Recent discussions among cryptographers, government cybersecurity experts, and encryption advocates suggest that advances in artificial intelligence might soon render sophisticated hacking tools far less available to governments than they are today. Tied to public commentary by Matthew Green, a Johns Hopkins cryptography professor, the concern is that AI-powered tools discovering and patching vulnerabilities at speed and scale could push law enforcement toward pushing for backdoors in software—threatening privacy and digital security as a consequence.
Why Security Flaws Might Become Rare
Green’s core argument centers on the possibility that AI models could revolutionize vulnerability discovery. With modern large language models (LLMs) rapidly improving, there’s early evidence that they can find bugs more efficiently than human teams. This could lead to software becoming much more bug-resistant, with fewer exploitable flaws that governments rely on for surveillance or investigations. Green worries that this shift might deprive law enforcement and intelligence agencies of lawful hacking capabilities. Such capabilities—often referred to as “zero-days”—are rare, valuable, and central to many state-level surveillance tools.
This scenario, Green predicts, could break the uneasy status quo where privacy protections like strong default encryption coexist alongside government investments in spyware or exploit-based tools. As bugs decline, pressure may build for encryption backdoors to restore access—posing a risk to the overall trustworthiness of digital infrastructure.
Different Viewpoints From Experts on Bug Scarcity
The article canvasses viewpoints from several experts in offensive cybersecurity. Some agree that we’re in a temporary “gold rush” of finding bugs—one likely to end as AI systems improve and bug discovery becomes harder. Others believe easy vulnerabilities will disappear first, but that complex bugs—those with deep, nontrivial exploits—will remain in demand and value, and AI itself can assist in finding or weaponizing those.
One researcher noted that for every bug AI systems find and report, many more still escape detection. Some zero-day marketplace professionals argue that the underlying protections being added to devices—secure boot, hardware-level security, tighter code-signing—matter more than AI in determining how easy or hard hacking becomes. Meanwhile, in settings where patching is slow or inconsistent, even if vulnerabilities are better known, they remain exploitable.
The idea of “going dark”—where law enforcement loses the ability to access communications or device data due to encryption—was once a concern raised in the 2010s as apps pushed strong end-to-end encryption and default device encryption. Green suggests we could be headed toward a darker version where not just encrypted channels—but software itself—becomes too secure for traditional state-level hacking to penetrate.
Backdoors, Authoritarian Pushes, and What Comes Next
Privacy defenders warn that decreasing bug abundance could fuel efforts to mandate backdoors—that is, built-in access points for law enforcement. Authoritarian governments in particular have long argued for “exceptional access,” even at the cost of weakening software built for general use. If vulnerabilities become truly scarce, that argument gains extra leverage.
At the same time, other experts argue that hardware protections and the increasing complexity of modern systems will still leave room for exploit-based tools, especially for high-value targets. And even in an AI-enhanced future, discovery and weaponization of zero-days will carry costs—technical, ethical, political—that may preserve some friction for misuse.
Some believe that any major impact from AI reducing government access will only materialize slowly. One cybersecurity leader speculated that serious policy moves to restore access—through backdoors or other legal measures—may not gain traction until after pivotal political moments, potentially after the next U.S. presidential election.
Context & Implications
Over the past decade, governments have increasingly leaned on exploit-based surveillance rather than seeking to weaken encryption directly. The belief that encryption itself obstructs investigations is longstanding; movements promoting “going dark” gained attention when messaging platforms implemented end-to-end encryption. At the same time, software ecosystems have steadily added defenses—secure boot, code-signing, hardware roots of trust—that make exploitation more difficult. AI’s rise adds a new vector.
This isn’t just a theoretical debate. AI tools already aid in finding vulnerabilities. Agencies and zero-day traders buy exploits. Device security models evolve. And so far, defenders are investing in patching, code audit frameworks, and hardware-level safeguards. What’s changing now is the scale and speed of AI-driven discovery—and the prospect that vulnerabilities could become rare enough to shift the legal and policy landscape around surveillance.
As software bugs potentially grow scarce thanks to AI, the core tension between privacy and public safety enters a new phase. The push for backdoors—mandated access—becomes more appealing to some governments seeking investigative tools. But introducing such backdoors could weaken security for everyone and open new attack surfaces. We’re entering a moment where societies will need to decide: demand perfect security and accept potential blind spots in crime-fighting, or preserve investigative tools and risk systemic vulnerabilities.