Apple pauses researchers 180 days over AI-generated bug reports
TL;DR
- Apple can pause a researcher's Security Bounty submissions for 180 days if they repeatedly file AI-generated reports without human validation.
- Researchers with more than two paused periods may be permanently removed, and curl and Nextcloud have already suspended paid programs entirely.
- Meta, Microsoft, Apple and Crypto.com collectively paid at least $58 million to security researchers in 2025.
The rules of security research are quietly changing around a problem that barely existed two years ago: bug bounty programs are being buried under AI-generated reports that look serious but don't survive review. A Financial Times report lays out how Apple, curl and Nextcloud are among the programs pushing back, and Apple's response has teeth. Under its Security Bounty guidelines, Apple can pause a researcher's reports for 180 days for repeatedly submitting ineligible findings, including issues discovered by AI without proper validation, and researchers with more than two paused periods can be permanently removed.
The scale is the striking part. Bugcrowd, the platform whose clients include OpenAI, Motorola and T-Mobile, said the number of submissions it received more than quadrupled during a three-week period in March, with most turning out to be false positives or low-quality AI-generated findings. Curl's creator Daniel Stenberg called it an 'explosion in AI slop reports' when he suspended the paid program in January; Nextcloud followed in April, citing a 'massive increase of low-quality reports.' Ross McKerchar, CISO at Sophos, told the FT that the influx of poor-quality reports was 'quickly becoming a major problem.'
Why this matters if you don't run a bounty program: the workaround pattern is going to spread. Meta, Microsoft, Apple and Crypto.com collectively paid at least $58 million to researchers in 2025, so a company the size of Apple documenting a penalty for AI-assisted reports tells you where the industry defaults are heading. Independent researchers who lean on models to draft submissions will need to validate the finding themselves before filing, or lose access to a lucrative channel.
The honest caveat is that the reporting doesn't quantify what share of these programs' inbound is actually AI-generated versus low-quality human reports that always existed, and it doesn't say how many researchers Apple has already paused under the 180-day rule. What the story doesn't answer is whether platforms will build automated triage that filters AI-drafted reports on the way in, rather than punishing submitters on the way out, which is probably where the useful engineering ends up.
Originally reported by ft.com
Read the original article →Original headline: Apple Imposes New Cap and 30-Day Cool-Off on Bug Report Submissions After Deluge of AI-Assisted Reports