Today, May 8, 2026, Instagram removed end-to-end encryption from direct messages. From this moment on, Meta technically has the ability to read the content of every DM exchanged on the platform. The news may look like a technical detail for insiders. It isn’t. It’s worth understanding what actually changes — and why the problem is bigger than Instagram.


What exactly happened

End-to-end encryption (E2EE) is the mechanism that guarantees only the devices of the participants in a conversation can read the messages. The provider — in this case Meta — sees the traffic, runs the infrastructure, delivers the packets, but cannot access the content of the conversations.

Instagram had introduced this protection as an opt-in feature in December 2023. Even then it was a late and partial move, well behind the standards of Signal or WhatsApp itself. But at least it existed. As of today, it no longer does.

Meta’s official reason? Spokesperson Dina El-Kassaby Luce simply stated that “very few people were turning on end-to-end encryption in DMs, so we decided to remove it.” Low uptake became the justification for stripping away a safeguard instead of promoting it.


The excuse and the reality

Taking the official version at face value would be naive. Behind the removal lies a structural pressure that has been building for years.

The Take It Down Act, signed into law in the US in May 2025, requires platforms to remove non-consensual sexually explicit images — deepfakes included — within 48 hours of a report. By May 19, 2026, every platform must have an operational system to do so. The problem is that a platform that can’t read messages can’t scan them. End-to-end encryption and automated content moderation are technically incompatible.

On top of this come years of pressure from governments, law enforcement and child protection groups in the US, UK, EU and Australia, all historically opposed to E2EE because — they claim — it “protects criminals.” It’s the same argument that has been used for decades to justify every erosion of digital privacy.

The practical result: Meta found in a child safety law the political cover to do what it probably wanted to do anyway. Instagram DMs are now accessible, analyzable, transmittable to authorities on legal request — and, according to some cryptography experts, potentially usable to train Meta’s artificial intelligence models.


The real problem: the ecosystem, not the single app

Here is where the most important — and most underestimated — point comes into play.

Meta isn’t an app. It’s a constellation of observation surfaces watching the same user from different angles. Instagram sees what you post, who you interact with, how much time you spend on each piece of content. Facebook adds your social relationships, your events, your groups. Messenger handles another slice of conversations. WhatsApp — which for now keeps end-to-end encryption — handles the most personal and intimate traffic.

All this data converges into the same industrial architecture, tied to the same identities through Meta’s Accounts Center. The group’s privacy policy — which, not by chance, is now called a data policy — runs to roughly 64 pages.

Removing E2EE from Instagram DMs doesn’t just add “Meta reads your messages on Instagram.” It adds a new layer of live, readable content to a system that already collects metadata, behaviors, activity times, social connections, advertising signals. If Alice messages Bob on Instagram, that conversation becomes a signal correlatable with everything else: Bob’s friendships on Facebook, his behavior on WhatsApp, his past interactions with the system.

You don’t need to read everyone’s messages. Sometimes it’s enough to read some of them, at certain points in the system, and let correlation, inference and artificial intelligence reconstruct the rest.


What to do now

The first thing is to stop using Instagram DMs for any conversation of even the slightest personal relevance. Not because it’s illegal, but because it was never designed to be a private space — and now it isn’t one even formally.

Alternatives exist and they work. Signal is the reference standard for private messaging: end-to-end encryption on by default, minimal metadata, verifiable open-source code. WhatsApp, despite belonging to Meta, still keeps E2EE active for now — though the metadata remains within the group’s perimeter regardless. For those who want to leave the Meta ecosystem entirely, Element (built on Matrix) is an excellent federated alternative.

The second step, often overlooked, is to raise awareness among the people you communicate with. Privacy isn’t an individual choice: it also depends on the devices and apps used by the people on the other side of the conversation.


Conclusion

The removal of end-to-end encryption from Instagram isn’t an accident or a misstep. It’s the result of a consistent political and commercial pressure that advances gradually and without much noise. Every time a safeguard disappears with the justification of “low usage,” the right question isn’t why nobody used it, but why nobody knew it existed. The signal to catch isn’t technical: it’s that truly private spaces on commercial platforms never really existed — and anyone who believed otherwise should update their thinking, fast.


Sources: