AI could create a problem governments have spent years trying to avoid: fewer undiscovered software vulnerabilities available to exploit.
Governments have increasingly turned to hacking tools when encryption prevents them from accessing a suspect’s phone or computer, creating a market where companies and researchers hunt for vulnerabilities that can be turned into exploits. But that market has an obvious dependency: there must be exploitable bugs left to find.
Security cryptographer and professor Matthew Green published an analysis noting that AI could start attacking that dependency from the other side. If technology companies can use AI to continuously search, identify, and patch vulnerabilities before attackers can weaponize them, the supply of useful exploits could shrink — not because encryption got stronger, but because the software itself became harder to break.
That possibility would have consequences well beyond ordinary cybercrime. Agencies that rely on commercial hacking tools could find themselves competing with the same AI systems that vendors use to eliminate the vulnerabilities those tools depend on.
What is Green’s argument about
The emergence of stronger encryption has pushed governments to exploit vulnerabilities in devices or their software instead.
That has made previously unknown vulnerabilities valuable commodities. Governments can develop exploits themselves or buy them from researchers and commercial hacking firms, but the entire market depends on one thing: vulnerabilities remaining undiscovered long enough to be exploited.
Green argues that AI could start taking that advantage away.
The point is not that AI will eliminate software vulnerabilities. It is that AI could make the window between a vulnerability existing and someone discovering it much shorter, reducing the supply of useful bugs available to offensive researchers.
If that happens across widely used software, Green argues, governments could eventually find it harder to obtain the exploits they use to access protected devices, creating a new problem he says is similar to “Going Dark.”
AI vulnerability research is already moving into production
Green’s argument would be easier to dismiss as speculation if AI-assisted vulnerability discovery were still largely experimental.
Recent work from Microsoft and Google suggests it is already becoming a practical part of how major software companies find and fix security flaws.
Microsoft’s July Patch Tuesday is one example, with the company using AI-assisted tools to help identify and fix 570 flaws. Google has gone further with Chrome, using AI to find vulnerabilities and fix a staggering 1,072 security bugs, including one sandbox escape flaw that had existed for 13 years.
Those examples do not show that governments are already running out of usable exploits. They do, however, support the underlying premise: software vendors are gaining automated tools that can search for vulnerabilities at a scale and speed that would have been difficult to sustain manually.
Must-read security coverage
- UK Police Convicts Pair in £5.5 Billion Bitcoin Launder Case
- Blackpoint Cyber vs. Arctic Wolf: Which MDR Solution is Right for You?
- How GitHub Is Securing the Software Supply Chain
- 8 Best Enterprise Password Managers
A possible second-order effect
If AI makes useful vulnerabilities harder for governments to obtain, the next question is what they do when hacking is no longer a reliable way around encryption. One possible answer is a return to exceptional access: requiring technology companies to provide a government-only backdoor to otherwise protected data or devices.
The idea has been debated for years. The 2016 case between the FBI and Apple put that into the spotlight when the FBI demanded that Apple grant it access to the iPhone of a shooting suspect, a request Apple declined, citing the security consequences of adding a backdoor to its services.
Green’s argument could give that debate a new trigger. If governments begin losing a technical route into encrypted devices because the vulnerabilities they depend on are being found and patched faster, pressure for companies to provide an alternative route could increase.
With governments increasingly testing the limits of their influence over how technology companies design their services, renewed pressure could create an interesting turn of events between both parties.
The dual-headed nature of AI in security
There is, however, a problem with assuming AI will give defenders the upper hand: attackers get the technology too. If AI enables software makers to find and close vulnerabilities before they can be exploited, attackers can use the same technology to search for weaknesses that defensive systems have missed.
That could turn vulnerability discovery into a faster contest between AI systems on both sides. The same logic applies to governments, who may now turn to using AI to search for vulnerabilities themselves.
The result may therefore be less about AI making hacking obsolete and more about raising the speed and sophistication of the race to find vulnerabilities first.
Where do these all leave us?
AI is not about to make software unhackable, and there is no guarantee that defenders will stay ahead of attackers. What is changing is the speed at which both sides can search for vulnerabilities, turning vulnerability research into a much faster contest.
For governments, that could make traditional hacking operations harder if defensive AI consistently finds and closes valuable vulnerabilities first. But if offensive AI becomes equally effective at finding flaws that defenders miss, governments may adopt the technology themselves, keeping the contest alive.
For enterprise security teams, the immediate lesson is less about government surveillance and more about speed.
AI-assisted vulnerability discovery could give software makers a better chance of finding dangerous flaws before attackers do. But the same technology could also shorten the time between a vulnerability appearing and someone trying to exploit it.
Green’s argument matters because both sides may soon be searching for the same weaknesses with increasingly capable AI systems. The advantage may belong not to whoever has the better hackers, but to whoever finds and acts on the vulnerability first.
More news: iPhone and Android users can set up emergency contacts and medical information that first responders or bystanders can access from the lock screen without a passcode.