The relationship between AI and zero-day exploits is moving to the centre of one of cybersecurity’s oldest arguments: how governments balance the need to hack criminals against everyone else’s right to privacy. A blog post by Matthew Green’s Cryptographic Engineering blog has reignited that debate, with the Johns Hopkins cryptographer positing that AI could eventually make software so secure that governments lose their primary route into criminal devices.
‘I’m concerned that AI is going to make software much too secure,’ Green wrote, warning that an unprecedented volume of bugs being patched by AI tools could leave law enforcement without exploitable footholds. Green, who has spent years watching the tension between encryption advocates and government surveillance demands, noted that entire continuous integration toolchains are being rebuilt to incorporate AI-based vulnerability scanning before a human reviewer ever touches the code.
The ‘Going Dark’ Problem, Revisited
The anxiety Green is describing has a long history. On 16 October 2014, then-FBI Director James Comey delivered his famous ‘Going Dark’ address at the Brookings Institution in Washington, D.C., warning that encryption was putting lawful surveillance on a collision course with public safety. Signal, WhatsApp, and Apple’s iMessage had just begun rolling out end-to-end encryption to mainstream users, rendering traditional wiretapping of calls and messages largely obsolete.
Comey returned to Congress in 2016, testifying before the Senate Judiciary Committee alongside Deputy Attorney General Sally Quillian Yates. Even then, his position was more nuanced than his critics acknowledged: in that Senate testimony, Comey called strong encryption ‘a key tool to secure commerce and trade, safeguard private information, promote free expression and association, and strengthen cyber security,’ even as he pressed for law enforcement access.
The San Bernardino attack in 2015, carried out by Syed Rizwan Farook and Tashfeen Malik and killing 14 people with 22 more injured, became the ‘going dark’ debate’s sharpest flashpoint. The FBI sought Apple’s help to break into Farook’s encrypted iPhone. A Department of Justice Inspector General report later found that the FBI had not exhausted its own internal capabilities or third-party vendors before rushing Apple to court, casting doubt on how severe the access problem truly was.
Since then, the uneasy resolution has been to sidestep the backdoor argument entirely. Rather than forcing technology companies to weaken their products, governments have funded a market in hacking tools and spyware capable of subverting device security from the outside. That market, as Green now argues, could dry up.
AI and Zero-Day Exploits: Where the Industry Splits
The cybersecurity community is far from unanimous on whether Green’s scenario will materialise. Luna Tong, a researcher with experience at firms that develop exploits for government clients, agreed with the premise: there is, she said, ‘a gold rush of bugs right now but it’s a temporary phenomenon and bugs will get scarce again soon.’
A second veteran of offensive security firms, speaking without attribution, said AI risks making human researchers obsolete, with defenders eventually gaining a structural advantage over the people paid to find and sell flaws.
Paolo Stagno, chief technology officer at Crowdfense, a company that develops, acquires, and sells zero-day vulnerabilities to government clients, framed the current arrangement differently. The process of requiring governments to exploit security flaws is, he said, ‘the most democratic system we have,’ though he acknowledged the status quo may not hold if bugs become genuinely hard to find. Crowdfense acquires zero-days across mobile, desktop, embedded, and enterprise platforms, and may also pick up recent vulnerabilities up to six months old for mobile targets, depending on their impact and exploitability.
Others pushed back on the scarcity thesis. Hamid Kashfi, founder of offensive security firm DarkCell and a researcher at AI cybersecurity startup Xbow, argued that ‘for every AI found and reported bug out there, there are probably 20 that are not reported.’ Researchers who choose not to disclose to vendors can still locate complex, high-value flaws that AI tools are unlikely to surface and patch automatically.
Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation, offered a bifurcated view. Offence holds the advantage now, she argued, partly because AI is adept at finding bugs and partly because ‘vibe-coding’ with AI tools is introducing new vulnerabilities faster than defenders can respond. She also noted that finding bugs does not guarantee they will be patched quickly, or at all, given the complexity of the patching process. Backdoor demands from authoritarian regimes will return regardless, Galperin added, because such governments always seek ‘exceptional access.’
Katie Moussouris, founder and chief executive of Luta Security, took the longest view. ‘We have some distance to go before the latest phones and laptops are completely bug free,’ she said, adding that a harder bug environment may eventually ‘trigger these pressures to build in backdoors.’ Her timeline: ‘I think we have at least until after the next presidential election before the intelligence community is materially hampered enough to push for backdoors in a serious way.’
That deadline, if Moussouris is right, gives the industry a window. Whether governments use it to accept a more secure internet or to legislate their way back in will define the next chapter of the encryption wars.
