How AI is changing the software vulnerability landscape
In June 2026, Google reported more bugs fixed in Chrome than in the previous two years combined, thanks to AI systems that detect vulnerabilities at scale. Matthew Green, a cryptography professor at Johns Hopkins, sums up the central thesis: if AI keeps up that pace of detection and patching, software becomes progressively less vulnerable. Fewer bugs mean fewer zero-days available.
Zero-days are unpatched vulnerabilities that governments and intelligence agencies use to access encrypted devices. WhatsApp, Signal and iMessage block traditional eavesdropping with end-to-end encryption, so intercepting communications requires exploiting flaws in the operating system or the apps — flaws that, if AI closes them all, will stop existing.
What the experts say: a temporary gold rush or a permanent change?
Luna Tong, a researcher at exploit-hunting firms, describes the current situation as "a bug gold rush", but warns it is temporary. Paolo Stagno, CTO of Crowdfense, acknowledges that exploiting vulnerabilities is today "the most democratic system we have" and that it might not survive if bugs become hard to find. That is exactly what worries governments and agencies.
The opposing view comes from Hamid Kashfi of DarkCell: "for every bug found and reported by AI, there are probably 20 that aren't". Researchers who hunt for flaws without reporting them keep discovering complex vulnerabilities no automated model detects yet. Eva Galperin, director of cybersecurity at the EFF, adds that AI-assisted development also introduces new vulnerabilities, not just closes them.
"Going dark" returns: a debate that never ended
The concept was popularized in 2014 by James Comey, then FBI director, who argued that mass encryption would leave law enforcement without access to criminal communications. At the time the debate ended without backdoor legislation, partly because zero-days were still available as an alternative route. If that route disappears, regulatory pressure comes back stronger.
Katie Moussouris, CEO of Luta Security, offers the most concrete horizon: "we have some way to go before the latest phones and laptops are completely bug-free. There will be a point when finding bugs is much harder, and that may trigger these pressures." Her estimate: roughly one election cycle before the tension becomes unsustainable.
What this means for users and businesses in Latin America
For companies in the Dominican Republic and the region, the debate has practical implications. Software made more secure by AI is directly beneficial: fewer breaches, lower incident costs, less exposure of customer data. But the political counterweight — backdoor legislation that would weaken encryption in messaging apps — would affect any company that relies on tools like WhatsApp Business, Signal or encrypted platforms to handle sensitive information.
The resource gap matters too: if only large corporations like Google or Microsoft can access AI defensive tools, the cybersecurity gap between large companies and small businesses widens. For mid-sized businesses that can't afford specialized teams, AI democratizing vulnerability detection is an opportunity — but it requires someone to actively apply it to their infrastructure.
Frequently asked questions
What is a zero-day and why does it matter in this debate?
A zero-day is a software vulnerability the vendor doesn't know about yet and hasn't patched. Governments and hackers use them to access devices. If AI closes them all before they're exploited, that route of access disappears.
Is an encryption backdoor really that dangerous?
Yes. Cryptography experts agree there's no such thing as a "backdoor only for the good guys". If encryption is weakened so governments can get in, the same weakness can be exploited by malicious actors. It's mathematically impossible to create access that only authorities can use.
When could this problem become critical?
According to Katie Moussouris (Luta Security), we're roughly one election cycle away from the scarcity of zero-days creating real legislative pressure. The pace at which AI detects vulnerabilities will determine whether that timeline gets shorter.
How can a business protect itself in this scenario?
By choosing software with end-to-end encryption, auditing its technology providers and monitoring regional legislation on government access to data. Anticipating regulation is part of a cybersecurity strategy.