in government. It rests on something uncomfortable: the documented, industrial-scale reality of child sexual abuse material circulating through platforms and devices that the rest of us use every day. The Internet Watch Foundation reported tens of millions of confirmed CSAM URLs in 2024. Not estimates but confirmed. The volume is not hypothetical. The harm is not hypothetical. Real children, real abuse, distributed at scale across infrastructure that currently has no consistent mechanism to detect or intercept it. Hash matching technology, specifically PhotoDNA and its successors already works. Voluntarily deployed by Microsoft, Google, Meta, and others, it has resulted in millions of reports to the National Center for Missing and Exploited Children. These reports have led to real prosecutions. The children in those images are real. Some of them have been identified and removed from ongoing abuse situations as a direct result. The serious pro-scanning argument says that voluntary deployment is not enough, because platforms that choose not to deploy it or that deploy end-to-end encryption without it become the path of least resistance. Mandatory OS-level implementation closes that gap. You cannot opt your way out of it. The floor rises for everyone. The argument also addresses circumvention directly. Sophisticated actors will route around it. But the distribution of CSAM is not exclusively a sophisticated actor problem. A significant proportion of it moves through ordinary consumer devices, mainstream platforms, and people who are not technically capable of deploying secure operating systems. Raising the floor catches those actors, even if it doesn’t catch everyone. On the political slippery slope concern, the United Kingdom is not China. We have an independent judiciary. We have the Human Rights Act. We have a functioning free press and a political opposition capable of holding the government to account. The infrastructure being proposed is subject to legal challenge, parliamentary scrutiny, and judicial oversight in ways that Chinese surveillance systems simply are not. Treating those institutions as if they don’t exist is a form of bad faith. Where It Still Breaks Down I’ve tried to give that argument its full weight. Let me explain why, even at its strongest, it doesn’t clear the bar.On the harm being real, I don’t dispute it. I never disputed it. The question has never been whether CSAM is a serious harm. It is, categorically. The question is whether this specific technical intervention is an effective and proportionate response to it. Pointing to the scale of the problem does not automatically validate any particular solution to it. Hash matching, It works where it has been voluntarily deployed by platforms, on their own infrastructure, with their own legal and technical accountability. The leap being made here is from “this tool works when used by companies on their servers” to “therefore it should be mandated at OS level on personal devices.” Those are fundamentally different threat models. The attack surface created by a centralised mandatory system embedded in device firmware is different from, and vastly larger than, a server-side implementation on a platform. This is the most attractive part of the argument and the one I want to be most careful about. Yes, mandatory deployment catches actors who aren’t sophisticated enough to circumvent it. But the population of people it catches with false positives (and there will be false positives, every hashing system has them. Thank You especially BitDefender) includes people whose most private documents, medical images, and intimate photographs are now being scanned by a government mandated process they cannot opt out of. The floor rising means the floor rising for everyone. Including people who have done nothing wrong, and who are entitled to privacy as a condition of living in a free society. The UK is not China, this is true. The institutions named are real and I do not dismiss them. But the argument “our institutions will prevent abuse” is precisely the argument made in favour of building surveillance infrastructure in every democratic country that has subsequently drifted toward authoritarianism. Hungary was a democracy. Turkey was a democracy. The institutions that protect against abuse of this infrastructure are political. Political arrangements change. Technical infrastructure, once mandated and embedded, does not. The Human Rights Act has already been subject to sustained political pressure to reform or repeal it. The independence of the judiciary is regularly contested by ministers who find its decisions inconvenient. They are things happening now. Arguing that these institutions are sufficiently robust to be trusted with permanent, population scanning infrastructure requires a confidence in their permanence that recent history does not support. What I Actually Concede Running this exercise has clarified a few things for me. I concede that voluntary deployment has real limits, and that a patchwork of platform-level compliance does create routes around it. That’s a genuine problem, and “just do more voluntary stuff” is not a complete answer. I concede that the argument, while technically accurate, can be overstated. Not every offender is capable of technical circumvention. Measures that catch a proportion of actors, even if not all of them, have some value. What I don’t concede is that either of these points justifies OS-level mandatory scanning on personal devices. The proportionality test still fails. The attack surface created is still catastrophic. The scope of what the infrastructure can be pointed at is still determined by policy. There is a version of this conversation worth having about adequately funded law enforcement, about international cooperation on production and distribution networks, about targeted legal action against hosting infrastructure. Those conversations are harder. The government’s stated goal is legitimate. The mechanism is not. That was true before I steelmanned the other side, and it remains true now. Further Reading I’d encourage you to go further. Part 1 of this article. read here. The attached articles and the links below are worth your time they are not opinion pieces, they are documented evidence of where this road leads. The Bulletin of the Atomic Scientists on how China’s high-tech surveillance apparatus has been used to drive the oppression of the Uyghur population: read here. Human Rights Watch on China’s phone search programme and its systematic trampling of Uyghur rights: read here. The Electronic Frontier Foundation’s technical breakdown of why adding client-side scanning fundamentally breaks end-to-end encryption: read here. Bugs in our pockets: the risks of client-side scanning written by some of the world’s leading cryptographers: read here. Read them, share them, and send them to anyone who thinks this proposal is straightforward. Have any thoughts? Share your reaction or leave a quick response — we’d love to hear what you think! 0 1 0 0 0 0