Are AI models drying up the vulnerability market and prompting governments to push for backdoors again?
Listen to this article
Read by Anchor
Cryptography professor Matthew Green reignited an old debate in the cyber security community by positing a unfamiliar hypothesis, warning that the rapid acceleration of AI's ability to discover software vulnerabilities and patch them at scale could make software so heavily fortified that law-enforcement and intelligence agencies would be deprived of the exploits they rely on to legally breach suspects' devices.
The debate traces back to the roots of the encryption crisis that erupted in 2014 when security agencies, such as the FBI, warned that the widespread adoption of end-to-end encryption in apps like Signal, WhatsApp and iMessage, and automatic device encryption, would block traditional surveillance. The situation then settled into a unspoken truce, with governments substituting the demand for built-in backdoors with the purchase of spyware tools and unknown exploits known as zero-day vulnerabilities.But that truce now faces the risk of unraveling if language models succeed in closing security gaps faster than attackers can discover new vectors.
Offensive security experts are divided on how quickly this shift will materialize. Researcher Luna Tong, who develops intrusion tools for government clients, supports the notion that the current surge in vulnerability discovery is a temporary phenomenon that will be followed by a sharp scarcity of available exploits. Conversely, Paulo Stânio, CTO of Crowdfense, which brokers zero-day vulnerabilities, argues that reliance on exploits remains the most balanced system for lawful monitoring, warning that their scarcity will inevitably revive governmental pressure to impose exceptional access.
On the other hand, a team of developers and digital-rights experts sees the picture as more complex. Hamid Kashfi, founder of Dark Seal, notes that for every disclosed vulnerability there are roughly twenty undisclosed ones, and that high-value complex bugs will not vanish easily. Eva Galbreen, head of cybersecurity at the Electronic Frontier Foundation, observes that what is called intuition-driven programming based on automated generation tools continually introduces new software defects, while patching remains slow and cumbersome. Kitty Musoreis, CEO of Luta Security, confirms that achieving devices completely free of flaws remains out of reach, but the difficulty of extracting vulnerabilities will gradually push the intelligence community toward demanding mandatory legislation for backdoors.
This technological shift has direct and tangible implications for IT managers and cloud-infrastructure teams across the Arab region, from Riyadh and Dubai to Cairo and Amman.If the effectiveness of zero-day exploits declines and their global purchase price rises, regulators may move to tighten data sovereignty and oversight of foreign-company software operating locally. This reality also compels regional organizations to invest early in automated code-audit tools before deployment, rather than relying solely on traditional testing, to harden their banking and governmental services against a wave of automated attacks that exploit easy vulnerabilities within minutes.
The arms race between defenders and attackers in the digital realm is entering a new phase driven by the speed of automation. While generative testing tools may represent a generation of the most secure software, the corresponding cost could be a resurgence of legal and political battles over encryption privacy and the inevitability of governmental access.