Apple's bug bounty program, which pays vetted outside researchers for real security flaws, will cap submissions and add a 30 day cooldown after AI generated reports overwhelmed reviewers.
Apple's bug bounty program, which pays vetted outside researchers for real security flaws in its software, will now cap submissions and add a 30-day cooldown between reports, the Financial Times reported. The change, detailed in Apple's bounty program guidelines, targets a backlog of low-quality reports that AI-powered scanners produce at industrial volume.
When a single automated scan flags thousands of potential issues, most of which turn out to be false positives or simple misreadings of how the code actually works, the scarce resource is no longer the researchers. It is the human reviewers triaging every submission. Apple's response, a cap plus a 30-day buffer plus a formal exception request for researchers who need to exceed it, is a redesign of how outside research reaches the security team, part of the program's longer evolution toward higher-impact findings.
Google made the same move earlier in 2026, shifting rewards toward complex challenges rather than vulnerabilities an AI can find in minutes. Two programs arriving at the same remedy suggests cap-and-cooldown is becoming the default shape of AI-era research programs.