⚡ Uncle Cat AI Radar
IndustrySafetyAgents

Apple caps bug reports as AI-written filings flood in

Apple has imposed a submission ceiling and a 30-day cool-off on Feedback Assistant bug reports, blaming a deluge of AI-assisted findings.

The change

Apple has begun rate-limiting vulnerability disclosure. According to reporting published on 2 August, the company has introduced a cap on how many bug reports an individual can file through Feedback Assistant, paired with a 30-day cool-off period once that ceiling is hit. Researchers with a track record can apply for higher quotas.

Apple's stated reason is volume: a flood of AI-assisted submissions that arrive looking technically credible but do not survive triage. Because a plausible-sounding report cannot be dismissed without human review, each invalid filing consumes the same scarce security-engineering attention as a genuine zero-day, and the ratio has moved sharply in the wrong direction.

The throttle sits awkwardly alongside Apple's simultaneous effort to attract more research. The company raised its maximum bounty to $2 million for zero-click exploit chains last November, with bonuses capable of pushing a single award past $5 million, and says it has paid more than $35 million to over 800 researchers since the programme began.

Not the first

Apple is following, not leading. The curl project and the Internet Bug Bounty had already imposed their own filters after maintainers reported spending disproportionate time refuting machine-generated reports. What is new is scale: this is the first time a vendor of Apple's size has formally rate-limited AI-assisted disclosure, which turns an open-source maintainer complaint into an industry norm.

The move also lands against a broader picture in which AI-discovered flaws are numerous but rarely weaponised. Security firm VulnCheck's first-half 2026 analysis traced 1,061 vulnerabilities to AI-assisted discovery and found confirmed exploitation in just 14 of them.

Why it matters

Bug bounties are one of the few places where AI-generated output meets a hard, adversarial quality gate, and the gate is buckling. If the biggest programmes respond by restricting who may submit and how often, the economics of coordinated disclosure shift toward established researchers and away from the long tail that bounty programmes were designed to recruit — precisely as autonomous security agents make bulk submission trivial. The same dynamic already visible in code review, app stores and social feeds has now reached the vulnerability pipeline: the constraint is no longer finding problems, it is affording to read about them.

Sources