Apple limits bug bounty submissions amid flood of AI-generated reports
Apple has introduced new limits on its bug bounty program, including a cap and a 30-day cooldown period, in response to the overwhelming number of AI-generated vulnerability reports. The move aims to prevent review teams from being swamped and ensure human-discovered bugs remain visible.

Apple has updated the rules of its bug bounty program to restrict how many submissions an individual or organization can make. According to the Financial Times, the change comes as a response to the surge in findings produced by artificial intelligence tools. While AI can be effective at identifying programming flaws, the massive volume of such reports has strained review teams and potentially overshadowed vulnerabilities found by human security researchers.
The company stated that the adjustments include "a cap and a 30-day cool-off period on submissions through its internal security portal." Anyone wishing to exceed the cap will need to submit a special request to do so. This mechanism is intended to filter out low-quality automated reports and give priority to genuinely significant bugs.
Apple is not alone in revising its approach to crowdsourced security research in the age of AI. Google also overhauled its bug bounty program earlier this year, emphasizing that difficult-to-solve issues earn higher rewards than the trivial bugs that AI can easily detect.


