An Announced End Without Drumrolls or Trumpets
On May 8, 2026, a chapter silently closed for private life on Instagram. The platform officially ceased supporting end-to-end encryption (E2EE) for its direct messages (DMs), in accordance with a quietly published announcement in its help center a few weeks prior. The BBC described this withdrawal as a "major turnaround" by Meta, Instagram's parent company.
The news, initially spotted in mid-March 2026 by the site 9to5Mac, sparked little public uproar — which, given the stakes, is concerning. End-to-end encryption ensures that only the devices of the participants in a conversation can decrypt the content of the messages: neither Meta, nor a malicious actor, nor a government can theoretically access it. It is one of the strongest protections that a messaging platform can offer.
A Chaotic Journey to Encryption
The history of encryption at Meta is long and winding. The company began working on E2EE for Facebook Messenger as early as 2019, describing the task at the time as "an incredibly complex and challenging engineering puzzle" requiring them to "rewrite almost the entire messaging and calling codebase."
The deployment of E2EE for Messenger began in August 2023 and was completed by the end of that same year. Meta then promised that E2EE for Instagram direct messages would follow. It did materialize, but only in the form of an optional feature, buried deep within the app's settings. The user had to manually enable encryption in the settings for each conversation.
As a result: as acknowledged by 9to5Mac author Arin Waichulis, "personally, I wasn't aware that this option existed on Instagram until this week. And I doubt I'm the only one in this case."
"Low Adoption": A Circular Argument
Meta's official justification relies on a rather circular argument. A company spokesperson told WIRED and other media:
"Very few people opted for end-to-end encrypted messaging in DMs, so we are removing this option from Instagram in the coming months."
And added: "Anyone wishing to continue using E2EE messaging can easily do so on WhatsApp."
This explanation has sparked sharp criticism. Davi Ottenheimer, a security chief at a large firm, called the approach "deeply cynical" in an interview with WIRED:
"They designed the feature so that no one could find it, then removed it because it wasn't easy enough to find and therefore unpopular."
The parallel is striking: it's as if a restaurant removed its smoke detectors on the grounds that they hadn't been used.
A Commitment Swept Aside
The withdrawal is all the more problematic given that Meta had publicly committed to rolling out E2EE by default on Instagram — and not just as an option. Matthew Green, a cryptographer and professor at Johns Hopkins University, publicly denounced this turnaround on the social network X.
Let’s recall that in 2022, Meta itself commissioned a human rights impact assessment concluding that extending end-to-end encryption supports a range of fundamental rights. A few years later, this commitment has become nothing more than a "paper tiger," to borrow the phrase from 9to5Mac.
Troubling Timing with Meta AI and Advertising
What makes this withdrawal particularly suspect is its context. In December 2025, Meta confirmed that interactions with its Meta AI tools within private conversations could be used for targeted advertising. However, end-to-end encrypted messages cannot be exploited for this purpose, as Meta cannot technically read them.
Removing encryption thus radically changes the game: previously protected conversations become potentially exploitable for commercial purposes. While Meta has not publicly linked these two decisions, the timing is concerning. As 9to5Mac points out: "removing E2EE is a choice that turns out to be particularly convenient for Meta's business model, functioning as a high-speed data collection channel."
A Worrying Trend Beyond Instagram
Instagram's withdrawal does not occur in isolation. A few weeks earlier, on March 4, 2026, TikTok announced to the BBC that it would not introduce end-to-end encryption for its direct messages, arguing — paradoxically — that this technology would make users "less safe" by preventing security teams and police from reading messages.
In contrast, almost all other major messaging services — iMessage, WhatsApp, Signal, Google Messages, Facebook Messenger — already use E2EE or are moving in that direction. Snapchat uses it for photos and videos and is extending its deployment to text. Even Discord has announced its adoption for voice and video calls.
This simultaneous movement of Instagram and TikTok creates a dangerous precedent, according to observers. As Ben Lovejoy (9to5Mac) points out: "this creates an extremely troubling precedent for other tech companies that may take an equally lax approach to government pressures."
What Happens to Your Messages
Concretely, since May 8, 2026:
- Conversations previously end-to-end encrypted on Instagram are no longer so.
- Meta retains access to the content of direct messages, just as before the introduction of E2EE.
- Users wishing to export their encrypted conversations had to do so before the deadline.
- WhatsApp, also owned by Meta, still maintains E2EE enabled by default.
However, one may question the longevity of E2EE on WhatsApp. Nothing guarantees that Meta won't repeat a similar withdrawal on its flagship messaging service, especially as the company has begun integrating Meta AI into WhatsApp conversations — a use potentially incompatible with full encryption, although Meta claims to have designed a specific system to preserve the privacy of these AI interactions.
What Alternatives for Privacy-Conscious Users?
In light of this regression, users attached to the privacy of their communications can turn to:
- Signal: the gold standard for E2EE, open-source and ad-free.
- WhatsApp: still encrypted by default, but owned by Meta, raising questions about long-term trust.
- iMessage: end-to-end encrypted by default for exchanges between Apple devices.
- Threema: a paid Swiss alternative that requires no phone number.
A Revealing Setback
This episode illustrates a fundamental truth: privacy features on ad-funded platforms are never guarantees. They depend on business decisions that can be revised at any time. Meta had presented E2EE as a pillar of its strategy to protect human rights; it quietly abandoned it as soon as it conflicted with its economic objectives.
Cryptographer Matthew Green and many experts remind us that true privacy protection cannot rely solely on the goodwill of platforms. It requires binding regulatory frameworks — as partially provided by the European Digital Services Act (DSA) — and constant vigilance from users regarding the tools they choose to communicate.