The directive
In February 2026, Brigadier General Mattias Hanson, the Chief Information Officer of the Swedish Armed Forces, issued a directive. Calls and text messages that do not concern classified information should, as far as possible, be made using the Signal messaging app. The directive was not a suggestion. It was a decision by Sweden's military CIO, motivated by a specific and well-documented threat: the vulnerability of conventional telephone networks to eavesdropping and number spoofing.
General Hanson's reasoning was operational. "Strengthening Sweden's militarily and acting as part of a collective defense requires us to increase our defensive capabilities," he stated. "We need to utilize the latest technology and all the innovative power of the Swedish private sector." Signal, with its open-source end-to-end encryption protocol, represents that latest technology. Sweden's military adopted it because conventional communications channels are not secure enough.
In the same month, Sweden's government was advancing legislation that would make Signal's core technology -- its end-to-end encryption -- functionally illegal.
The bill, formally designated Ju2024/02286, "Datalagring och åtkomst till elektronisk information" -- Data Storage and Access to Electronic Information -- would compel messaging services including Signal, WhatsApp, and other providers to store all user communications and make them accessible to Swedish law enforcement agencies. The Swedish government proposed that the legislation take effect on March 1, 2026, with a Riksdag vote expected in the spring.
Signal's response was immediate and unequivocal. Meredith Whittaker, president of the Signal Foundation, told Swedish news outlet SVT Nyheter that Signal would leave Sweden rather than comply. "We would rather exit the market than create vulnerabilities that could be exploited by third parties," Whittaker said. "We will not walk back."
In a single month, Sweden's military told its personnel to use Signal because it is secure. Sweden's government told Signal to become insecure or leave. And the Swedish Armed Forces -- in their formal response to the proposed legislation -- warned that the bill "cannot be fulfilled without introducing vulnerabilities and backdoors that third parties could exploit."
The same government is simultaneously strengthening its military's communications security and proposing to undermine it. The contradiction is not subtle. And it is not unique to Sweden.
The mathematics of impossibility
The proposed legislation grants Swedish law enforcement expanded access to electronic communications. Its mechanism is straightforward: all providers of electronic communication services operating in Sweden would be required to store user communications data and make it available to law enforcement upon request.
For services that do not use end-to-end encryption, compliance is technically trivial. The provider already has access to message content, stored on its servers. A legal requirement to preserve and produce that content on demand changes the provider's legal obligations but not its technical architecture.
For end-to-end encrypted services, the requirement is technically impossible to fulfill without breaking the encryption. This is not a matter of engineering difficulty. It is a mathematical certainty.
End-to-end encryption means that messages are encrypted on the sender's device and decrypted only on the recipient's device. The service provider -- Signal, in this case -- never possesses the encryption keys and therefore cannot read the messages, even if it wanted to. There is no key to hand over. There is no backdoor to open. The system is designed so that the provider is technically incapable of accessing message content.
To comply with the Swedish law, Signal would need to redesign its system so that either the provider holds a copy of the encryption keys, or a third party holds a copy, or the encryption is weakened in some way that allows access. Each of these approaches introduces what cryptographers call a "single point of failure" -- a mechanism that, if compromised by anyone, compromises the security of all users.
The consensus among cryptographers is not divided on this point. There is no known method of providing government access to encrypted communications that does not simultaneously provide access to anyone else who discovers or compromises the access mechanism. A backdoor for Sweden is a backdoor for Russia, China, criminal organizations, and any other actor with the motivation and capability to exploit it.
The Swedish Armed Forces said exactly this. In their formal assessment of the proposed legislation, the military stated that "access requirements in end-to-end encrypted communications cannot be fulfilled without introducing vulnerabilities and backdoors that could be exploited by third parties." This is not a privacy advocacy organization. This is not a technology company protecting its business model. This is NATO's newest member state's military, which has operational experience with the consequences of compromised communications, telling its own government that this law will make Sweden less safe.
The coalition
The Swedish Armed Forces were not alone in their assessment. A coalition of 237 civil society organizations, cybersecurity experts, and major technology companies signed a joint letter urging Sweden's Riksdag to reject the legislation. The letter was coordinated by members of the Global Encryption Coalition, a network of over 400 organizations across 108 countries advocating for strong encryption worldwide.
The signatories included Mozilla, Proton, Wire, Tuta Mail, and Signal itself. The Center for Democracy and Technology endorsed the opposition. The Internet Society published its own analysis warning of the security implications.
The coalition's argument was technically grounded. The creation of an encryption backdoor creates vulnerabilities that would leave Sweden less safe against cyber threats and foreign adversaries. Those most reliant on encryption -- journalists protecting sources, activists organizing under threat, survivors of domestic violence communicating with support services, military personnel conducting operations -- would be disproportionately harmed.
The letter addressed the law enforcement rationale directly. Yes, encryption makes it harder for police to access the communications of criminal suspects. But weakening encryption does not selectively affect criminals. It affects everyone. And the criminals who are the ostensible targets of the legislation will simply move to other tools -- self-hosted servers, custom encryption software, or platforms operated from jurisdictions outside Sweden's reach. The people who cannot easily move to alternative tools are ordinary citizens, who will be left with weakened security while the criminal targets adapt and disappear.
The Swedish government has not publicly responded to the Armed Forces' assessment or the coalition letter with a technical rebuttal. It has not explained how the law could be implemented without introducing the vulnerabilities that its own military has identified. The legislation appears to proceed on the assumption that because the government wants access, a safe method of providing it must exist -- an assumption that every qualified cryptographer who has examined the question has rejected.
Signal draws a line
Meredith Whittaker's statement that Signal would leave Sweden was not a negotiating tactic. It was a statement of technical and organizational principle, consistent with Signal's response to identical pressure from the United Kingdom.
"We will not walk back," Whittaker said, speaking about both the Swedish and British situations. "Signal's position is very clear -- we will not walk back, adulterate, or otherwise perturb the robust privacy and security guarantees that people depend on."
This is not an abstract philosophical commitment. Signal is a nonprofit foundation. It does not sell advertising. It does not monetize user data. Its only product is secure communication. If it cannot provide secure communication, it has no product and no reason to exist. The decision to leave a market rather than compromise encryption is, for Signal, an existential imperative rather than a strategic choice.
The precedent is Signal's own history. In 2016, a federal grand jury in the Eastern District of Virginia subpoenaed Signal for user data. Signal complied with the subpoena -- and produced exactly two data points: the date the account was created and the date it last connected to Signal's servers. That was all Signal had. No message content, no contacts, no group memberships, no profile information. The system is designed so that Signal cannot produce what it does not possess.
If Sweden's law passes and Signal leaves, approximately 2.2 million Swedish Signal users -- including the military personnel who were just directed to use it -- will lose access to the app. The tool their own military selected as the best available option for secure communication will no longer be available in their country because their government required it to become insecure.
Apple already buckled
To understand what happens when a government successfully pressures a technology company on encryption, look at the United Kingdom.
On February 24, 2025, Apple announced that it would withdraw its Advanced Data Protection feature from UK users. Advanced Data Protection provided end-to-end encryption for iCloud backups, meaning that even Apple could not access the data stored in a user's iCloud account. The UK government, using a Technical Capability Notice under the Investigatory Powers Act 2016, had secretly ordered Apple to maintain the capability to provide access to iCloud data.
Apple's response was not to build the backdoor. It was to remove the encryption feature from UK users entirely. As of February 21, 2025, UK users could no longer enable Advanced Data Protection. Users who had already enabled it were required to disable it. The ten iCloud data categories covered by ADP -- including photos, notes, and device backups -- reverted to standard encryption, meaning Apple holds the keys and can provide data to law enforcement on demand.
Apple chose to reduce security for millions of UK users rather than build a backdoor that could compromise security for everyone. This is often described as Apple "standing up" to the UK government. It was not. Apple complied with the practical effect of the demand. UK users lost encryption. The government got what it wanted: access to UK users' data.
The UK did not stop there. In September 2025, the Home Office issued a second Technical Capability Notice, this time demanding backdoor access specifically to encrypted iCloud backups for UK users. Privacy International filed a challenge at the Investigatory Powers Tribunal, alongside Liberty and two individual claimants, with a seven-day hearing scheduled for 2026.
The Apple precedent demonstrates the pattern. A government issues a secret order demanding access to encrypted data. The company faces an impossible choice: comply and compromise security for all users, or withdraw the security feature from users in that jurisdiction. Either way, users lose. The encryption is either broken or removed.
Signal has stated it will not follow Apple's path. It will not withdraw encryption from Swedish users while maintaining it elsewhere. It will not build a Swedish-specific backdoor. It will leave entirely. This is a different response -- arguably a more principled one -- but the outcome for Swedish users is similar. They lose access to secure communication.
The week Europe chose
The Swedish and British situations are not isolated incidents. They are part of a pattern that becomes visible only when you see the simultaneous events.
On March 26, 2026 -- eighteen days before this article's publication -- the European Parliament voted 311-228 to reject extending the ePrivacy Directive derogation known as Chat Control. That derogation, in force since August 2021, had given Google, Meta, Microsoft, and TikTok a legal basis to voluntarily scan billions of private messages for child sexual abuse material. The Parliament killed it by a margin of eighty-three votes, after the conservative EPP Group attempted to force a re-vote and a parallel scheme emerged to obtain Council approval through a meeting of fisheries ministers.
The vote was, in the words of Pirate Party MEP Patrick Breyer who led the opposition for four years, "a historic day that brings tears of joy." The Electronic Frontier Foundation called it "the first time any major jurisdiction has actively rolled back government-sanctioned mass surveillance of private communications."
As of April 3, 2026, the legal basis for scanning European citizens' private messages expired. Google, Meta, Microsoft, and Snap immediately announced they would continue scanning anyway.
And the permanent replacement legislation -- Chat Control 2.0, the Child Sexual Abuse Regulation -- resumes trilogue negotiations on May 4, with a political deal targeted for July. The Council's position still includes mandatory age verification that privacy advocates warn would effectively kill anonymous online communication in Europe.
In Belgium, a proposed encryption backdoor law was scrapped after 107 organizations mobilized in opposition, with the final text declaring that "the use of encryption is free." In France, Article 8 of the Narco Trafficking Bill, which would have required backdoor access to encrypted communications, was rejected in March 2025.
Each of these battles was won. Each victory was narrow. Each must be defended again.
The three fronts
Step back further and the pattern becomes geopolitical.
While Europe debates whether to scan messages, China is moving to cut the physical connections that carry them. A leaked notice from Shaanxi Telecom, dated April 8, 2026, orders internet service providers to halt all outbound connections beyond mainland China -- including to Hong Kong, Macau, and Taiwan. The Ministry of Industry and Information Technology held a meeting on "strengthening management of unauthorized internet connections via dedicated cross-border data lines." The enforcement mechanism is not blocking or filtering. It is disconnection. Carriers face permanent shutdowns.
While Sweden debates whether to require backdoors, Russia is deploying artificial intelligence to make circumvention impossible. Roskomnadzor, the Russian communications regulator, is spending 2.27 billion rubles -- over $29 million -- on an AI-powered censorship system that integrates machine learning into its deep packet inspection infrastructure. The system does not just block by IP address. It detects traffic patterns that resemble VPN connections and blocks them automatically. Roskomnadzor has already restricted access to 469 VPN services, a 70 percent increase in three months. VPN-related content blocking increased 1,235 percent year-over-year.
Three models. China cuts the wires. Russia deploys AI to detect circumvention. Democratic governments demand that the tools themselves be weakened from the inside. The approaches differ in method. They converge in outcome: a world in which private communication is architecturally impossible.
The defense that does not require trust
The lesson of the Swedish contradiction is not that governments are malicious. Sweden's law enforcement has legitimate operational needs. Criminals do use encrypted communications. Investigations are harder when messages cannot be read.
The lesson is that the proposed solution -- weakening encryption for everyone to catch specific criminals -- does not work. Sweden's own military explained why. The Global Encryption Coalition's 400 organizations explained why. Every qualified cryptographer who has studied the question explained why.
The tools that protect Swedish soldiers from Russian intelligence are the same tools that protect journalists from government surveillance, activists from authoritarian repression, domestic violence survivors from their abusers, and ordinary citizens from data breaches. There is no version of encryption that is strong for the military and weak for the government. The mathematics does not negotiate.
End-to-end encryption works because nobody in the middle -- not the provider, not the carrier, not the government -- can access the communication. The moment you create an exception, the architecture fails. This is why Signal chose the design it did. This is why the Swedish military chose Signal. And this is why the Swedish government's demand is not just a policy disagreement. It is a request to weaken the national defense.
Decentralized networks extend this principle further. Traditional VPN providers route traffic through centralized servers -- servers that can be targeted by court orders, technical capability notices, or infrastructure-level disconnection. Decentralized architectures distribute traffic across independent nodes with no single point of interception. There is no central server to compromise, no single provider to serve a court order on, no cable to cut. The architecture is the defense.
The pattern of the last decade is clear. Centralized services can be pressured, compromised, or shut down. Apple buckled in the UK. Signal will leave Sweden rather than compromise. The next company may not have Signal's principles. The only durable defense is architecture that does not depend on any company's willingness to resist government pressure -- architecture that makes compliance with a backdoor order technically impossible, not just organizationally inconvenient.
The question for Sweden
Sweden's Riksdag has not yet held the final vote. The timeline has slipped from the government's initial target of March 2026, and the intensity of opposition -- from the military, the technology industry, civil society, and Sweden's international allies -- has created political uncertainty.
But the dynamics pushing toward encryption backdoors have not changed. Law enforcement wants access. Politicians want to deliver it. And the fundamental question -- what happens to the security of 10 million Swedes when a NATO member state deliberately weakens the communication infrastructure that its own military identified as essential -- has not been answered.
If the law passes, Signal leaves Sweden. Swedish military personnel lose the secure communication tool their CIO selected. Swedish journalists lose the ability to protect sources. Swedish citizens lose the encryption their government's own Armed Forces said was necessary. And the criminals the law was supposed to catch continue communicating through tools that do not comply with Swedish jurisdiction, from servers that do not sit on Swedish soil, using protocols that do not answer to Swedish law.
Sweden's military figured this out. Signal figured it out. The 237 organizations that signed the coalition letter figured it out. Every cryptographer who has examined the question figured it out.
The question is whether Sweden's parliament will figure it out before the vote.
Sources (11)
Sources: Cyber Insider, "Swedish Armed Forces Adopt Signal for Secure Communications" (February 2026); Cyber Insider, "Signal Threatens to Leave Sweden Over Encryption Backdoor Law"; Infosecurity Magazine, "Signal May Exit Sweden If Government Imposes Encryption Backdoor"; TechRadar, "Signal would rather leave the UK and Sweden than remove encryption protections"; Cyber Insider, "Global Coalition Warns Sweden Against Encryption Backdoor Legislation"; Global Encryption Coalition joint letter (April 2025, 237 signatories); Tuta Blog, "Swedish Armed Forces: Use Signal to defend against interception"; Privacy International, "PI Apple TCN Challenge" and "Update: Our case against UK Government's secret surveillance orders to be heard in 2026"; Computer Weekly, "Home Office issues new backdoor order over Apple encryption" (September 2025); Apple Support, "Apple can no longer offer Advanced Data Protection in the United Kingdom to new users" (February 2025); Element.io, "Why the Swedish Armed Forces' switch to Signal misses the mark"; State of Surveillance, "Signal Would Rather Leave the UK and Sweden Than Break Encryption"; Patrick Breyer, "End of Chat Control: EU Parliament Stops Mass Surveillance in Voting Thriller" (March 26, 2026); Electronic Frontier Foundation, "EU Parliament Blocks Mass-Scanning of Our Chats -- What's Next" (April 2026); Center for Democracy and Technology, "CDT Europe's Response to the European Parliament Rejection of Chat Control 1.0's Extension"; Vision Times, "China's Telecom Crackdown May Block All Overseas Internet Access, Leaked Notice Suggests" (April 11, 2026); United24 Media, "Russia to Launch AI-Powered Internet Censorship System in 2026"; Forbes/Pravda, "Roskomnadzor will create an AI system to block VPNs for 2.3 billion rubles" (January 2026).