The Dilemma of a Less Private Future: Meta Ends End-to-End Encryption on Instagram 

On May 8, 2026, Meta announced the closing of the end-to-end encryption (E2EE) option previously available to Instagram users. The reason for the decision, according to Meta, was that too few people were using the feature. 

The announcement immediately rekindled questions at the heart of data governance, privacy and online safety, where privacy advocates fault the move as one that leaves users of the platform susceptible to data breaches and privacy violations,  and children’s charities and advocates welcoming it because it makes it easier to track, identify and prosecute pedophiles and other criminals online who hide behind E2EE to commit crimes without getting caught. At the heart of the debate is the pertinent question: what kind of data future do we want? A less private one in favour of a ‘safer’ one? Or is there a way to have both? 

Meta and the rise of E2EE

E2EE is a secure communication technique that converts data into codes before sending it from one endpoint to another endpoint. The recipient’s device decrypts the data in transit. It uses cryptography, just like other encryption techniques, to convert readable plaintext into unreadable ciphertext. This procedure ensures that only the intended recipients, who have the right decryption key, can access sensitive data and protect it from unauthorised users.

More so, E2EE is one of the most secure forms of online messaging, ensuring only the sender and recipient can view messages. E2EE is markedly different from standard encryption because, whereas Meta can access private messages if they want to for legal purposes or otherwise, they’re unable to do the same with E2EE. This is the default on major messaging platforms like Signal, WhatsApp, Facebook Messenger, Apple’s iMessage, and Google Messages.

Hence, Meta’s decision to officially retire end-to-end encryption (E2EE) support for Instagram direct messages highlights a shift in the approach to digital privacy. It is a reversal from Mark Zuckerberg’s 2019 declaration that “the future is private.”  This is even more stark because Meta was a champion of the feature, rolling it out across its platforms in 2023. However, while it was defaultly applied for WhatsApp and Messenger,  it was kept optional for Instagram and  hidden away, such that most users did not know it existed in the first place.

The erosion of privacy and the AI suspicion

Although Meta’s stated reason for discontinuing the feature on Instagram is its reported low usage, it has renewed concerns about data privacy in Meta’s ever-expanding ecosystem. In November 2025, an Instagram post with more than 100,000 likes claimed that Meta would start reading users’ direct messages once it made a privacy policy update on December 16, 2025, warning that “Every conversation. Every photo. Every voice message. Fed into AI”. Although this claim was found to be false by fact-checkers at Snopes, who confirmed that Meta’s planned privacy policy update on December 16, 2025, did not pertain to direct messages at all. A Meta spokesperson confirmed directly that “We do not use the content of your private messages with friends and family to train our AIs unless you or someone in the chat chooses to share those messages with our AIs.”

But the fear is not unfounded. It emanates from a much broader, well-documented pattern of Meta’s creeping expansion of data use. In December 2025, Meta said interactions with its Meta AI tools, including those inside private conversations, may be used for targeted ads. Before that, the company already allowed the use of all Meta AI interactions for AI training. Critics have also pointed out that Meta may have sabotaged the E2EE rollout on Instagram to justify killing it, in which case, the “low adoption” may as well just be a convenient cover story. When a platform buries a feature so deep that most users never find it, blaming low uptake for its removal is a self-serving argument.

Also, in Europe, the company has been aggressively pushing to train its AI models on public user data, facing significant regulatory resistance under the GDPR. Meta has stated that it will train its AI systems using public posts and comments shared by adult users in the EU, as well as users’ interactions with Meta AI, to train and improve its models. While it insists that private DMs are excluded, the pattern reflects a continuously-expanding data appetite. And now that Instagram DMs are no longer protected by E2EE, Meta has the technical ability to access them, even if it says it currently chooses not to.

The case for removing E2EE: why child safety advocates are not entirely wrong

There is a genuine and documented crisis driving pressure from the other direction. Official EU figures highlight a peak of over 36.2 million reports of suspected online child sexual abuse in 2023, with grooming reports escalating by over 300% between 2021 and 2023. Law enforcement agencies like Europol have argued that E2EE services have provided a “safe haven” for offenders. This is corroborated by the dramatic drop in the number of Child Sexual Abuse Material (CSAM) reports to the National Center for Missing and Exploited Children (NCMEC) once Meta applied E2EE, and there is little doubt that the decrease was directly linked to the encryption rollout.

In the United States, legislators have tried to respond through the STOP CSAM Act, a bipartisan bill that would expand companies’ obligations to report child sexual abuse material. In the EU, the debate over what they refere to as “Chat Control” regulation, which would require the scanning of private messages for CSAM, has divided member states deeply, with some insisting it amounts to mass surveillance and others arguing it is an urgent safeguard for children. This is the dilemma at the heart of the E2EE debate: the anti-encryption advocates are rarely authoritarians seeking to erode privacy rights. They are often parents, prosecutors and child welfare specialists confronting a crisis that encryption has made harder to address.

However, weakening encryption does not automatically make children safer.  The Center for Democracy and Technology argues that the STOP CSAM Act would undermine the very tools that keep children’s communications secure and their personal lives private. The Electronic Frontier Foundation has similarly called for US Congress to reject legislative moves that would force companies to weaken encryption. And the 3CL Foundation unequivocally states that the CSAM detection proposal represents a false choice between child safety and privacy, whereas it delivers neither. As such children won’t necessarily be protected because criminals will easily game the system, while privacy will be destroyed for billions of law-abiding citizens. 

In addition, there is the risk that surveillance infrastructure built in the name of child safety is rarely confined to that purpose. Once platforms are compelled or incentivised to scan message content, that capability does not disappear when the original mandate is fulfilled. Chances are that it expands. History, particularly on the African continent, has shown exactly how that expansion tends to unfold.

Africa in the mix: what are the stakes for us?

While the global debate over E2EE, privacy and child safety is urgent everywhere, the stakes for African citizens, particularly journalists, activists, opposition figures and ordinary people living under governments that treat dissent as a threat to national security, are acute.

According to Freedom House, in 2024, internet users were arrested, imprisoned, or detained in retaliation for their online speech in 16 of the 17 African countries assessed. One example in Tunisia saw a military court sentence a blogger and human rights defender to seven years in prison for social media posts calling for demonstrations. In Uganda, the pattern has been remarkably consistent and escalating. In November 2024, three TikTokers were arrested and charged under the Computer Misuse (Amendment) Act for “hate speech” and “spreading malicious information”. their alleged offence was posting videos deemed insulting to President Yoweri Museveni and his family. Across East and Southern Africa, Amnesty International has documented increased internet blockades and the use of restrictive cybersecurity laws to restrict media freedom, especially in countries that held elections in 2025 and early 2026.

The case of Kenya’s #RejectFinanceBill protests demonstrated how digital surveillance intersects with state power. Between June 2024 and July 2025, young Kenyans organised against proposed punitive taxes and broader government corruption. Kenyan authorities systematically deployed technology-facilitated violence as part of a coordinated and sustained campaign to suppress the protests, using online intimidation, surveillance, threats, incitement to hatred, and smear campaigns as core state tools to undermine the credibility and reach of government critics. These tactics were later used to justify arrests, enforced disappearances and killings of notable protest organisers. According to the Kenya National Commission on Human Rights, more than 83 cases of abductions and enforced disappearances were reported since June 2024. Many of those detained were held incommunicado, and upon release, recounted being tortured and interrogated about their online activities.

Amnesty International found that Kenyan government conducted digital surveillance on targeted individuals through phone triangulation, tracking, and the alleged use of spyware, with human rights defenders believing that surveillance was supported by Safaricom, one of Kenya’s biggest telecommunications companies. The movement’s organisers were tracked not because encryption had been breached, but through metadata, telecommunications access and the deep reach of state security apparatus. The worry is then about what becomes possible when a platform as widely used as Instagram removes the one layer of technical protection that even well-resourced governments cannot easily bypass. 

The surveillance infrastructure across the continent is already alarming. A database compiled by researchers from the Carnegie Endowment for International Peace details how government actors have targeted rights activists in Angola, Morocco and Rwanda, reporters in Togo, and journalist sources in Botswana. They have also targeted opposition figures in Ethiopia, Ghana and Gabon. A 2025 report by Unwanted Witness, a civil society organisation, details how surveillance in Uganda and other countries including Rwanda, Kenya, Ethiopia, Malawi, South Africa and Zimbabwe has evolved into a complex system combining broad monitoring with targeted spyware campaigns affecting journalists, civil society actors, human rights defenders, and opposition politicians. 

Nigeria’s standoff with Meta adds yet another dimension to the African picture. After a 38-month investigation, the FCCPC issued a $220 million fine against Meta in July 2024, with additional penalties from other agencies bringing the total to $290 million, for denying Nigerians the right to control their data, transferring and sharing Nigerian user data without authorisation, and discriminating against Nigerian users compared to those in other jurisdictions. Meta’s response was to threaten to pull Facebook and Instagram from Nigeria entirely. The dynamic is one whereMeta uses data from African users, profits from African markets, but treats the continent as a lower-tier regulatory environment where its practices face less structured accountability. 

The Question No One Wants to Answer

What does it mean for democratic life on a continent where, as Media Defence highlights,  Nigeria’s proposed Social Media Bill would allow the government to examine internet traffic to determine its content by restricting the use of E2EE or requiring that content be decrypted, while Zimbabwe’s Interception of Communications Act already mandates cryptography services to decrypt data at judicial authorities’ request? It means that the weakening of E2EE on Instagram, even if Meta’s own intentions are commercial rather than political, is not a neutral technical decision. It removes a tool that journalists, activists, opposition figures and civil society organisations across Africa have relied on precisely because their governments cannot be trusted with the contents of their online conversations. 

The flipside of the argument that encryption facilitates child abuse is real and must be taken seriously. But it is also worth noting that the governments most vocally opposed to encryption on child safety grounds are frequently the same governments most aggressively surveilling civil society. According to Africa Center, three-quarters of the 16 African countries facing armed conflict are authoritarian or semi-authoritarian, and digital repression serves as an amplifier of these tensions rather than a mitigator. Surveillance tools built for one purpose have a long and well-documented history of being redirected towards another. 

Meta’s rollback of E2EE on Instagram will not be the last move of its kind. The pressures from AI development, law enforcement, child safety advocates, and changing revenue models will all push towards more access to message content, not less. African governments, civil society, digital rights organisations and ordinary users must now urgently reflect and engage with this question: in a continent where democratic institutions are still being built and contested, who benefits most when our private conversations are no longer private?

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top