The rise of AI-powered vulnerability hunting is forcing a rethink of how AI government hacking tools fit into the broader tension between state surveillance and personal privacy. Johns Hopkins cryptography professor Matthew Green put it plainly in a blog post published on 14 August 2026: if AI makes software significantly more secure by eliminating the bugs governments currently exploit, law enforcement and intelligence agencies could soon find themselves locked out of the devices they are legally permitted to target.

The argument, which spread quickly through the cybersecurity community, is less alarmist than it sounds once you understand the underlying deal that has held for a decade.

The Fragile Truce That Replaced the Backdoor Wars

Green calls it an ‘uneasy kind of truce.’ When encryption rolled out at mass scale through apps such as Signal, WhatsApp and Apple’s iMessage, governments faced a choice: demand backdoors into every device, or find another way in. They chose the latter.

Instead of forcing technology companies to weaken their own products, authorities invested in buying hacking tools and spyware from specialist firms that could subvert device security from the outside. It kept devices broadly secure for ordinary users. It kept governments functional. Nobody was entirely happy, but nobody was entirely stuck either.

The ‘going dark’ framing entered the policy vocabulary around 2014, when then-FBI Director James Comey warned that encryption was hampering authorities’ ability to intercept communications and access device data. Comey, who served as FBI Director from 4 September 2013 to 9 May 2017, later testified before the Senate Judiciary Committee and the Senate Select Committee on Intelligence on 8 July 2015, focusing on how groups including ISIL were using technology to recruit and communicate.

Federal law already drew a line on what the government could compel. The Communications Assistance for Law Enforcement Act requires telecommunications carriers to build intercept capability into their networks but does not require them to decrypt communications that customers encrypted themselves, provided the carrier did not supply the encryption. Hacking tools filled the gap that the law deliberately left open.

AI Government Hacking Tools May Be Squeezed at Both Ends

Green’s thesis is that AI threatens this arrangement by accelerating bug discovery and, more critically, by accelerating the patching that follows. Fewer unpatched vulnerabilities means fewer entry points for government operators to exploit.

Luna Tong, a researcher with experience at two companies that develop exploits for government clients, agreed with Green’s direction of travel: there is a ‘gold rush of bugs right now but it’s a temporary phenomenon and bugs will get scarce again soon.’ A second offensive security researcher, with over a decade of industry experience, told the original reporter they are worried AI will make human vulnerability researchers obsolete over time.

Not everyone reads the market the same way. Crowdfense, founded in early 2017 with an initial $10 million fund for its vulnerability acquisition programme, sits in the middle of this ecosystem: it develops, acquires, and sells zero-days to government clients including national security and law enforcement agencies. Paolo Stagno, listed as Director of Research on Crowdfense’s own website (the original article described him as chief technology officer; the company’s own page, as of 10 March 2026, gives the Director of Research title), said the current system is the ‘most democratic system we have,’ but acknowledged it may not survive if bugs become genuinely hard to find.

Crowdfense’s Exploit Acquisition Program pays up to $1.5 million for a full-chain Chrome exploit and up to $500,000 for a Microsoft Word or Excel remote code execution vulnerability, figures that illustrate just how much governments and their intermediaries are currently willing to spend for reliable access.

Hamid Kashfi, founder of offensive security firm DarkCell and also affiliated with AI cybersecurity startup Xbow, pushed back on the scarcity narrative. ‘For every AI found and reported bug out there, there are probably 20 that are not reported,’ he said, arguing that researchers who choose not to disclose to vendors will continue surfacing complex, high-value vulnerabilities regardless of what AI can automate.

Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation, offered a more layered read. AI is currently very capable of finding bugs, and ‘vibe-coding’ with AI tools is simultaneously introducing new vulnerabilities at scale. But finding bugs faster does not automatically mean they get patched faster, or patched at all; the patching pipeline has its own inertia. Galperin also predicted a renewed push for backdoors regardless, because authoritarian regimes will always want ‘exceptional access.’

Katie Moussouris, founder and CEO of Luta Security, framed the timeline usefully: ‘we have some distance to go before the latest phones and laptops are completely bug free.’ Her estimate, shared in the original reporting, is that the intelligence community has ‘at least until after the next presidential election before’ it is ‘materially hampered enough to push for backdoors in a serious way.’

That date, if Moussouris is right, is the one worth watching. The FBI’s going-dark arguments have resurfaced and receded before. The question is whether, this time, AI on the defensive side finally gives them real teeth.

Share.

Marcus Hale has been filing general news for the better part of fifteen years. He started at a regional evening paper, moved to a mid-sized digital outlet covering UK news, and spent three years as a general assignment reporter before going freelance. He has covered inquests, council elections, infrastructure announcements, and the kind of stories that sit on page five but matter on page one. He writes about public services, housing, local government, and the institutional stories that take six months to develop and thirty seconds to read. He prefers facts to angles and considers that unfashionable. Marcus lives in Bristol. He still reads the local paper and thinks that makes him an endangered species.

Leave A Reply