Could AI Starve Governments of the Bugs They Need to Hack Targets?
As large language models promise to accelerate vulnerability discovery and patching, a debate is brewing over whether law enforcement will lose its most democratic surveillance tool and demand backdoors instead.

The Paradox of Perfect Security
Cryptography professor Matthew Green put forward an uncomfortable proposition this August: artificial intelligence might soon make software so secure that governments lose their ability to lawfully surveil criminal targets. The irony is sharp. For years, privacy advocates have fought for stronger encryption and fewer software vulnerabilities. Now, according to Green, the very tools that could deliver that vision may trigger the outcome advocates fear most: mandatory backdoors in consumer devices.
At DailyTechWire, we've tracked the encryption wars since 2014, when the FBI popularized the "going dark" narrative to describe how end-to-end encryption in Signal, WhatsApp, and iMessage was blinding law enforcement. Apple's decision to encrypt iPhone data by default forced a standoff that never quite resolved. Instead, an informal truce emerged. Governments stopped demanding backdoors and began buying exploits, zero-day vulnerabilities that let them break into devices without vendor cooperation. Green's thesis is that AI-driven bug discovery will collapse that truce.
The argument rests on a straightforward chain of logic. Large language models are demonstrating accelerating capability in automated vulnerability research. Companies that deploy these systems at scale will patch flaws faster and more comprehensively than ever before. As the reservoir of exploitable bugs shrinks, governments that rely on purchased zero-days to conduct surveillance will face a supply crisis. Faced with losing access entirely, they will return to demanding legislated backdoors, the very outcome that the exploit market was supposed to prevent.
Voices From the Zero-Day Market
The people who find, broker, and sell vulnerabilities to government clients are split on whether Green's scenario will materialize. Luna Tong, a researcher with experience at two firms specializing in offensive capabilities for state clients, described the current environment as a "gold rush of bugs" but warned the abundance is temporary. Another veteran researcher with more than a decade in offensive security expressed concern that AI will render human bug hunters obsolete, shifting the advantage permanently to defenders. Both asked for discretion, reflecting the sensitivity of work that sits at the intersection of national security and commercial espionage.
Paolo Stagno, chief technology officer at Crowdfense, a broker that acquires and sells zero-days to governments, acknowledged that requiring states to exploit security flaws rather than mandate access is "the most democratic system we have." But he stopped short of guarantees. If bugs become prohibitively scarce, Stagno suggested, the political pressure for exceptional access will return.
Not everyone sees scarcity on the horizon. Hamid Kashfi, founder of offensive security firm DarkCell and an engineer at AI cybersecurity startup Xbow, argued that for every AI-discovered bug that gets reported and patched, roughly twenty remain undisclosed. Researchers who prioritize profit over disclosure can still locate complex, high-value vulnerabilities. The most sophisticated exploits, those that chain multiple flaws or target obscure subsystems, are unlikely to be automated away in the near term.
Two active zero-day researchers told us they are less worried about AI than they are about modern hardware mitigations. Memory tagging extensions, pointer authentication, and hypervisor-based integrity checks have made contemporary devices significantly harder to compromise, regardless of how many bugs are discovered. In their view, the arms race is tilting toward defense not because of AI, but because of silicon-level protections that were years in the making.
The Defender's Dilemma
Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation and a longtime observer of government spyware deployments, sees the offense holding an edge today. She attributes this to two trends: AI's growing proficiency at surfacing bugs, and an explosion of new vulnerabilities introduced by developers using AI-assisted coding tools. The latter phenomenon, sometimes called "vibe-code," produces software that compiles and runs but often lacks rigorous input validation or memory safety.
Yet Galperin cautioned that discovery does not equal remediation. Finding more bugs does not guarantee they will be patched quickly, or at all. Patching requires coordination across vendors, carriers, and enterprise IT departments, a process that can stretch months or stall indefinitely for legacy systems. Even if AI accelerates detection, the organizational inertia around deployment means many flaws will remain exploitable long after disclosure.
Galperin also predicted that authoritarian regimes will push for "exceptional access" regardless of technical realities. For governments that prioritize control over privacy, the debate is less about feasibility and more about political will. If democracies resist backdoors, autocracies may simply mandate them and accept the security trade-offs.
How Much Time Is Left?
Katie Moussouris, founder and CEO of Luta Security and a veteran of vulnerability disclosure programs at Microsoft and other firms, argued that the industry has "some distance to go" before modern devices approach bug-free status. The complexity of contemporary operating systems, the proliferation of third-party libraries, and the introduction of new attack surfaces through connected peripherals and cloud integrations all ensure a steady supply of flaws for the foreseeable future.
Moussouris acknowledged that a tipping point will eventually arrive, one at which finding exploitable bugs becomes prohibitively difficult. When that happens, she expects renewed political pressure for backdoors. But she placed that inflection point further out than Green's warning implied. "I think we have at least until after the next presidential election before the intelligence community is materially hampered enough to push for backdoors in a serious way," Moussouris said.
Her timeline hinges on two assumptions: that AI-driven patching will take years to reach comprehensive deployment, and that the current stockpile of unpatched vulnerabilities in deployed devices will sustain offensive operations in the interim. Both assumptions are contestable. If LLM-assisted code review becomes standard practice in major software vendors' CI/CD pipelines within the next eighteen months, the depletion curve could steepen faster than Moussouris expects.
The Truce That Nobody Agreed To
The current equilibrium, in which governments buy exploits rather than demand access, was never formalized. It emerged from a combination of industry resistance, court rulings, and the practical availability of commercial spyware. Companies like NSO Group, Candiru, and others built a lucrative market supplying tools that could bypass encryption without requiring legislative change. That market's existence defused political momentum for backdoor mandates, but it also created a shadow industry with minimal oversight and frequent abuse.
Green's concern is that AI will eliminate the safety valve that market provided. If exploits become scarce or prohibitively expensive, governments will be forced to choose between accepting reduced surveillance capability or legislating access. History suggests they will choose the latter. The FBI's 2016 legal battle with Apple over the San Bernardino iPhone demonstrated how quickly technical constraints can escalate into constitutional confrontations.
The question is whether the offensive security industry can adapt quickly enough to maintain supply. Some researchers believe AI will become a force multiplier for human analysts, allowing them to focus on deeper, more creative exploitation techniques while automating the grunt work of fuzzing and static analysis. Others see a future in which the most valuable bugs are those that exploit not code, but the seams between systems: supply chain compromises, social engineering, and protocol-level attacks that no amount of patching can eliminate.
What Comes After the Gold Rush
The debate Green sparked reflects a deeper uncertainty about whether security is converging or diverging. Optimists see AI as a tool that will finally bring memory-safe languages, formal verification, and continuous security testing to mainstream software development. Pessimists worry that the same automation will empower attackers to discover and weaponize flaws faster than defenders can respond.
Both may be right. The next five years will likely see a bifurcation. Consumer devices from major vendors, which have the resources to deploy AI-assisted security tooling at scale, may become significantly harder to compromise. But the long tail of embedded systems, IoT devices, and legacy enterprise software will remain vulnerable, creating a two-tier security landscape. Governments that once relied on iPhone exploits may shift focus to routers, smart home devices, and industrial control systems, where patching is rare and lifespans are measured in decades.
The political dimension is harder to predict. If a high-profile terrorism case hinges on encrypted data that investigators cannot access, public opinion may swing toward exceptional access regardless of technical objections. Conversely, if a mandated backdoor is exploited by a foreign adversary or criminal group, the backlash could entrench opposition for another decade.
What is clear is that the informal truce Green described was always fragile. It depended on a Goldilocks condition: enough bugs to enable government operations, but not so many that software becomes unusable. AI threatens to end that equilibrium, not because it will make software perfectly secure, but because it will force both sides to articulate what they were always avoiding: how much insecurity we are willing to tolerate, and who gets to decide.


