Apple Caps Bug Bounty Submissions as AI-Generated Reports Flood the Queue

Apple has imposed a submission cap and a 30-day cool-off period on its bug bounty program, responding to a flood of AI-generated security reports that have overwhelmed review teams and risked burying vulnerabilities found by human researchers (Engadget, Financial Times).
The changes apply to submissions made through Apple's internal security portal. Researchers who hit the cap must file a special request to continue submitting reports beyond the limit (Engadget). The Financial Times confirmed the program adjustments (Engadget).
The catalyst is what 9to5Mac characterized as a surge of "AI slop" — AI-generated security reports flooding the bounty queue (9to5Mac). Automated tools, likely built on large language models (LLMs), can scan for potential vulnerabilities and file formatted reports at a volume no human team can manually sort through. Apple's security engineers now face two challenges at once: processing the high volume of submissions and telling the difference between AI-generated noise and reports that describe real, exploitable flaws.
The concern is not purely hypothetical. Apple and the security firm Bynario agreed that a GPT-5.5 system identified a genuine macOS bug, confirming that AI-generated reports can surface legitimate vulnerabilities (The New Stack). That case cuts both ways: it validates the use of AI in vulnerability research while illustrating why the submission pipeline is straining. If an AI system can produce both valid findings and plausible-looking false positives at scale, the bottleneck shifts from finding bugs to verifying them.
Apple's bounty program offers rewards of up to $200,000 for critical security bugs in its products (Reuters). At those payout levels, the economic incentive to automate report generation is straightforward. An operator who can use an LLM to draft and file dozens of candidate vulnerability reports faces minimal cost per submission. The review burden, however, falls entirely on Apple's side.
Google has already moved to address the same structural pressure. Earlier this year, the company overhauled its Android and Chrome Vulnerability Rewards Programs to emphasize that difficult-to-solve problems earn bigger payouts than the small bugs AI tools can easily identify (Engadget, Google Bug Hunters Blog). Google's approach redirects incentive structures rather than throttling volume. Apple's cap-and-cool-off model is a rate-limiting response to the same problem.
The two strategies reveal a shared underlying tension. Bug bounty programs were designed around a model where skilled researchers invested significant manual effort per submission, and rewards were calibrated to that effort. LLM-driven tooling compresses the cost of producing a formatted, plausible-looking report toward zero. Without adjustment, the programs become a sorting nightmare for vendors and a low-cost lottery for automated submitters.
Apple's rate-limiting approach buys time but does not resolve the verification problem. A cap on submission count does not improve the quality of individual reports. The cool-off period may slow the inflow enough for review teams to keep pace, but the core challenge remains: each AI-generated report still requires human expertise to validate or reject. Google's restructuring of payout tiers addresses the incentive side more directly, steering the ecosystem toward high-difficulty findings that automated tools are less likely to produce on their own.
The broader concern here is that rate limits may disproportionately affect legitimate high-volume researchers. Security professionals who methodically work through a product's attack surface may file many valid reports in a short window. A submission cap, however generous, creates friction for exactly the cohort the program is designed to reward. The special-request mechanism mitigates this somewhat, but it introduces a gating step that could slow time-to-payout for valid findings.
The Bynario case suggests a more nuanced path forward. If AI systems can identify real vulnerabilities, the question for vendors shifts from how to exclude AI-generated reports to how to sort through them efficiently. That might mean automated validation pipelines, structured submission formats that machine-generated reports must satisfy, or tiered review processes that fast-track reports meeting higher confidence thresholds. Apple and Google have each taken a first step, but neither has fully addressed the verification bottleneck.
For now, Apple's message to the security research community is direct: the portal has a throughput limit, and the queue is full. Whether caps and cool-offs remain the right tool as AI-driven vulnerability research matures is an open question. The industry will likely need more than rate limiting to keep bounty programs functional when the cost of generating a report continues to fall.


