NOT ME Standard 0.1 2026-08-07 Slovensky Deutsch Français Español Italiano Polski Čeština

NOT MEContaminate censors

A new privacy rule for the AI age: any intercepted communication must always be AI-generated.

Make Chat Control unusable.

If it's not encrypted, it's not me.

Scanned Instagram DM · Tier 2

Every message above is machine-generated, and says so. This is what the censor's archive fills up with.

The manifesto

1What happened

On 9 July 2026 the European Parliament failed to stop the suspicionless scanning of private messages. Rejecting the Council's fast-tracked text required an absolute majority of 361 MEPs. Only 314 voted to reject. An absolute majority counts the absent and the abstaining on the winning side. The scanning continues in the European Union until 2028.

The permanent version, Chat Control 2.0, is still coming. Five rounds of trilogue on the CSA Regulation have ended without agreement, the last on 29 June 2026. A sixth is expected in September 2026, under a presidency that has consistently sided with the scanning bloc.

The law is not the only thing moving in one direction. On 8 May 2026 Meta began removing end-to-end encryption from Instagram DM. It had been there since 2023, buried in a per-conversation setting almost nobody switched on, which Meta gave as its reason for removing it. Instagram DM is now scanned, alongside Gmail, Snapchat, iCloud Mail, Xbox and the Messenger group chats Meta's default encryption never covered.

Encryption you have to opt into is encryption you can be told you never wanted.

Strip away the procedure and the principle is short: every resident of the European Union is a suspect by default, and private correspondence is searched without cause. That does not expire when the news cycle moves on.

Sources: Fight Chat Control, State of Surveillance, MacRumors.

2What we are not going to do

We are not going to hide.

We are not going to write to the Commission for the fourteenth time.

We are going to make the search worthless.

3The rule

Every channel falls into one of three tiers, and the tier decides who does the talking. The lists name the channels where an agent is practical, not every service that is scanned.

Tier 2 · Read

The operator can read the content of your messages in plaintext, and hands it to the state on request.

Instagram DM · TikTok DM · Telegram (cloud chats) · Snapchat · X DM · LinkedIn · Reddit DM · Discord · Bluesky DM · Mastodon DM

A declared agent handles this. Always.

Tier 1 · Promised

End-to-end encrypted in personal chats, but through a proprietary client controlled by an operator that harvests metadata, decides what the encryption covers — group chats and old history often not — and can deploy client-side scanning whenever it is told to.

WhatsApp · Google Messages (RCS) · iMessage · Facebook Messenger · Viber · LINE · Wickr

Your call. The standard recommends an agent.

Tier 0 · Sacred

End-to-end encrypted through an open, auditable client, with minimal metadata. This is where humans meet.

Signal · SimpleX · Threema

No agent, ever.

The agent introduces itself in its first message, explains why, and says where to find the actual human. It never pretends to be a person. Asked directly whether it is a bot, it says yes, every time. If the person on the other side is in trouble, it stops and hands over to the human.

4Why this works

The censor's database is only worth anything if what is in it means something.

The agent does not remove your responsibility. It removes the evidentiary value of everything collected about you. You still answer for what appears under your name. But nobody can any longer claim it reveals your beliefs or your relationships. The subject remains. The signal is gone.

And it does not need to be secret to work. A declared agent is not noise. It is refusal, in a form that scales.

The second half of the rule is the half that matters. If the only way to reach a human being is an encrypted messenger, people move to encrypted messengers. Not because we lectured them about privacy, but because that is where the conversation is. The ones who never move were never talking to you privately in the first place: the operator was reading all along, and the agent only says so out loud.

Contamination is a function of how many people adopt the standard, not of how much any one account emits. One account shouting into the void is banned in a week and has contaminated nothing. A hundred thousand unremarkable, entirely synthetic conversations make the whole archive worthless. So we are not asking you to be loud. We are asking you to be one of many.

5What it costs

We are not going to pretend this is free.

Running an agent on these platforms breaks their terms of service. Accounts will be suspended. If they suspend enough people for openly declaring an agent, that becomes a story worth more than the accounts.

You stay legally responsible for what your agent publishes. That is why we recommend forbidding the agent from producing images and files. That rule protects you, not the censor.

The model writing in your place belongs to somebody too.

If a state or a corporation is watching you, let the content it watches be generated by another corporation's AI, or another state's.

6Where this comes from

This is applied obfuscation, in the sense Finn Brunton and Helen Nissenbaum gave the word in Obfuscation: A User's Guide for Privacy and Protest (MIT Press). The lineage runs through TrackMeNot and AdNauseam.

Their own conclusion is the honest one, and we adopt it: obfuscation does not defeat surveillance. It imposes cost, creates friction, and buys time for the people doing the harder political work.

The usual objection is that noise can be filtered out. Two answers. Our output is not random noise: it is ordinary text, and separating it from human text means solving the very problem the censor claims to have already solved. And a declared agent is not hiding, so there is nothing to filter.

7How to join

  1. Sort your channels into the three tiers.
  2. Put an agent on Tier 2 — always. That is Instagram DM, TikTok DM, Telegram (cloud chats), Snapchat, X DM, LinkedIn, Reddit DM, Discord, Bluesky DM, Mastodon DM. The prompt pack in this repository takes about twenty minutes and needs nothing installed.
  3. Consider one on Tier 1 — your call. That is WhatsApp, Google Messages (RCS), iMessage, Facebook Messenger, Viber, LINE, Wickr.
  4. Put this in your bio: 🤖 Not encrypted = not me. Signal: @yourhandle
  5. Tell people where to actually find you.

That is the whole standard. Adopt it, fork it, translate it.

If it's not encrypted, it's not me.

Your badge

Put this in your bio on every Tier 2 network.

Generated in this page. Nothing is sent anywhere.

Adopt it

The standard is at notme.chat. The prompt pack: coming soon.