Apple just did something no major tech company has done before. It capped how many bug reports a security researcher can submit, plus added a 30 day cool off period, because the inbox got buried under AI generated submissions.
According to the Financial Times, the problem is not that AI is bad at finding bugs. It is that AI is very good at generating reports that look real but describe vulnerabilities that do not actually exist. Every one of those still has to be read, tested, and ruled out by a human on Apple’s security team.
There’s a real cost to this. An Italian startup called Bynario used ChatGPT to find an actual macOS flaw, one researchers estimate could be worth 100 to 200 thousand dollars on the black market. They tried to report it responsibly. They could not, because Apple’s submission window was already closed from the flood.
So Apple is now rate limiting its own bug bounty program, the same move curl and other open source projects made earlier this year for the same reason. Researchers who need a higher quota can request one.
Here’s the part worth sitting with. This is not AI breaking security research, it is AI changing the ratio of signal to noise so fast that the humans on the other end cannot keep pace with their inbox. Apple is also using AI from Anthropic and OpenAI internally to hunt for its own flaws, and its last update shipped with five times the usual number of fixes.
The tools are getting sharper on both sides of this fight. The system just needs traffic control to catch up, not a reason to slow down. Expect more companies to follow Apple here before the year is out.
——
Follow: @Ali Demi
Book your free AI clarity call, NOW!
https://buff.ly/TpWy277
——
Sources:
https://the-decoder.com/a-real-macos-flaw-worth-200k-went-unreported-because-apples-bug-bounty-inbox-was-full-of-ai-slop/
https://www.digitaltrends.com/computing/ai-is-finding-apple-security-flaws-faster-than-apple-can-sort-through-them/
Repost this. Thanks.

