Apple caps bug bounty program due to deluge of AI submissions
Apple has introduced limits on submissions to its bug bounty programme after being inundated with reports generated using artificial intelligence, the Financial Times has confirmed. The surge of AI-assisted submissions has reportedly strained the company's review teams and risks burying genuine vulnerabilities identified by human security researchers, prompting Apple to tighten how the scheme operates.
Under the new rules, Apple has imposed a cap and a 30-day cool-off period on submissions made through its internal security portal, with researchers needing to file a special request if they wish to exceed the limit. Apple is not alone in taking this step, as Google similarly revamped its own bug bounty programme earlier this year, shifting incentives towards rewarding harder-to-find flaws more generously than the simpler bugs that AI tools can readily detect.
- Apple limits bug bounty submissions after AI-generated reports overwhelm reviewers
- New cap includes a 30-day cool-off period on the security portal
- Google made similar changes to its bounty programme earlier in 2026