Apple Is Limiting Bug Reports Because AI Is Flooding the System

Apple has put a cap on how many bug reports a single person can submit to its security program, and added a 30-day waiting period before they can submit more. The reason: a flood of AI-generated reports has overwhelmed the teams who review them, making it harder to spot real security flaws found by human researchers (Engadget, Financial Times).
The changes apply to submissions made through Apple's internal security portal. Researchers who hit the cap must file a special request to continue submitting reports beyond the limit (Engadget). The Financial Times confirmed the program adjustments (Engadget).
Bug bounty programs are a way for companies to pay outside researchers who find security flaws in their products. Apple offers rewards of up to $200,000 for critical bugs (Reuters). The problem is that AI tools can now generate and file large numbers of plausible-looking bug reports at almost no cost. The site 9to5Mac described the flood as "AI slop" (9to5Mac). Apple's reviewers have to read each report and figure out whether it describes a real vulnerability or just sounds like one.
The concern is not purely hypothetical. Apple and the security firm Bynario agreed that a system called GPT-5.5 identified a genuine macOS bug, confirming that AI-generated reports can surface legitimate vulnerabilities (The New Stack). That cuts both ways: it shows AI can find real flaws, but it also shows why the system is straining. If an AI can produce both real findings and convincing false alarms at high volume, the hard part is no longer finding bugs — it is checking which ones are real.
Google has already moved to address the same problem. Earlier this year, the company changed its Android and Chrome bug reward programs so that harder-to-find bugs earn bigger payouts than the small ones AI tools can easily spot (Engadget, Google Bug Hunters Blog). Google's approach redirects the incentives rather than limiting how many reports people can file. Apple's cap-and-wait approach is a different response to the same underlying issue.
Bug bounty programs were originally designed for skilled researchers who spent significant time on each submission. Rewards were sized to match that effort. AI tools compress the cost of writing a report that looks credible down toward zero. Without changes, these programs risk becoming a sorting nightmare for companies and a cheap lottery for anyone running an automated tool.
Apple's rate-limiting approach buys time but does not solve the core problem. A cap on how many reports someone can file does not make individual reports better. The waiting period may slow things down enough for reviewers to keep up, but every AI-generated report still needs a human to check it. Google's approach, which raises payouts for harder bugs, goes further by steering attention toward the kinds of findings that automated tools are less likely to produce on their own.
There is also a risk worth noting. Rate limits could affect legitimate researchers who file many valid reports in a short period because they are doing thorough work. A submission cap, however generous, creates extra friction for the very people the program is meant to reward. The special-request option helps, but it adds a step that could slow down payment for genuine findings.
The Bynario case points to a possible middle ground. If AI can find real vulnerabilities, the question becomes how to sort through AI-generated reports efficiently rather than how to keep them out. That could mean automated checking systems, required formats that reports must follow, or faster review for reports that meet a higher confidence bar. Apple and Google have each taken a first step, but neither has fully solved the verification problem.
For now, Apple's message is straightforward: the portal has a limit, and the queue is full. Whether caps and waiting periods are the right tool as AI gets better at finding bugs is an open question. The industry will likely need more than rate limiting to keep these programs working as the cost of generating a report keeps falling.


