The most interesting security policy debate of the year started with a cryptography professor asking what happens if AI makes bugs too rare for governments to hack criminals. It sounds abstract. It isn’t. According to TechCrunch, Johns Hopkins professor Matthew Green published a thread and blog post arguing that AI-assisted vulnerability discovery could eventually leave law enforcement with no practical way to break into suspect devices, pushing governments back toward demanding encryption backdoors.
Green’s argument rests on a fragile equilibrium that has held for roughly a decade. When apps like Signal, WhatsApp, and iMessage rolled out end-to-end encryption around 2014, the FBI warned loudly about “going dark,” the idea that encryption would make surveillance impossible. But that crisis never fully materialized. Governments adapted by buying commercial spyware and zero-day exploits from firms like NSO Group and Crowdfense, tools that subvert device security without requiring tech companies to weaken their products. Backdoors stayed off the table. The market for exploits filled the gap.
Green’s worry is that AI closes that gap. If large language models get good enough at finding security vulnerabilities at scale, companies can patch bugs faster than researchers find them. Fewer exploitable bugs means fewer tools for governments to buy. And when governments lose those tools, history suggests they come back to legislators asking for mandated backdoors. That makes everyone’s devices less secure, not just criminals’ devices.
The people who actually build and sell these tools are split. Luna Tong, a researcher with experience at major exploit-development firms, agrees with Green, calling the current moment a “gold rush of bugs” that won’t last. Paolo Stagno, CTO at Crowdfense, called the current exploit-market model “the most democratic system we have” but acknowledged it may not survive if bugs become genuinely scarce.
Others are less convinced. Hamid Kashfi, founder of DarkCell and a researcher at AI security startup Xbow, argued that for every AI-discovered bug that gets reported, around 20 don’t get disclosed at all. Researchers with financial incentives to sit on vulnerabilities will keep doing so. And several active zero-day researchers told TechCrunch they’re more worried about new hardware security protections than about AI outpacing them.
Eva Galperin at the EFF raised a point that cuts both ways: finding bugs faster doesn’t mean patching them faster. Patching is slow, organizational, and often political. So even in a world where AI surfaces thousands of vulnerabilities, many will sit unpatched long enough to remain useful. She also noted that vibe-coded AI-assisted development is actively introducing new bugs, which partially offsets any defensive gains.
Katie Moussouris, CEO of Luta Security and one of the more measured voices in this space, put a rough timeline on it. She thinks the intelligence community has at least until after the next U.S. presidential election before the bug shortage becomes severe enough to restart serious backdoor lobbying. That’s not forever. Developers building secure products and founders in the security space should treat this debate as an early signal, not a distant hypothetical.




