The AI Security Trap: Why the 'Bug Drought' is a Pretext for Permanent Backdoors

AI-generated image · Bay Street Wire
As AI makes software more secure, tech giants and government agencies may use the scarcity of vulnerabilities to demand 'exceptional access' to our devices.
OPINION: For years, the relationship between the tech giants and government intelligence has existed in what cryptography professor Matthew Green calls an "uneasy kind of truce." Instead of forcing companies to build intentional weaknesses into our hardware, governments spent billions buying spyware and zero-day vulnerabilities to bypass security. It was a messy system, but it allowed the average consumer to maintain a semblance of privacy while authorities chased criminals.
Now, that truce is under threat, and tech giants are poised to play right into the hands of the surveillance state.
As TechCrunch first reported, Matthew Green has posited a provocative theory: AI is becoming so efficient at finding and patching security flaws that software may soon become "too secure." If LLMs can identify and fix an unprecedented volume of bugs, the traditional hacking tools used by law enforcement could vanish. This creates a vacuum that the government will inevitably try to fill.
We have seen this playbook before. In 2014, then-FBI director James Comey popularized the concept of "going dark," arguing that end-to-end encryption from services like WhatsApp, Signal, and Apple’s iMessage hindered the ability of authorities to monitor criminals. While the government shifted toward buying exploits to maintain access, the fear is that once those exploits become too rare to purchase, the demand for mandatory backdoors will return with a vengeance.
Some industry insiders agree the clock is ticking. Luna Tong, a researcher previously employed by two firms that develop exploits for governments, told TechCrunch there is currently a "gold rush of bugs," but warned this is a temporary phenomenon. Similarly, an unnamed researcher with over a decade of experience in offensive security expressed concern that AI could make human researchers obsolete, eventually giving defenders the upper hand.
Of course, the surveillance apparatus will not simply give up. Paolo Stagno, CTO at Crowdfense—a firm that sells zero-day vulnerabilities to governments—told TechCrunch that "no state will throw away the possibility of surveillance." While Stagno describes the current system of exploiting flaws as the "most democratic system we have," he acknowledges the status quo is fragile.
There are skeptics, such as Hamid Kashfi, founder of DarkCell and a contributor to Xbow, who argues that complex, valuable bugs will persist and that AI will actually assist those selling exploits to the state. However, the risk to the consumer remains the same. Whether the bugs disappear entirely or just become harder to find, the result is a push for "exceptional access."
Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation, noted that authoritarian regimes always crave this access. Katie Moussouris, CEO of Luta Security, warned that once finding bugs becomes sufficiently difficult, it may trigger the pressure to build in backdoors.
Let's be clear: the "security risk" the suits will warn us about isn't the AI-driven bugs—it's the solution they'll propose. By framing the loss of hacking tools as a crisis of public safety, tech giants and their government allies will attempt to bake surveillance directly into our silicon. They aren't worried about our security; they are worried about their access.

