Bug hunting used to be a test of patience and technical skill. Now it's a test of whether review teams can keep up with AI's output.
According to a report confirmed by the Financial Times, Apple has made changes to its bug bounty program because the sheer volume of AI-generated vulnerability reports has overwhelmed its internal review team. AI is genuinely useful for spotting code flaws, but when submissions of this kind pile up far beyond what teams can handle, genuine findings from human security researchers end up getting lost in the noise.
Per Apple, the changes include "a cap on submissions through the internal security portal, along with a 30-day cooldown period." In other words, there's now a limit on how many bug reports a researcher or team can submit within a given timeframe — and if they want to go beyond that cap, they'll need to file a special request to keep submitting.






