Bug hunting used to be a test of patience and technical skill. Now it's a test of whether review teams can keep up with AI's output.
According to a report confirmed by the Financial Times, Apple has made changes to its bug bounty program because the sheer volume of AI-generated vulnerability reports has overwhelmed its internal review team. AI is genuinely useful for spotting code flaws, but when submissions of this kind pile up far beyond what teams can handle, genuine findings from human security researchers end up getting lost in the noise.
Per Apple, the changes include "a cap on submissions through the internal security portal, along with a 30-day cooldown period." In other words, there's now a limit on how many bug reports a researcher or team can submit within a given timeframe — and if they want to go beyond that cap, they'll need to file a special request to keep submitting.
Apple isn't the only one dealing with this. Google overhauled its own bug bounty program earlier this year, tilting the reward structure toward "hard-to-crack" problems — bugs that AI can't easily sniff out now earn bigger payouts, creating a clearer line between genuinely valuable discoveries and the minor issues AI can churn out in bulk.
Both companies are heading in the same direction: not shutting AI out of bug hunting, but redesigning the system so review resources go toward what's actually worth the time.






