AI is overwhelming bug bounty programs. Apple sets limits, while Microsoft offers payments.
AI has become adept at identifying software bugs more rapidly than humans, leading to challenges for the programs that reward these discoveries. In just one week, the three largest companies took three distinct approaches.
Microsoft disbursed a record amount. Apple imposed restrictions on the number of bugs researchers can submit. Google subtly adjusted its pricing structure. All three were responding to the same overwhelming influx.
According to The Register, Microsoft allocated over $20 million to 562 researchers during its most recent bounty year, marking a record for both total payout and number of researchers. The previous year, the company had spent approximately $17 million on 344 researchers. Microsoft attributed this increase to the "growing use of AI" in security research.
However, the comparison isn't straightforward, as the company also expanded the definition of what constitutes a bug midway through the year.
Apple, on the other hand, went in the opposite direction. It introduced a limit and a 30-day waiting period for submissions through its security portal, requiring anyone wishing to submit more to make a special request. This change was implemented because AI-driven discoveries had overwhelmed its review teams and were overshadowing human researchers, according to the Financial Times.
The financial implications are significant. The security firm Bynario discovered a critical macOS vulnerability that allowed a remote attacker to create files and execute commands as root. However, they were unable to report the flaw promptly since they had reached Apple’s limit after submitting 50 bugs in just three weeks.
Apple contacted them directly for remediation. Interestingly, Bynario had identified the bug using AI.
Google opted for a third route by revamping its Android and Chrome reward structure. It now offers higher rewards for complex and novel exploits that AI is still incapable of generating, and lower rewards for the more routine issues that AI can handle. The company announced the retirement of bonuses for techniques that have become "almost routine" due to AI. Additionally, it prefers concise, specific reproducers over the lengthy reports typically produced by AI.
The underlying issue revolves around finances. Bug bounties were originally structured around the limited expertise of humans, but AI has made both the detection and reporting of bugs inexpensive. This surplus of low-quality submissions is also affecting the public vulnerability database. Meanwhile, AI is successfully identifying significant flaws at scale, relentlessly scanning for bugs while also producing noise.
For defenders, the benefit is substantial. An AI bug-hunter assisted in uncovering a master key that grants access to every database within Microsoft’s Azure Cosmos DB. Anthropic’s Claude identified flaws in cryptographic algorithms that had been overlooked by experts. The challenge now lies in distinguishing meaningful signals from the overwhelming noise. Each of the big three has adopted a different strategy to address this issue, and none appears to be a definitive solution.
Published August 5, 2026 - 1:07 pm UTC
Back to top
Other articles
AI is overwhelming bug bounty programs. Apple sets limits, while Microsoft offers payments.
Apple limited its bug bounty in response to a surge of AI-generated submissions, coinciding with Microsoft offering a record $20 million. Meanwhile, Google adjusted its pricing to incentivize the discovery of more challenging bugs.
