Apple has begun limiting how many vulnerability reports researchers can submit through its bug-bounty program as the company struggles to keep pace with a wave of AI-related security findings, the Financial Times reported on August 2. The cap is an unusual concession from a company that has historically bragged about the openness of its security channels.
Why the Backlog
Two trends collided. First, the broader boom in AI security research has produced more reports across all software vendors - Apple disclosed that the number of AI-related submissions it received in the first half of 2026 was higher than in any previous full year. Second, Apple's own expanding AI surface - Apple Intelligence, on-device LLMs, and privacy-preserving inference pipelines - has given researchers more to probe. The result is a triage backlog that Apple engineers can no longer clear.
"We're not closing the door. We are asking people to be selective about which doors they knock on," an Apple security lead told the FT.
The New Rules
Researchers can now submit a maximum number of reports per quarter, and Apple is asking that duplicate or low-severity findings go to a separate, lower-priority queue. The company has also raised bounty payouts for high-severity AI-related issues to clear its most important backlog first. Independent researchers said the change is reasonable but warned that smaller labs and one-off finders may simply stop reporting to Apple altogether.
The Industry Pattern
Apple is not alone. Cisco patched a Secure Firewall Management Center zero-day this month that had been exploited in the wild, and Apple-related vulnerabilities were among the 87 patched in iOS 26.6 in July. The FT piece notes that AI security work has matured from a niche sub-field into a discipline in its own right, and bug-bounty programs are being forced to adapt.
Comments (0)
Log in or sign up to leave a comment.
No comments yet. Be the first to share your thoughts.