- Meta has disabled end-to-end encryption for Instagram direct messages and calls globally.
- The company cites low adoption, but the change opens the door for Meta to monitor and analyze chat content.
- The measure comes amid strong regulatory and child protection pressures in the United States, the European Union and other countries.
- Privacy experts recommend migrating sensitive conversations to apps like WhatsApp, Signal, or Telegram's secret chats.
If you're one of those people who use Instagram direct messages like any other everyday chat, there's a new development that completely changes the game. Starting this Friday, May 8, 2026, Meta has decided to remove end-to-end encryption (E2EE) from Instagram DMs, a measure that affects both messages and calls within the app.
This change represents a clear step backward for the platform's privacy . From now on, chats will no longer have that extra layer of protection that prevented anyone, not even Meta, from reading their content. The decision has technical, legal, and also very practical implications for millions of users in Spain and Europe who use Instagram as their primary means of informal communication.
What was end-to-end encryption on Instagram and how did it work?

End-to-end encryption is a cryptographic technology designed so that only the sender and receiver of a message can read or listen to it. When active, the message is locked on your mobile device with a unique key and is only unlocked on the recipient's device. Neither the platform, your internet provider, nor any third party intercepting the connection has access to the content.
On Instagram, this protection was introduced as an optional feature in December 2023 for direct messages and calls. It wasn't enabled by default, wasn't available in all regions simultaneously, and, to top it all off, was quite hidden in the settings. In practice, only those explicitly concerned about privacy ended up enabling it.
Meta clearly defined the system in its help center: with E2EE, “only you and the people you communicate with can see or hear what is sent, and no one else, not even Meta, can .” That promise has now been broken: encrypted messages will no longer be accepted after May 8, 2026, and the company has urged users to download any encrypted history they wish to keep.
It's important not to confuse this with other features like disappearing messages that vanish after being viewed . Just because something disappears from the recipient's screen doesn't mean it traveled encrypted to get there. These are different mechanisms, and with the phasing out of E2EE, this confusion becomes even more dangerous.
What changes from May 8, 2026

As of May 8, all direct messages and calls on Instagram will function as standard chats without end-to-end encryption . This means that the content of conversations is once again technically accessible to Meta and, if necessary, to the authorities through the appropriate legal channels.
On its support page, Instagram warns that “end-to-end encrypted messages on Instagram will no longer be supported after May 8, 2026.” The app displays notices and specific steps for users with encrypted DMs to download their messages and media files before they become unavailable on the platform.
For the average user, the real change is the level of privacy when writing in DMs . Previously, although not everyone had it enabled, there was the option to protect more sensitive chats. Now, that option is gone. Any message sent from this date forward will be treated as a regular message that the company can process and store.
There's an important distinction: if you never manually enabled encryption on your account , you've been using direct messages without that extra protection since 2023. In your specific case, the daily experience hardly changes, but the option to add a layer of security when you want a truly private conversation disappears.
For those who did activate E2EE, the loss is more obvious: Instagram will no longer be able to display previous encrypted messages within the app once the withdrawal process is complete. Hence Meta's insistence that you download your history if you want to save it outside the platform.
Meta's explanations: low adoption, pressures, and official discourse
Meta has offered a rather brief public explanation . In various statements to the media and in its official documentation, the company repeats the same argument: “Very few people were activating end-to-end encryption in direct messages, so we are removing this option from Instagram. Anyone who wants to continue sending messages with end-to-end encryption can easily do so on WhatsApp.”
The critical analysis from privacy experts is that a feature being used by few people is not the same as a feature being undesirable . Encryption was never enabled by default, never prominently promoted, and its configuration was so buried that many people weren't even aware it existed. Building an invisible feature, measuring that almost no one uses it, and then removing it due to lack of use is a line of reasoning that generates considerable skepticism.
There is also a political and regulatory context that helps explain the decision. The withdrawal of E2EE comes just 11 days before the Take It Down Act takes effect in the United States , which requires platforms to detect and remove non-consensual intimate images, including those generated by artificial intelligence, within 48 hours. To comply with such a law, the company needs to be able to scan the content, something impossible with strict end-to-end encryption.
This comes on top of years of pressure from governments and law enforcement agencies in the US, UK, the European Union, and Australia , as well as from child protection organizations , which believe that E2EE hinders the fight against child sexual abuse, harassment of minors, and terrorism. In the case of Instagram, whose audience is younger than that of other platforms, this pressure has been particularly intense.
In fact, international media outlets have revealed that the introduction of encryption caused internal friction within Meta . Some executives even called the measure "irresponsible" because it prevented them from monitoring criminal activity. The rollout of end-to-end encryption slowed down, was tested on a limited basis starting in 2021, and was never fully implemented on a large scale across Instagram.
What can Meta do now with your messages?
Without end-to-end encryption, the scenario changes completely: Meta regains the technical capacity to read and process the content of direct messages . This doesn't mean that people are manually reviewing chats, but it does open the door to several automated uses that were previously unfeasible.
Among the uses that various technical sources and legal documents consider possible are automatic scans to detect prohibited content (for example, child abuse material, direct threats or clearly criminal activities), as well as cooperation with judicial investigations by handing over the full content of conversations under order.
The option of training artificial intelligence models and tailoring personalized advertising is also being considered again . Meta hasn't explicitly confirmed that it will use Instagram DMs for these purposes, but the company has already informed its own employees that their interactions on corporate devices will be used to train its AI systems, and this approach aligns with its overall strategy.
In practice, any message, photo, video, or voice note you send via Instagram becomes potentially accessible to the company's algorithms . This change contradicts the idea, frequently repeated in recent years, that "the future is private," a slogan Meta itself used in 2019 to defend its decision to encrypt communications on Facebook, Messenger, and Instagram following controversies such as the Cambridge Analytica scandal.
Another factor to consider is the risk from third parties. If messages are not end-to-end encrypted, the attack surface increases : a security breach on the servers , a data breach, or internal misuse can have more serious consequences than when the information is end-to-end encrypted and the company itself does not have the key.
Arguments for and against: privacy versus child safety
Meta's decision has polarized reactions. Child protection organizations and some law enforcement agencies welcome the end of E2EE on Instagram, understanding that it facilitates the detection and removal of abusive content, especially that related to minors, and allows for faster action against harassers or organized networks.
On the other hand, privacy advocates, technology journalists, and digital rights experts believe this sets a dangerous precedent. They emphasize that it is the first time a major messaging platform has so clearly backtracked on encryption, just when the general trend seemed to be moving in the opposite direction.
The main argument of these groups is that the elimination of end-to-end electronic communications (E2EE) structurally weakens the protection of private communications . In their view, allowing platforms to analyze messages to prosecute crimes opens the door to abuses, creates new commercial temptations, and could ultimately normalize mass surveillance that is difficult to reverse.
In Europe, this debate is linked to other ongoing discussions, such as proposals to require encrypted services to scan messages for child abuse . Both in Spain and throughout the EU, authorities are trying to balance the fight against crime with respect for the confidentiality of communications, a fundamental right enshrined in various legal texts.
What does seem clear is that Meta's move sends a message to the industry: end-to-end encryption is no longer sacrosanct . What for years was presented as the minimum security standard for messaging is beginning to be seen, in certain contexts, as a negotiable element.
How to download your encrypted messages before they disappear
For those who previously enabled end-to-end encryption on Instagram, it's important to act before the old encrypted chats become unavailable within the app. The platform itself displays notifications in the affected conversations, with a direct link to the download process.
If you don't see the notification, the first recommended step is to update the Instagram app to the latest version from your mobile app store. Some downloadable features only appear once the app is up to date, so it's best not to leave it until the last minute.
Next, you'll need to go into your direct message settings and find the option to download encrypted messages and associated media files. The system will generate a file with your history that you can save to your device or the cloud, but it will no longer be accessible from Instagram as regular chats.
If those conversations contain particularly sensitive information (personal documents, bank details, private photos, etc.), the general recommendation is to remove it as soon as possible and store it securely on other, more controlled services or devices, ideally protected by encryption and backups.
In any case, after the deadline, those encrypted conversations will cease to exist as such within Instagram. Only those who have completed the download process will retain a local copy of that content.
End-to-end encrypted alternatives to continue chatting securely
If confidentiality is non-negotiable for you, the wisest course of action is to migrate your sensitive conversations to apps that prioritize end-to-end encryption (E2EE) . The good news is that in Spain and the rest of Europe, there are widely available options that don't require convincing everyone in your circle to install an exotic app.
The most obvious alternative is WhatsApp , also owned by Meta . Unlike Instagram, the messaging app has had end-to-end encryption enabled by default since 2016 for all chats, calls, and video calls. There's no need to change any settings: every conversation between WhatsApp users is encrypted end-to-end.
The drawback of WhatsApp is that you need the other person's phone number . One of the advantages of Instagram Direct was precisely the ability to message a content creator, a brand, or an acquaintance without having to exchange phone numbers. For those more casual relationships, WhatsApp doesn't completely replace Instagram's social functionality.
If you want to avoid relying on large corporations, Signal has established itself as the leading privacy provider. It uses an open-source encryption protocol, the app is free, ad-free, and collects minimal user data. In Europe, it boasts a growing user base, particularly among groups that value digital security.
Another well-known option is Telegram , although there are some important nuances. Its standard chats are not end-to-end encrypted; instead, they are stored on the company's servers. To use E2EE encryption, you have to open a "Secret Chat" with the other person from their profile, and only this type of conversation enjoys maximum protection and extra features such as automatic message deletion.
Within the Apple ecosystem, iMessage also appears as a solid option: messages between Apple devices are end-to-end encrypted by default and are integrated into the iPhone, iPad, and Mac experience. However, it has shortcomings such as the lack of usernames or a native message self-destruct system—limitations that Apple could address if it wants to capitalize on the privacy gap left by Instagram.
Finally, other platforms like X (formerly Twitter) are working on encrypted messaging systems based on usernames , trying to combine the social layer with the protection of private chats. They are currently in the early stages and require a certain degree of trust that the encryption promises will hold over time.
How the everyday use of Instagram as a messaging app is changing
Beyond the technical and legal aspects, Meta's move forces a rethink of Instagram's role as a tool for private conversations . Until now, many people in Spain used DMs almost as an informal substitute for WhatsApp: commenting on a story, sharing a meme, making quick plans, talking to someone you follow but whose phone number you don't have.
In that context, the general perception was that this space was “reasonably private.” With the elimination of end-to-end e-reading, that sense of privacy weakens . Not because someone will manually read what you write, but because the technical guarantee that they can't disappears.
The most sensible approach from now on is to clearly differentiate between casual conversations and truly sensitive communications . For the former, Instagram remains convenient, fast, and well-integrated with the rest of the social network experience. For the latter, using its DMs makes less and less sense.
It also changes the relationship of trust with the platform itself. Many users wonder if this decision could foreshadow future changes in other Meta products , especially WhatsApp, where encryption is a key selling point. The company insists it doesn't intend to touch this pillar, but Instagram's reversal demonstrates that, if the regulatory context and commercial interests push it, end-to-end encryption may cease to be sacrosanct.
Ultimately, Instagram's move marks a turning point in how we understand private conversations on social media. From now on, those who truly value privacy will have to combine the social aspect of each platform with genuinely secure messaging tools , choosing more carefully what they say and where they say it.