Cryptographer warns AI security gains could force US law enforcement 'go dark'
A leading cryptographer argues that AI-driven software hardening is reversing the decade-long trend of law enforcement accessibility, potentially triggering renewed demands for intentional backdoors that could weaken global digital infrastructure.
A cryptographer has issued a stark warning that artificial intelligence is accelerating software security to a point where US intelligence and law enforcement agencies may suddenly lose their ability to conduct surveillance. Speaking from the Usenix Security conference in Baltimore, the author argues that AI-assisted vulnerability scanning is rapidly eliminating the exploitable bugs that authorities have relied upon for over a decade.
The concern centres on the prediction that within two years, major software platforms will run out of remotely exploitable vulnerabilities. This shift represents a significant reversal of the trend that began in the late 2000s, when the proliferation of smartphones and end-to-end encryption made communications increasingly difficult for law enforcement to access.
The history of this tension dates back to 2010, when Apple began encrypting iPhone data using keys derived from user passcodes, with Google following suit. By 2016, WhatsApp had nearly a billion users employing end-to-end encryption. In response, FBI Director James Comey launched the "Going Dark" initiative in 2014 to address the loss of access to communications media.
The stalemate between the FBI and Apple regarding access to a shooter’s locked iPhone was eventually broken not by policy, but by an outside company claiming it could hack the device without Apple’s assistance. For the subsequent decade, law enforcement agencies requested exceptional access backdoors, while vendors like Apple and Google vigorously closed vulnerabilities as they were discovered.
Recent developments have disrupted this equilibrium. In April, Anthropic announced a vulnerability-finding model called Mythos, which the US government temporarily blocked from export. However, OpenAI and Chinese labs such as Z.ai and Moonshot have demonstrated that vulnerability finding is not monopolised by a single model. Defenders are now rebuilding development toolchains to incorporate AI vulnerability scanning before software reaches testing phases.
The author suggests that the destruction of "low-hanging vulnerability fruit" will make the demand for intentional backdoors more acute. This pressure could lead to a scenario where US systems are weakened by design, allowing foreign adversaries to find new ways to attack communications infrastructure just as defenders are learning to protect it more effectively.
While the debate over exceptional access has largely hibernated in the US due to expert pushback regarding the risks of backdoors being abused by adversaries, the author fears the market is merely pricing supply. The impending scarcity of exploitable bugs may force a re-architecture of systems to be friendly to exceptional access, potentially leading to self-sabotage of US digital infrastructure.

