
Cryptography professor Matthew Green has sparked a fresh debate about how AI could make it harder for governments to use hacking tools, arguing that a world in which software bugs become much scarcer could weaken one of law enforcement and intelligence agencies’ most important ways of getting into targets’ devices. In Green’s view, if AI helps companies and defenders find and patch vulnerabilities faster than attackers can exploit them, governments may eventually lose access to the flaws they have relied on for lawful hacking.
Matthew Green’s warning about a future with fewer bugs
Green, who has long followed the tension between government hacking and strong encryption, raised the issue in an X thread and a longer blog post that circulated widely in cybersecurity circles earlier in August. His central concern was blunt: “I’m concerned that AI is going to make software much too secure,” he wrote, warning that the U.S. government may lose access to security flaws it needs in order to surveil targets.
The argument matters because it reframes a familiar policy fight. For years, authorities have complained that encryption can limit access to communications and device data, while privacy advocates have argued that weakening security for everyone creates unacceptable risk. Green’s point is that AI may shift that balance again, not by undermining encryption directly, but by reducing the number of exploitable bugs that make device hacking possible in the first place.
From “going dark” to an uneasy truce
The debate has deep roots. In 2014, the phrase “going dark” entered the mainstream as then-FBI director James Comey warned that encryption could prevent authorities from listening in on conversations or accessing data on devices. Around the same period, services including Signal, WhatsApp, and Apple’s iMessage rolled out end-to-end encryption, while major device makers began encrypting more data by default.
That made traditional real-time wiretapping far harder. But law enforcement and intelligence agencies did not stop gathering evidence; instead, as Green describes it, the field settled into an “uneasy kind of truce.” Rather than require built-in backdoors, governments increasingly spent money on hacking tools and spyware designed to defeat device security in specific cases.
That model has allowed both sides to claim some ground: privacy protections for ordinary users, and targeted access for investigators pursuing serious suspects. Green’s concern is that AI could disturb that equilibrium by making bugs harder to find at scale.
How AI could change the economics of exploitation
Supporters of Green’s thesis say the key issue is scale. Large language models and related tools are becoming better at spotting security weaknesses faster than humans can, and that may push vendors to patch software more quickly and more thoroughly. If that happens, the supply of usable vulnerabilities could shrink, especially the kind that are easiest to weaponize.
In Green’s scenario, that scarcity would not make lawful hacking disappear entirely. Instead, it could make it much more difficult for governments to obtain the access they want through legal warrants and approved surveillance operations. If the loopholes are fewer and harder to find, authorities may renew calls for exceptional access built into products from the start.
What the offensive security industry says
Not everyone agrees that AI will leave governments empty-handed. TechCrunch spoke with privacy and cybersecurity experts, as well as people who have worked on hacking tools for governments. Their views split in several directions.
- Luna Tong, a researcher who has worked at companies that find bugs and develop exploits for governments, agreed with Green and said there is a “gold rush of bugs right now but it’s a temporary phenomenon and bugs will get scarce again soon.”
- An offensive security researcher with more than a decade of experience said AI could make human security researchers obsolete, with defenders eventually gaining the advantage over offensive teams. The person asked not to be named.
- Paolo Stagno, chief technology officer at Crowdfense, said, “It’s clear that no state will throw away the possibility of surveillance,” and argued that requiring governments to exploit flaws is currently the “most democratic system we have.”
Others in the industry were less worried. Three current offensive cybersecurity workers and one former researcher argued that AI may make easy bugs easier to find, but that the more complex and valuable bugs governments want will not disappear. They also pointed out that AI can assist the researchers who sell exploits, rather than only helping defenders.
Hamid Kashfi, founder of offensive security firm DarkCell and also a researcher at the AI cybersecurity startup Xbow, said that “for every AI found and reported bug out there, there are probably 20 that are not reported.” His point was that even if some vulnerabilities are quickly disclosed and patched, others with higher value or more complexity may still be discovered and kept for exploit development.
Defenders, patches and the limits of AI
Two researchers who make a living finding bugs for zero-day firms told TechCrunch they are more concerned about the new security protections built into modern devices than about AI itself. In other words, the hardening of phones and laptops may matter as much as, or more than, the rise of automated bug hunting.
Eva Galperin, cybersecurity director at the Electronic Frontier Foundation and an expert on government spyware, said offense currently has the edge because AI is effective at discovering bugs, while “vibe-code” development with AI tools may be introducing new vulnerabilities. But she also warned that finding bugs does not mean they will be patched quickly, or patched at all, since remediation can be slow and difficult.
Galperin added that authoritarian governments will continue to seek “exceptional access,” suggesting the policy pressure for backdoors is unlikely to disappear even if the technical landscape changes.
Why the backdoor debate could return
Katie Moussouris, founder and CEO of Luta Security, said there is still a long way to go before the latest phones and laptops are “completely bug free.” She acknowledged, however, that there will likely be a point when finding bugs becomes much harder, and that could reignite demands for built-in access.
“I think we have at least until after the next presidential election before the intelligence community is materially hampered enough to push for backdoors in a serious way,” Moussouris said. That timeline suggests the issue may not be immediate, but it also shows how AI is already shaping expectations about the future of surveillance, vulnerability research, and device security.
For now, the debate remains unsettled. AI may reduce the number of flaws that governments can use to break into devices, or it may simply change who finds those flaws first. Either way, the longstanding compromise between security, privacy and lawful access is likely to face renewed pressure.
Source: Original report
Was this helpful?
Explore more: Application Audit & Review More Cybersecurity Tech News
Last Modified: September 1, 2026 at 1:51 am
3 views

