AI security reports are collapsing the old 90-day norm
AI security reports are machine-assisted vulnerability submissions that use language models to describe flaws, often flooding maintainers with issues whose impact and accuracy vary widely while forcing projects to reconsider the traditional vulnerability disclosure timeline that once relied on slower, human-driven discovery and triage. Volunteer maintainers now receive a steady flow of security vulnerability reports produced with AI tools, many with no mention of language model involvement. That volume has pushed GNOME to stop pretending AI is an edge case and instead apply one set of rules to all reports, AI-assisted or not. In effect, vulnerability reports that are not discovered by AI have become unusual, so optimizing security disclosure policy for handcrafted reports is starting to look nostalgic rather than responsible. The question is no longer whether AI belongs in security work, but whether teams can stay sane under its firehose.
GNOME’s 30-day deadline: faster disclosure under AI pressure
GNOME’s decision to cut its vulnerability disclosure timeline from 90 days to 30 is a quiet but significant rebuke of the old norm. For years, reports sat confidential for three months, even though maintainers either fixed them within weeks or left them untouched until the clock ran out. That lag added delay without real benefit. With AI security reports now arriving steadily, GNOME’s security tracker lead Michael Catanzaro will switch to a 30-day disclosure deadline for issues reported on August 1, 2026 or later. He discloses a report and requests a CVE once a fix ships or once the deadline passes, whichever comes first. This is a pragmatic stance: treat AI-generated and human-written reports the same, but shorten the window so known vulnerabilities do not linger. Projects that ban AI-generated content in their trackers will still receive notifications, yet this shows how rigid AI policies can backfire when most serious reports now contain AI-written material.
GitHub’s bug bounty program bets on signal over volume
While GNOME tightens timelines, GitHub is attacking the AI report problem from the opposite angle: quality control. GitHub is changing its bug bounty program to reward higher-quality vulnerability reports and reduce low-effort submissions, including AI-generated reports, with changes taking effect on July 27, 2026. According to Jarom Brown, the platform has seen "a sharp increase in submissions that don’t demonstrate real security impact," including reports with no proof of concept and theoretical attacks that collapse under scrutiny. In response, GitHub is formalizing a private, invite-only VIP program for researchers who consistently deliver high-impact findings, backed by a new payout table that ties a single amount to each severity level and allows discretionary bonuses for exceptional submissions. To qualify for VIP, participants must log one critical, two high, four medium, or seven low-severity findings. This is a deliberate statement: AI may help find issues, but reputation and demonstrated signal will decide who gets closer collaboration and faster responses.

New filters and stricter policies: security teams push back
Security teams are no longer politely absorbing the AI-generated wave; they are building filters. GitHub is introducing HackerOne’s signal requirement so newcomers can submit up to four initial reports while they prove their value, after which continued participation depends on meeting a signal threshold. The explicit goal is to reduce low-effort and AI-generated reports while keeping the bug bounty program accessible to new researchers. On the open-source side, GNOME’s move to a 30-day disclosure deadline is a middle path between the long 90-day window and the Linux kernel’s much harsher stance of immediate disclosure for reports that appear AI-generated, based on the belief that anything AI can surface is probably already known to attackers. That approach risks pressuring maintainers to rush fixes, a trade-off GNOME is unwilling to make. The common thread is clear: AI is forcing platforms to encode expectations about rigor, proof, and impact directly into their security disclosure policy instead of trusting researchers to self-police.

The next phase: faster timelines, fewer junk reports, more burnout?
Taken together, these changes show a security ecosystem trying to stay ahead of AI’s speed without drowning in its noise. GNOME’s planned handoff of its security tracking—Catanzaro will stop tracking newly reported issues on November 1, 2026, clear the backlog in November, and finish once every remaining deadline has passed by December 1—hints at the human cost of this work. He describes the role as largely secretarial, dominated by logging, closing, and disclosing issues and requesting CVEs. As AI security reports grow, that admin load only increases. Platforms are responding by shortening disclosure timelines, rewarding high-signal researchers, and throttling low-quality submissions. The risk is obvious: if policies swing too far, real but unconventional findings may be filtered out alongside junk. The opportunity is just as clear: a future where AI-accelerated discovery pairs with disciplined triage, making vulnerability disclosure faster, clearer, and less dependent on outdated 90-day habits.






