AI Bug-Hunting May Force Governments Back to Encryption Backdoors
As AI tools find and patch vulnerabilities faster, law enforcement could lose the exploits they rely on for surveillance—reviving demands for built-in access.
The paradox of AI-hardened security
Cryptography professor Matthew Green has sparked debate in the cybersecurity community with a provocative thesis: artificial intelligence may soon make software so secure that law enforcement loses its ability to lawfully hack criminal targets—potentially forcing a return to demands for encryption backdoors.
In an August blog post that went viral among security professionals, Green argued that as AI tools become better at identifying and helping patch security vulnerabilities at scale, the exploitable bugs that government agencies depend on for surveillance will become increasingly scarce. TechCrunch first reported on the reactions from industry experts.
Why it matters
This debate cuts to the heart of a decade-long tension between privacy and surveillance. Since 2014, when then-FBI director James Comey warned about "going dark" due to encryption, governments have relied on purchasing exploits rather than demanding backdoors. If that middle ground disappears, the pressure to weaken security by design could return—affecting billions of devices and undermining the privacy protections that encryption currently provides.
The current truce
For years, an uneasy balance has existed. After companies like Apple, Signal, and WhatsApp rolled out end-to-end encryption and device-level protections, governments shifted strategy. Rather than forcing backdoors into products, intelligence and law enforcement agencies invested in commercial spyware and exploit acquisition—buying unknown vulnerabilities (zero-days) from specialized firms to break into targets' devices.
This arrangement allowed both sides to claim partial victory: citizens got strong encryption, and authorities maintained surveillance capabilities through technical means.
Industry voices divided
Reactions from offensive security professionals reveal no consensus. Luna Tong, a researcher with experience at exploit development firms, agreed with Green's assessment, calling the current abundance of bugs "a temporary phenomenon."
Paolo Stagno, chief technology officer at zero-day broker Crowdfense, acknowledged that "no state will throw away the possibility of surveillance" and warned the current system may not survive if bugs become too scarce.
But others pushed back. Hamid Kashfi of DarkCell and Xbow argued that while AI might find easy bugs faster, complex vulnerabilities valuable to governments won't disappear. Two current zero-day researchers told TechCrunch they're more concerned about new device security protections than AI-driven bug detection.
Eva Galperin of the Electronic Frontier Foundation noted that offense currently has the advantage, partly because AI-assisted coding may actually introduce new vulnerabilities. She also pointed out that finding bugs doesn't guarantee they'll be patched quickly—or at all.
Timeline uncertainty
Katie Moussouris, founder of Luta Security and a veteran of vulnerability disclosure programs, said modern devices still have "some distance to go before" becoming bug-free. She estimated that serious pressure for backdoors likely won't materialize "until after the next presidential election," though she acknowledged the inflection point will eventually arrive.
The debate reflects genuine uncertainty about AI's trajectory in cybersecurity. Early data suggests large language models are improving at vulnerability detection, but whether they'll create a defender's advantage or simply shift the exploit marketplace remains an open question with profound implications for privacy and surveillance policy.
Details of the debate and expert reactions were first reported by TechCrunch.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call
