← Latest briefing

Technology

Cybersecurity experts debate whether AI could make software vulnerabilities scarce for government surveillance

A theory that AI vulnerability discovery will starve the market for hacking exploits has drawn mixed responses from industry researchers and executives.

The short version

  • Cryptography professor Matthew Green proposed that AI automated patching could make software bugs so rare that governments lose access to target devices using zero-day exploits.
  • Cybersecurity experts disagree on the timeline and impact, with some warning of future political demands for built-in backdoors and others pointing out that AI-assisted coding also creates new vulnerabilities.
  • Industry researchers emphasize that complex bugs remain plentiful and modern hardware protections currently pose a more immediate barrier to offensive hacking than AI tools.

Key facts

  • Cryptography professor Matthew Green argued that AI-driven vulnerability discovery could drastically reduce software bugs, disrupting the current practice of governments purchasing exploit tools rather than demanding device backdoors.[TechCrunch]
  • Crowdfense CTO Paolo Stagno and former vulnerability researcher Luna Tong suggested that the current abundance of discoverable bugs is temporary and that finding exploits will eventually become significantly harder.[TechCrunch]
  • Electronic Frontier Foundation director Eva Galperin stated that offensive operations currently hold an advantage, citing vulnerabilities added through AI-assisted software development and slow patch deployment.[TechCrunch]
  • DarkCell founder Hamid Kashfi noted that complex vulnerabilities will persist and that many AI-discovered security flaws go unreported to software vendors.[TechCrunch]
  • Luta Security CEO Katie Moussouris estimated that devices remain far from bug-free and predicted intelligence agencies will not face severe exploit shortages before the next U.S. presidential election.[TechCrunch]

What remains uncertain

  • It remains uncertain whether AI defender tools will eliminate software bugs faster than AI coding tools introduce new vulnerabilities or how quickly software makers will deploy patches for AI-identified flaws.[TechCrunch]

Sources