How AI could make government hacking tools scarce
Cryptography professor Matthew Green warns that AI-driven software security could eliminate software bugs, making it harder for governments to legally hack targets.

Stock photo for illustration only, not from the actual event
- Professor Matthew Green warns that AI could make software too secure by eliminating bugs.
- This security boost could prevent law enforcement from accessing targets via hacking tools.
- Cybersecurity experts remain divided on whether AI will truly render bugs scarce.
- The shift may eventually pressure governments to demand built-in system backdoors.
In August 2026, cryptography professor Matthew Green published a controversial thread on X and a comprehensive blog post that quickly went viral across the cybersecurity community. Green raised a provocative hypothesis: What if artificial intelligence makes software bugs so scarce that law enforcement and intelligence agencies can no longer lawfully hack criminals?
Green expressed deep concern that AI is rendering software excessively secure, warning that the U.S. government could lose access to critical security flaws needed for surveillance as tech companies patch unprecedented volumes of bugs. This debate echoes concerns raised back in 2014 by then-FBI director James Comey regarding the challenges authorities faced due to the widespread adoption of end-to-end encryption.

Stock photo for illustration only, not from the actual event
Over the years, governments managed to bypass encryption by purchasing specialized hacking tools and spyware from private firms—a dynamic Green describes as an uneasy truce. However, that truce faces imminent disruption as large language models become increasingly efficient at identifying security vulnerabilities at scale, theoretically enabling companies to build systems that are largely resistant to attacks.
Additional Context: The ongoing battle over system backdoors highlights the eternal tension between national security and digital privacy. If AI automates bug discovery and patching to a degree where zero-day exploits dry up, law enforcement agencies may lose their primary method of lawful intercept.
Paolo Stagno, chief technology officer at vulnerability broker Crowdfense, noted that no state will ever abandon surveillance capabilities entirely, calling the current exploitation-based system the most democratic mechanism available. Yet, he acknowledges this status quo might collapse if bugs become practically unfindable.

Stock photo for illustration only, not from the actual event
Conversely, other industry veterans hold differing views. Hamid Kashfi, founder of offensive security firm DarkCell, argued that for every bug found and reported by AI, numerous unreported vulnerabilities remain. Meanwhile, Eva Galperin of the Electronic Frontier Foundation pointed out that finding bugs does not guarantee swift patching, suggesting authoritarian regimes will inevitably renew their demands for exceptional access.
Source: TechCrunch
Found something wrong in this article? Report an issue with this article
Comments
Leave a Comment