Artificial intelligence could make software so secure that governments struggle to hack suspects lawfully, prompting renewed demands for built-in access to encrypted devices, cybersecurity experts have warned.
The possibility was raised by cryptography professor Matthew Green in a widely circulated post on X and a longer essay earlier this month. He argued that increasingly capable AI systems could identify software flaws at a scale that allows companies to fix vulnerabilities faster than they can be exploited.
That could undermine the informal balance that has developed between privacy and surveillance. Rather than forcing technology companies to create permanent backdoors, governments have generally bought or commissioned hacking tools that exploit weaknesses in phones, computers and online services.
“I’m concerned that AI is going to make software much too secure,” Green wrote, warning that the US government could lose access to the flaws needed to monitor targets.
AI and the future of government hacking
The issue follows years of warnings from law enforcement that widespread encryption has made it harder to investigate serious crimes. The phrase “going dark” became prominent in 2014, when then-FBI director James Comey said encryption risked preventing authorities from accessing messages and data.
Services including Signal, WhatsApp and Apple’s iMessage subsequently adopted end-to-end encryption for large numbers of users. Apple also made data stored on its devices encrypted by default, making access to an iPhone protected by a strong passcode considerably more difficult.
Authorities have nevertheless continued to obtain evidence by compromising suspects’ devices, often using spyware and so-called zero-day vulnerabilities — previously unknown security flaws for which no patch exists.
Green’s argument is that advances in large language models could alter that arrangement. If automated systems discover vulnerabilities quickly and software companies repair them in large numbers, the supply of exploitable weaknesses could shrink.
Luna Tong, a researcher who has worked for companies involved in finding bugs and developing exploits for government customers, said the industry was experiencing a temporary abundance of vulnerabilities.
“There is a gold rush of bugs right now but it’s a temporary phenomenon and bugs will get scarce again soon,” Tong said.
Another researcher with more than a decade in offensive security said AI could make it increasingly difficult for human specialists to compete in finding vulnerabilities. The researcher, who was not named, said defenders could eventually gain the advantage.
But people working in the market for government hacking tools disputed the idea that AI would eliminate the most valuable flaws. They said basic bugs would probably become easier to locate, while sophisticated weaknesses in modern devices would remain difficult to find and could continue to command high prices.
Hamid Kashfi, founder of offensive security company DarkCell and an employee of AI cybersecurity firm Xbow, said the number of vulnerabilities discovered by AI would not necessarily reflect the number that remained hidden.
“For every AI found and reported bug out there, there are probably 20 that are not reported,” Kashfi said, arguing that researchers could continue to uncover complex flaws without disclosing them to software manufacturers.
Paolo Stagno, chief technology officer at Crowdfense, which develops, acquires and sells zero-days to governments, said states would not voluntarily abandon surveillance capabilities.
“It’s clear that no state will throw away the possibility of surveillance,” Stagno said. He described the current model, in which authorities must exploit a vulnerability to gain access, as “the most democratic system we have”.
That model could come under pressure if vulnerabilities become substantially harder to obtain. Stagno said the resulting debate could revive demands for exceptional access to encrypted products.
Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation, said AI was currently benefiting offensive researchers as well as software defenders. She pointed to both the ability of AI tools to identify flaws and the growing number of weaknesses that can be introduced when developers rely heavily on automated “vibe-code” systems.
However, Galperin said identifying vulnerabilities did not guarantee they would be fixed quickly, or at all. Patching can be technically complicated, particularly where software forms part of a wider system, leaving some weaknesses available for exploitation.
Katie Moussouris, founder and chief executive of Luta Security, said the latest phones and laptops were still far from being completely free of bugs.
“There will be some point at which finding bugs will be much harder and that may trigger these pressures to build in backdoors,” she said.
Moussouris predicted that the intelligence community would not be sufficiently affected to press seriously for backdoors until after the next US presidential election.
Privacy campaigners have long argued that deliberately weakened encryption would expose ordinary users as well as criminal suspects. The debate over AI and government hacking therefore risks reopening the same conflict: whether authorities should retain exceptional access to technology, or whether stronger security for everyone must take precedence.
