In August, cryptography professor Matthew Green sparked debate within the cybersecurity community by suggesting that advancements in artificial intelligence (AI) could render software significantly more secure, potentially undermining governments’ ability to lawfully hack into criminals’ devices. Green argued that as AI tools become more adept at identifying and patching software vulnerabilities at scale, the pool of exploitable bugs—upon which law enforcement and intelligence agencies rely for surveillance—may dwindle, forcing governments to reconsider their reliance on such exploits.
The article highlights the historical context of the “going dark” debate, wherein law enforcement has long contended that strong encryption hampers their ability to monitor criminal activity. In response, governments have increasingly invested in purchasing hacking tools and spyware to circumvent encryption, rather than advocating for backdoors. Green posits that AI-driven improvements in software security could disrupt this “truce,” as the scarcity of vulnerabilities might compel governments to once again push for systemic backdoors, thereby compromising the security of all devices. However, the article also presents counterarguments from cybersecurity experts and practitioners who believe that while AI may make certain types of bugs easier to find and patch, more complex and valuable vulnerabilities will persist, and AI can also assist researchers in discovering these high-value exploits for government clients.
Experts offer varied perspectives on the timeline and implications of this potential shift. Some, like Luna Tong and an unnamed researcher with extensive experience in offensive security, align with Green’s concerns, predicting a future where bugs become scarce and backdoor demands resurge. Others, including Hamid Kashfi and current zero-day researchers, argue that complex vulnerabilities will remain elusive to automated tools, and that AI can enhance, rather than diminish, the effectiveness of human researchers in finding valuable exploits. Additionally, figures such as Eva Galperin and Katie Moussouris suggest that while AI may accelerate bug discovery, the patching process remains complex and uneven, and that pressures for backdoors may intensify once finding vulnerabilities becomes sufficiently challenging. Moussouris even speculates that significant governmental pushback on backdoors may not materialize until after the next U.S. presidential election.