AI Could Shrink the Supply of Exploits Governments Rely On

AI Could Shrink the Supply of Exploits Governments Rely On

AI is becoming an important determinant in the contest for vulnerabilities between defenders, governments, and even threat actors. Image: ChatGPT

AI could accelerate vulnerability discovery, shrinking the pool of exploits governments rely on while speeding up the race between attackers and defenders.

Sep 7, 2026

AI could create a problem governments have spent years trying to avoid: fewer undiscovered software vulnerabilities available to exploit.

Governments have increasingly turned to hacking tools when encryption prevents them from accessing a suspect’s phone or computer, creating a market where companies and researchers hunt for vulnerabilities that can be turned into exploits. But that market has an obvious dependency: there must be exploitable bugs left to find.

Security cryptographer and professor Matthew Green published an analysis noting that AI could start attacking that dependency from the other side. If technology companies can use AI to continuously search, identify, and patch vulnerabilities before attackers can weaponize them, the supply of useful exploits could shrink — not because encryption got stronger, but because the software itself became harder to break.

That possibility would have consequences well beyond ordinary cybercrime. Agencies that rely on commercial hacking tools could find themselves competing with the same AI systems that vendors use to eliminate the vulnerabilities those tools depend on.

What is Green’s argument about

The emergence of stronger encryption has pushed governments to exploit vulnerabilities in devices or their software instead.

That has made previously unknown vulnerabilities valuable commodities. Governments can develop exploits themselves or buy them from researchers and commercial hacking firms, but the entire market depends on one thing: vulnerabilities remaining undiscovered long enough to be exploited.

Green argues that AI could start taking that advantage away.

The point is not that AI will eliminate software vulnerabilities. It is that AI could make the window between a vulnerability existing and someone discovering it much shorter, reducing the supply of useful bugs available to offensive researchers.

If that happens across widely used software, Green argues, governments could eventually find it harder to obtain the exploits they use to access protected devices, creating a new problem he says is similar to “Going Dark.”

Advertisement

AI vulnerability research is already moving into production

Green’s argument would be easier to dismiss as speculation if AI-assisted vulnerability discovery were still largely experimental.

Recent work from Microsoft and Google suggests it is already becoming a practical part of how major software companies find and fix security flaws.

Microsoft’s July Patch Tuesday is one example, with the company using AI-assisted tools to help identify and fix 570 flaws. Google has gone further with Chrome, using AI to find vulnerabilities and fix a staggering 1,072 security bugs, including one sandbox escape flaw that had existed for 13 years.

Those examples do not show that governments are already running out of usable exploits. They do, however, support the underlying premise: software vendors are gaining automated tools that can search for vulnerabilities at a scale and speed that would have been difficult to sustain manually.

Must-read security coverage

A possible second-order effect

If AI makes useful vulnerabilities harder for governments to obtain, the next question is what they do when hacking is no longer a reliable way around encryption. One possible answer is a return to exceptional access: requiring technology companies to provide a government-only backdoor to otherwise protected data or devices.

The idea has been debated for years. The 2016 case between the FBI and Apple put that into the spotlight when the FBI demanded that Apple grant it access to the iPhone of a shooting suspect, a request Apple declined, citing the security consequences of adding a backdoor to its services.

Green’s argument could give that debate a new trigger. If governments begin losing a technical route into encrypted devices because the vulnerabilities they depend on are being found and patched faster, pressure for companies to provide an alternative route could increase.

Advertisement

With governments increasingly testing the limits of their influence over how technology companies design their services, renewed pressure could create an interesting turn of events between both parties.

The dual-headed nature of AI in security

There is, however, a problem with assuming AI will give defenders the upper hand: attackers get the technology too. If AI enables software makers to find and close vulnerabilities before they can be exploited, attackers can use the same technology to search for weaknesses that defensive systems have missed.

That could turn vulnerability discovery into a faster contest between AI systems on both sides. The same logic applies to governments, who may now turn to using AI to search for vulnerabilities themselves.

The result may therefore be less about AI making hacking obsolete and more about raising the speed and sophistication of the race to find vulnerabilities first.

Where do these all leave us?

AI is not about to make software unhackable, and there is no guarantee that defenders will stay ahead of attackers. What is changing is the speed at which both sides can search for vulnerabilities, turning vulnerability research into a much faster contest.

For governments, that could make traditional hacking operations harder if defensive AI consistently finds and closes valuable vulnerabilities first. But if offensive AI becomes equally effective at finding flaws that defenders miss, governments may adopt the technology themselves, keeping the contest alive.

For enterprise security teams, the immediate lesson is less about government surveillance and more about speed.

AI-assisted vulnerability discovery could give software makers a better chance of finding dangerous flaws before attackers do. But the same technology could also shorten the time between a vulnerability appearing and someone trying to exploit it.

Advertisement

Green’s argument matters because both sides may soon be searching for the same weaknesses with increasingly capable AI systems. The advantage may belong not to whoever has the better hackers, but to whoever finds and acts on the vulnerability first.

More news: iPhone and Android users can set up emergency contacts and medical information that first responders or bystanders can access from the lock screen without a passcode.

Joseph Ofonagoro

Joseph is a technical writer with about three years of experience creating clear, practical content across consumer technology, startups, tutorials, and cybersecurity. He is also advancing a career in cyber threat intelligence, driven by a strong interest in the responsible use of technology and its role in protecting people, organizations, and digital systems. His passion for cybersecurity grew out of a broader commitment to helping others understand technology safely and effectively. As an undergraduate at the National Open University of Nigeria, he leads a community of technology enthusiasts, guiding beginners, sharing learning resources, and helping students build confidence as they explore careers in tech. Joseph’s writing combines technical curiosity with an accessible, beginner-friendly style. In addition to his editorial work, he periodically shares cybersecurity case studies and research reports on social media, covering threat trends, security lessons, and practical insights for readers interested in cyber awareness and digital safety.