Governments can better mitigate risk from the burgeoning surveillance software industry with bug bounties, not export controls
Benjamin Brake / Foreign Affairs :
Context & Ripple Effects
Writing in Foreign Affairs, Benjamin Brake argues governments should manage the risk of the commercial surveillance-software trade by buying vulnerabilities back through bug bounties rather than restricting sales abroad. Weeks after publication, Washington moved the other way, proposing tighter export controls on zero-day flaw information sold outside the US, and five years later Brussels followed with plans to cover hacking software under toughened 'dual use' export rules.
The intervening coverage suggests the market Brake worried about grew regardless: Google's TAG catalogued roughly 40 commercial spyware vendors and called for more aggressive government action, while researchers documented how vendors survive restrictions by renaming, re-incorporating, or shifting jurisdictions. The bug-bounty alternative he endorsed has also matured unevenly — even dark net markets like Hansa began running them — but critics charge that closed, NDA-bound programs buy researcher silence and may breach labor law.
First-order effects
- Governments that adopted the export-control route — the US on zero-day sales, the EU on dual-use hacking tools — are now policing a vendor ecosystem that Google TAG counts at roughly 40 firms, validating Brake's warning that licensing sales does not shrink the industry.
- The bug-bounty mechanism Brake proposed is now contested terrain itself: critics argue closed, NDA-gated programs suppress disclosure rather than channel it, giving governments weighing his recommendation a counterargument from within the researcher community.
Second-order effects
- As Atlantic Council researchers show, spyware vendors respond to export restrictions by renaming or changing legal jurisdiction, forcing regulators to consider demand-side tools — procurement bans, action against government buyers — instead of chasing suppliers across borders.
- If bounties are to serve as the mitigation tool, their design becomes policy: open, non-exclusive programs compete with closed corporate ones, and dark net markets adopting bounty models signals that whoever pays first shapes where flaws land.
Third-order effects
- A decade of coverage points toward a structural split in surveillance-software governance: supply-side export controls persist on paper while enforcement migrates toward targeting the buyers and users of spyware, since vendor mobility keeps defeating jurisdiction-based restriction.
- The vulnerability market itself is institutionalizing — bounty platforms, corporate NDAs, and even marketplace-run programs — meaning the state's lever over exploits increasingly runs through purchasing power rather than border controls.
The trend: Surveillance-software governance is drifting from supply-side export controls toward demand-side and market-based interventions as vendors evade jurisdictional limits.