Cryptography professor Matthew Green sparked renewed debate in the cybersecurity community in August with a viral post arguing that artificial intelligence could soon eliminate the software bugs that governments rely on to lawfully hack into criminal devices. Green, a longtime observer of the encryption-versus-surveillance divide, suggested that AI-assisted vulnerability discovery might make software so secure that U.S. law enforcement and intelligence agencies lose their ability to conduct court-authorized hacks. He warned that the trend could push the government to demand backdoors into consumer devices, weakening security for everyone.

The debate echoes the 2014 "going dark" panic, when then-FBI director James Comey argued that encryption would block authorities from accessing communications and data. Around that time, end-to-end encryption rolled out widely in apps such as Signal, WhatsApp, and Apple's iMessage, and Apple began encrypting device data by default. Since then, an uneasy truce has held: governments avoided demanding backdoors, instead purchasing hacking tools and spyware to break into targets. Green now argues that AI could shatter that truce by making bugs scarce.

Several experts offered mixed reactions to Green's thesis. Luna Tong, a researcher who previously worked at two firms that develop exploits for governments, agreed that the current abundance of bugs is temporary and that scarcity will return. An unnamed offensive security veteran with over a decade of experience said AI could make human researchers obsolete and give defenders the edge. Paolo Stagno, chief technology officer at Crowdfense, a company that buys and sells unknown vulnerabilities known as zero-days, said no state will give up surveillance capabilities, but the current system of requiring governments to use exploits may not survive if bugs vanish.

Others pushed back against the doomsday scenario. Hamid Kashfi, founder of offensive security firm DarkCell and an employee at AI cybersecurity startup Xbow, argued that for every AI-found and reported bug, there are many more that go unreported, and complex bugs will remain findable for researchers who choose not to disclose them. Two current zero-day hunters expressed more concern about new device security protections than about AI. Eva Galperin, cybersecurity director at the Electronic Frontier Foundation, said offense still has the advantage, partly because AI tools also introduce new bugs through rapidly written code, but she added that authoritarian governments will always push for exceptional access regardless of bug availability.

Katie Moussouris, founder and CEO of Luta Security and a veteran of patching processes at major companies, cautioned that the latest phones and laptops remain far from bug-free. She predicted that a future point where bug-finding becomes much harder could trigger renewed pressure for backdoors. Moussouris estimated that the intelligence community is unlikely to be materially hampered before the next presidential election, giving the industry time before serious backdoor demands emerge.

More cybersecurity news from TechManNews.