Rapid advances in AI-assisted vulnerability discovery could make widely used software harder to hack and revive government demands for intentional access mechanisms, cryptographer Matthew Green argued in an essay published on August 14, 2026. The apparent paradox is that better defensive security may reduce the flaws law-enforcement and intelligence agencies use to reach encrypted devices.

The argument begins with the shift from telephone interception to data held on smartphones. Apple introduced passcode-derived iPhone storage encryption in 2010 and end-to-end encryption for its messages the following year, while WhatsApp later made encrypted messaging and calls the default for a user base approaching one billion. These changes limited traditional interception and device access.

In 2014, FBI director James Comey launched the “Going Dark” campaign for a public discussion about access to encrypted communications. The conflict became concrete in 2016 when the FBI sought Apple’s help opening an iPhone after a terrorist attack. Apple resisted, but an outside company offered to hack the device, demonstrating an alternative to compelling a manufacturer to build access.

Over the following decade, agencies bought targeted tools such as GrayKey for phone unlocking and NSO Group’s Pegasus for remote exploitation. Apple and Google patched disclosed weaknesses, while vulnerability researchers and exploit vendors continued finding others. Green argues that this market reduced the immediate pressure for formal backdoors because agencies could purchase access case by case.

AI may disrupt that balance. The essay cites an Anthropic model called Mythos, announced in April 2026, as unusually capable at finding software flaws. The US government temporarily restricted its export, but comparable work by OpenAI and open-weight developers including Z.ai and Moonshot suggested that no single laboratory would monopolize the capability. These claims are the author’s account; the supplied evidence does not include independent model evaluations.

Defenders can apply the same capability across old code and incorporate automated scanning into continuous-integration systems before release. Green forecasts that major, well-maintained software could lose much of its supply of remotely exploitable bugs within two years. He acknowledges that not every defect can be found, making this a prediction about useful exploit scarcity rather than bug-free software.

If targeted hacking becomes substantially less reliable, agencies could again press companies to design “exceptional access” into products. Security researchers have long warned that an intentional access path built for one authority can also become a target for criminals or hostile states. The essay’s concern is therefore not improved patching itself, but the political response when governments lose an alternative surveillance route.

The outcome remains uncertain. AI systems can assist both attackers and defenders, software complexity continues to create new flaws, and exploit availability is opaque. Green’s analysis identifies a policy feedback loop: automated discovery accelerates patching, scarcer vulnerabilities raise the cost of targeted access, and that cost may intensify demands to weaken otherwise secure systems by design.