
Artificial intelligence is usually discussed as a gift to attackers. It can write phishing emails, automate reconnaissance and help less skilled hackers move faster. But there is another possibility now getting serious attention: AI could also make software much harder to hack.
That argument was recently made by Johns Hopkins cryptography professor Matthew Green in a widely discussed essay titled Everything is about to go dark. His point was deliberately provocative. If AI helps defenders find and fix bugs at massive scale, governments may lose access to the security flaws they quietly depend on for lawful hacking and intelligence work.
That idea was explored further in a TechCrunch security analysis, but the debate is bigger than one article. For years, governments have complained about encryption making investigations harder. The FBI popularised the phrase going dark more than a decade ago when it warned that strong encryption could limit access to communications and devices.
The compromise has often been uncomfortable but practical. Instead of forcing every device to include a backdoor, governments and contractors have bought or developed exploits that target software vulnerabilities. That created a market for zero-days, which are unknown flaws that can be used before vendors patch them.
AI could disturb that arrangement. If models become very good at finding vulnerabilities before attackers or spyware vendors do, large software companies could patch more bugs faster. That would not end hacking. But it could make reliable, high-value exploits rarer and more expensive.
There are already signs that AI can help both sides. Google’s Threat Intelligence Group has described how attackers are using AI in vulnerability work, while Google DeepMind and Project Zero’s Big Sleep system has been used to find unknown software flaws. The same capability that helps attackers write better exploits can help defenders hunt them down first.
That is why the debate is not as simple as AI good or AI bad. AI may make weak software easier to exploit in the short term because more people can automate attacks. But over time, it may also make mature software harder to exploit because defenders can scan code, test patches and audit dependencies at speeds humans cannot match.
This lands at a sensitive moment. The industry is already warning that AI-powered cyberattacks are becoming more urgent, while agentic systems have raised new questions about software behaving outside expected boundaries. If AI strengthens both attack and defence, governments may have to rethink the tools they use and the laws they ask for.
The risk is that if zero-days become harder to buy or keep secret, governments may return to an older demand: built-in access. That would reopen the encryption backdoor fight and could make ordinary users less safe. A deliberate weakness created for law enforcement is still a weakness that criminals, hostile states or corrupt insiders may try to exploit.
The better answer is not to weaken software because hacking became harder. It is to build clearer rules for lawful access, stronger oversight over spyware vendors and more investment in defensive security. If AI helps remove bugs from the internet, that should be treated as progress, not a problem to be reversed.







