AI bug bounty programs: powerful, noisy, and increasingly political
AI bug bounty programs are security reward schemes where both companies and independent researchers use generative and analytical AI tools to discover, submit, and triage software vulnerabilities at scale, a shift that accelerates patching but also floods platforms with fake vulnerability reports and security researcher noise that is difficult for human teams to sort and prioritize. The uncomfortable takeaway is that AI now threatens the very economic and trust model bug bounties depend on. When a model can produce a plausible report in seconds, the bottleneck moves from discovery to verification—and that bottleneck is painfully human. Platforms that fail to adapt risk discouraging serious researchers while being buried in automated nonsense, turning a once-valuable feedback loop into a denial-of-service attack on their own security teams.

Apple’s quota gambit: fighting AI slop and sidelining a $200K exploit
Apple’s response to AI-generated noise shows how bug bounty platform management can backfire. Flooded by fake vulnerability reports, the company capped how many submissions a single researcher can have open, introducing a 30‑day cool‑off once they hit that quota, with the option to request a higher limit through its security portal. That might sound reasonable until you see the collateral damage. Security firm Bynario said the new policy held up disclosure of dozens of vulnerabilities, including a macOS Screen Sharing privilege escalation exploit they claim could fetch up to USD 200,000 (approx. RM920,000) on the black market. The exploit, tracked as CVE‑2026‑43760, used a legacy VNC authentication path to read protected files and escalate to root without triggering memory corruption, slipping past Apple’s Memory Integrity Enforcement defenses. Apple’s attempt to stem AI slop ended up burying exactly the kind of subtle, high‑impact bug its bounty is supposed to surface.

When fake vulnerability reports swamp real threats
Apple is not alone in being overwhelmed by AI-assisted noise. Curl’s security team has been sounding the alarm on so‑called “AI slop” since early 2024, and by 2025 the confirmed‑vulnerability rate on its bug bounty program had fallen below 5%, down from more than 15% before AI-generated claims surged. That drop is not a minor nuisance; it is a triage nightmare. The core problem is asymmetry: producing a plausible report is cheap for AI, but verifying it is expensive for humans. Even when companies use AI to sift through bug reports, each submission still demands far more expert time and context than it takes to generate in the first place. Left unchecked, this dynamic turns bug bounty programs into spam filters, not security pipelines. Serious researchers see their work delayed or ignored, while security teams waste hours disproving hallucinated threats instead of addressing real exploitable bugs.
Microsoft’s record payouts show AI’s upside and its signal-to-noise problem
Microsoft is the flip side of the AI bug bounty story: embracing AI and paying handsomely for the results. Between July 1, 2025, and June 30, 2026, it paid more than USD 20 million (approx. RM92 million) in bug bounties to 562 researchers, up from around USD 17 million (approx. RM78.2 million) to 344 researchers the previous year. One quotable summary: “The increased number of reports this year can also be partially explained by the noticeable influx of submissions… attributed in part to the growing use of AI to support security research”. Microsoft widened its scope with an “In Scope By Default” policy in December 2025, making critical bugs in third‑party and open‑source code eligible for rewards. At the same time, its own AI models have helped drive Patch Tuesday counts to record levels, with one recent release fixing 622 vulnerabilities. The upside is obvious—but so is the risk that platforms drown in sheer volume, especially when frustrated researchers start dropping sophisticated zero‑days outside coordinated disclosure.
Bug bounty platform management in the AI era: sort, don’t stop
The lesson from Apple and Microsoft is not that AI should be pushed out of bug bounty programs, but that platforms must learn to sort AI-assisted reports without choking legitimate work. Enforcing quotas to counter fake vulnerability reports can help, yet Apple’s own experience shows this blunt approach can block high‑quality AI-assisted findings and delay serious exploits. At the same time, AI has clearly boosted both the number and quality of valid reports; Bynario’s seven‑person team went from eight Apple exploits last year to more than 50 uncovered in three weeks using ChatGPT. Chrome’s last two versions fixing more than 1,000 vulnerabilities combined—more than the previous 23 releases together—illustrates the upside of this acceleration. The strategic move is not fewer AI tools, but better filters, clearer expectations, and economic incentives that reward depth over volume. Bug bounty platforms that treat AI as a flood to dam, rather than a river to channel, will find themselves permanently underwater.



