sakutto
Generative AI

How Apple Handles AI-Generated Bug Reports: A 180-Day Pause

AppleSecurityAI Adoption
How Apple Handles AI-Generated Bug Reports: A 180-Day Pause

How AI-generated reports are treated in Apple's bounty programme

Apple Security Bounty pays researchers who find and report vulnerabilities in Apple products and services — a bug bounty, in the usual industry term.

Its official guidelines carry several statements about reports involving AI. What is being restricted is not the use of AI. The line is drawn at whether a person validated the finding.

AI-related provisions in the official guidelines

Writing the report
Avoid lengthy descriptions generated by AI tools
Ineligible reports
Issues discovered by AI without proper validation count as infeasible reports
If repeated
Processing of your reports may be paused for 180 days
If pauses accumulate
More than two pauses may mean permanent removal from the programme
During a pause
No rewards, no credit, and reports generally not processed
Stated background
Many reports arrive generated by LLMs without validation by a person

"Discovered by AI without proper validation" is named explicitly

The list of ineligible reports includes this entry: theoretical issues, and issues discovered by AI without proper validation. Apple classifies these as infeasible reports.

The wording rewards careful reading. It says not "issues discovered by AI" but "issues discovered by AI without proper validation." How you found it is not in question. Submit it after a person has reproduced it and confirmed it works, and having used AI is not an obstacle.

View official source →
Infeasible reports, such as reports of theoretical issues or issues discovered by AI without proper validation. / Reports that are incomplete or not actionable, even if you were the first to report — such as reports without a reliable way to reproduce the issue. — From the list of reports ineligible for a reward

What triggers the 180-day pause, and what it means

It is not written as an immediate pause on a single ineligible report. The condition is repeated submission, and the language is that Apple may pause processing.

The condition and the stages

Condition
Repeatedly submitting ineligible reports (including theoretical issues and unvalidated AI findings)
Stage 1
Processing of your reports may be paused for 180 days
Stage 2
More than two paused periods may mean permanent removal from the programme

A high enough standard of evidence still gets processed

What a pause involves is spelled out. You are ineligible for bounty rewards and for credit in security advisories, and your reports will not be processed.

But an exception is written in. A report that captures the applicable Target Flag, or that demonstrates the issue with a fully packaged virtualisation of iOS or macOS, will still be processed. A Target Flag is a marker Apple places in specific locations so a researcher can show that an attack — a privilege escalation, say — actually landed.

So the pause is not designed to close the gate. It is designed to raise the standard of evidence. Assertions do not get through; something that demonstrably works does.

The stated background matches. Apple says it receives many reports claiming to be about serious security or privacy issues that were generated by large language models and submitted without the required proof or validation by a person, and that investigating them can prevent it from acting quickly on genuinely critical issues.

View official source →
If you repeatedly submit ineligible reports — including infeasible reports about theoretical issues or those discovered by AI without proper validation — we may pause processing your reports for 180 days. Researchers with more than two paused status periods may be permanently removed from the Apple Security Bounty program. / We receive many reports claiming to be about serious security or privacy issues, but that are generated by LLMs and submitted without the required proof or validation by a person. Investigating these and other ineligible reports can prevent us from acting quickly to resolve serious and critical security issues. / If your status in Apple Security Bounty is paused, you are ineligible for bounty rewards or credit in security advisories during this time. We will not process your reports, unless your report clearly demonstrates the security or privacy issue by capturing the applicable Target Flag or with a fully packaged virtualization of iOS or macOS. — From the pause condition, the stated background, and what applies during a pause

What Apple means by a "complete and actionable" report

So what should you submit? The guidelines set out the requirements concretely.

A working exploit, or a reliable proof of concept

What is asked for is a working exploit or a reliable PoC — a proof of concept, the minimal implementation showing the issue actually holds. Alongside it you need to explain the conditions required to start the attack and the control, data, or privilege you gain by the end of it.

And at minimum, a concise, numbered list of steps required to reproduce the issue is set as the floor.

There is a line about how to write it, too: avoid lengthy descriptions generated by AI tools. That is not a limit on volume but a standard for density — leave only what a reader can use to confirm the finding. Whether a report has run long is easier to notice once you actually count it.

Free ToolCharacter CounterCount characters, words, lines, and bytes in real time. Great for social media posts and reports.Try it now →

Note that only the first report qualifies. For any given issue, only the first complete and actionable report Apple receives is eligible for a reward, even if it is not the first or only report received. The test is not who reported first, but who first filed a complete and actionable report. Part of why volume-based tactics do not work here is this design.

View official source →
A working exploit that explains the conditions required to start the attack and the control, data, or privilege you gain by the end of the attack — or a reliable proof of concept (PoC) for the issue you’re reporting. Your report must at least include a concise, numbered list of steps required to reproduce the issue. / Avoid lengthy descriptions generated by AI tools. / Only the first complete and actionable report we receive for an issue is eligible for a reward, even if it’s not the first or only report we receive. — From the report requirements, the note on AI-generated descriptions, and which report qualifies for a reward

The reported submission cap and 30-day cooloff are not in the official guidelines

There is also reporting that Apple set a cap on how many reports can be submitted, with a 30-day waiting period once the cap is hit (9to5Mac, August 3, 2026, which credits the Financial Times). This article does not cover that.

The reason is simple: no submission cap and no 30-day figure appear in Apple's public guidelines. What the official text sets out, as above, is a 180-day pause on processing in response to repeated ineligible reports — not a limit on the number of submissions.

The two resemble each other but are different mechanisms. One is a pause conditioned on report quality; the other is a restriction on volume. Blend them and a constraint Apple has not published starts to look like established fact. If a submission cap is officially announced, we will cover it then.

Conclusion: drawing a line around plausible-looking AI output

What this text establishes is that Apple is not prohibiting AI; it is pinning the responsibility for validation on a person. How you found it does not matter. Showing that it works stays a human job. That way of drawing the line fits what a bounty programme is.

Output that looks plausible but is not correct slipping through mechanical checks happens in other fields too. An AI-assisted mathematical "disproof" that got accepted by exploiting a bug in the checker — the Collatz case — is the clearest example. Polish and correctness are different things.

In security reporting, the thing that closes that gap is reproducibility. Apple naming Target Flags and full virtualisation as the specific exceptions during a pause is that policy — demonstration rather than assertion — pushed down to the level of operations.

Free ToolCharacter CounterCount characters, words, lines, and bytes in real time. Great for social media posts and reports.Try it now →

FAQ

Q. Can bugs found with AI not be reported at all?
Reporting them is not prohibited. What is ineligible is a report where something AI found was submitted without a person validating it. The guidelines list theoretical issues and issues discovered by AI without proper validation as infeasible reports, and therefore ineligible for a reward. Turn that around: if a person has reproduced and verified it, having used AI to find it is not itself a problem.
Apple Security Bounty Guidelines — Ineligible Reports
Infeasible reports, such as reports of theoretical issues or issues discovered by AI without proper validation. Apple Security Bounty Guidelines — Ineligible Reports
Q. When does Apple stop processing your reports?
When ineligible reports are submitted repeatedly. Apple states it may pause processing your reports for 180 days if you repeatedly submit ineligible reports, including infeasible ones about theoretical issues or those discovered by AI without proper validation. It further states that researchers with more than two paused status periods may be permanently removed from the programme.
Apple Security Bounty Guidelines — Repeated submissions of ineligible reports
If you repeatedly submit ineligible reports — including infeasible reports about theoretical issues or those discovered by AI without proper validation — we may pause processing your reports for 180 days. Researchers with more than two paused status periods may be permanently removed from the Apple Security Bounty program. Apple Security Bounty Guidelines — Repeated submissions of ineligible reports
Q. What happens during a pause?
You are ineligible for bounty rewards and for credit in security advisories, and reports submitted during that time will not be processed. There is one exception: a report that clearly demonstrates the issue by capturing the applicable Target Flag, or with a fully packaged virtualisation of iOS or macOS, will still be processed. A route stays open if the standard of evidence is high enough.
Apple Security Bounty Guidelines — Repeated submissions of ineligible reports
If your status in Apple Security Bounty is paused, you are ineligible for bounty rewards or credit in security advisories during this time. We will not process your reports, unless your report clearly demonstrates the security or privacy issue by capturing the applicable Target Flag or with a fully packaged virtualization of iOS or macOS. Apple Security Bounty Guidelines — Repeated submissions of ineligible reports
Q. How much detail does a report need?
A working exploit or a reliable proof of concept. You need to explain the conditions required to start the attack and what you gain by the end of it, and at minimum include a concise, numbered list of steps to reproduce the issue. Apple also asks you to avoid lengthy descriptions generated by AI tools. The bar is reproducibility, not length.
Apple Security Bounty Guidelines — Report criteria
A working exploit that explains the conditions required to start the attack and the control, data, or privilege you gain by the end of the attack — or a reliable proof of concept (PoC) for the issue you’re reporting. Your report must at least include a concise, numbered list of steps required to reproduce the issue. Apple Security Bounty Guidelines — Report criteria

Related Tools

Related Tool Categories

Articles