Who loses? Law enforcement and intelligence agencies could find themselves shut out from exploits they rely on, as AI-driven tools begin to reduce the number of discoverable software bugs.

Earlier in August cryptography professor Matthew Green set off a debate when he suggested AI may make software so secure that governments can no longer lawfully hack targets they need to surveil. “I’m concerned that AI is going to make software much too secure,” Green wrote, arguing that faster, more thorough vulnerability discovery will prompt companies to patch an unprecedented volume of bugs, closing the windows governments use to subvert devices.

The tension between privacy and surveillance has a long history. Law enforcement warned about “going dark” after stronger encryption spread in the mid 2010s, when apps such as Signal, WhatsApp, and Apple’s iMessage rolled out end-to-end encryption and device makers moved to encrypt data by default. Rather than insist on built-in access, many governments bought exploits and spyware to bypass protections, a trade that Green calls an uneasy truce. If AI accelerates defensive fixes, that truce may fray, rekindling pressure for design-level exceptions.

Privacy and security specialists interviewed for this story split on whether that outcome is likely. Some within the offensive security community worry AI will give defenders the edge. One veteran researcher said AI could make human vulnerability hunters obsolete, and another researcher who has worked at firms that sell exploits to governments expects defenders will eventually gain the upper hand. Paolo Stagno, chief technology officer at Crowdfense, said the current market for buying and selling unknown vulnerabilities is vital to surveillance policy, calling it “the most democratic system we have,” but he acknowledged it may not survive if bugs become scarce.

Others pushed back, noting limits to what AI can remove and advantages it can create for attackers. Hamid Kashfi, founder of DarkCell and a contributor at AI security startup Xbow, argued that for every bug found and reported by AI there are many more not reported, saying “for every AI found and reported bug out there, there are probably 20 that are not reported.” Two active zero-day researchers pointed to rising device protections as a bigger constraint on offensive work than AI itself.

Advocates for privacy caution that a surge in vulnerability discovery does not automatically translate into safer systems. Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation, said offense currently benefits from both AI’s ability to surface flaws and a rise in insecure code produced with AI-assisted development, but she warned that vulnerabilities are not always patched quickly. That lag, she said, leaves room for continued surveillance and for authoritarian regimes to demand “exceptional access.” Katie Moussouris, founder of Luta Security, noted the gap between current devices and bug-free systems, saying “we have some distance to go before the latest phones and laptops are completely bug free.” She added that there will be a point when scarcity in discoverable bugs could prompt renewed calls for backdoors.

The debate frames what comes next. If AI genuinely drives down exploitable flaws, policymakers may face renewed lobbying to weaken device security in the name of law enforcement. If, instead, AI both helps defenders and is co-opted by offensive actors, the market for zero-days and the economics of surveillance may simply shift. For now experts agree on one clear consequence: AI is changing the supply and discovery of vulnerabilities, and that shift will shape surveillance policy and industry incentives for years to come.