How AI Could Make Government Hacking Tools Harder to Use
AI could make software more secure by reducing vulnerabilities, creating new challenges for governments that rely on hacking tools for surveillance.
Artificial intelligence could reshape the long-running debate over government hacking and digital privacy by making software vulnerabilities harder to find. The issue gained attention after cryptography professor Matthew Green argued that advances in AI-powered security could eventually reduce the availability of software flaws that governments use for lawful hacking operations.
In a post on X and a longer analysis published on his Cryptography Engineering blog, Green raised concerns that AI systems could help developers create more secure software by identifying and fixing vulnerabilities at a much larger scale.
AI Could Change the Balance Between Cyber Defence and Surveillance
Governments have historically relied on the discovery of security weaknesses, including zero-day vulnerabilities, to access devices used by criminals and intelligence targets. At the same time, privacy advocates have argued that stronger encryption is necessary to protect ordinary users from unauthorised access.
The debate became widely known through the “going dark” discussion, which focused on law enforcement concerns that widespread encryption could make investigations more difficult. The FBI has previously discussed concerns about the impact of encryption on access to digital evidence.
Since then, governments have continued investigations using a combination of traditional methods and targeted hacking tools, while technology companies have expanded security protections such as end-to-end encryption and stronger device protections.
Researchers Debate Whether AI Will Reduce Zero-Day Availability
Green’s argument centres on the possibility that AI systems could make it faster and more effective for defenders to find software vulnerabilities. If companies can discover and fix large numbers of bugs before attackers or government researchers exploit them, fewer exploitable flaws may become available.
Some cybersecurity researchers agree that AI could eventually make vulnerabilities more difficult to obtain. Luna Tong, a researcher with experience in companies that discover vulnerabilities and develop exploits for government customers, said the current availability of bugs may be temporary as AI improves security research.
Other experts disagree with the idea that vulnerabilities will disappear. They argue that while AI may help identify easier bugs, complex vulnerabilities in modern systems are likely to remain valuable and difficult to eliminate.
Hamid Kashfi, founder of offensive security firm DarkCell and an employee at AI cybersecurity startup Xbow, said many vulnerabilities discovered by researchers may never become publicly known or reported to software vendors.
Security Experts Warn Backdoor Debate Could Return
Paolo Stagno, chief technology officer at vulnerability research company Crowdfense, said governments are unlikely to abandon surveillance capabilities. He described the current system of using security flaws to access targeted devices as a more limited alternative to requiring built-in access mechanisms.
Some researchers said the bigger challenge may come from stronger security protections already built into modern devices rather than AI alone. Advanced hardware protections and improved software defences have made certain systems more difficult to compromise.
Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation, said AI has advantages for both attackers and defenders. She also noted that discovering more vulnerabilities does not necessarily mean companies will patch them quickly, as fixing security issues can be complex.
Katie Moussouris, founder and CEO of Luta Security, said that current devices still contain vulnerabilities and that the industry is not close to achieving completely secure phones and computers.
“There will be some point at which finding bugs will be much harder and that may trigger these pressures to build in backdoors,” Moussouris said.
Research into AI-assisted vulnerability discovery continues to shape discussions around cybersecurity. A study published by USENIX has previously examined automated approaches to finding software flaws, reflecting the broader effort to use technology to improve security testing.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0