AI May Reshape Governments’ Reliance on Hacking Tools

Artificial intelligence could eventually make software vulnerabilities harder to find and exploit, raising a fresh question for governments that use hacking tools for lawful surveillance. Cryptography professor Matthew Green argues that if AI enables companies to identify and patch bugs at unprecedented scale, law-enforcement and intelligence agencies may lose access to flaws used to compromise target devices.
The outcome could revive pressure for built-in access mechanisms, commonly described as backdoors. Green’s concern is not that this shift is imminent, but that software becoming materially less vulnerable could disrupt the balance that has developed around encryption and government access.
Encryption and the compromise around exploits
The “going dark” debate gained prominence in 2014, when then-FBI director James Comey argued that widespread encryption could obstruct investigations. Signal, WhatsApp and Apple’s iMessage expanded end-to-end encryption, while Apple encrypted device data by default. These changes made conventional interception of calls, messages and data substantially more difficult.
Governments did not abandon investigative access. Instead of requiring broad backdoors in consumer products, they invested in commercial hacking tools, spyware and purchases of unknown vulnerabilities, or zero-days. Green characterises this arrangement as an uneasy truce: people retain strong protections on their devices, while authorities can sometimes circumvent those protections against selected targets.
Will AI reduce or expand the supply of bugs?
Luna Tong, a researcher who has worked at companies that find vulnerabilities and develop exploits for governments, agrees with Green’s premise. Tong described the current abundance of bugs as a temporary “gold rush” and said vulnerabilities could become scarce again. An unnamed offensive-security researcher similarly warned that automated discovery may make it harder for human researchers to find flaws and could ultimately favour defenders.
Paolo Stagno, chief technology officer at zero-day supplier Crowdfense, said governments are unlikely to relinquish surveillance capabilities. He called the present requirement to exploit vulnerabilities the most democratic available system, while acknowledging that the model could come under strain if flaws become much harder to find.
Other practitioners dispute the expectation of scarcity. Hamid Kashfi, founder of DarkCell and an employee of AI cybersecurity startup Xbow, said that many AI-discovered vulnerabilities may never be reported to vendors. Several offensive-security researchers also argue that although AI may expose easy bugs faster, complex vulnerabilities valued by governments will persist and AI can help offensive teams find them.
Patching capacity remains decisive
Electronic Frontier Foundation cybersecurity director Eva Galperin adds a practical constraint: finding a vulnerability does not ensure it will be fixed quickly, or at all. Patching can be difficult, and AI-assisted “vibe-code” development may itself introduce more vulnerabilities. Katie Moussouris, founder and CEO of Luta Security, likewise said current phones and laptops remain far from bug-free, though a future decline in exploitable flaws could renew calls for backdoors.
For businesses, the implication is to use AI-assisted vulnerability discovery alongside disciplined remediation, secure development practices and strong encryption. Better detection only improves security when organisations can assess, patch and verify weaknesses without creating permanent access paths that reduce protection by design.

