Rise of the robo-bounty hunters: Prepare for AI-enabled vulnerability disclosures
Although public interest in the latest generation of frontier AI models has largely focused on the prospect of rogue AI agents hacking into networks, improving themselves without human intervention or control, and developing their own religions, a less visible but highly pervasive human use of new AI tools has increasingly been causing churn and expense for a wide variety of companies: vulnerability disclosures by individuals who present themselves as security researchers. Typically, they contact one or more individuals at a company, claim to have found a defect in the company’s security (such as sensitive data accessible from the open internet), and provide some proof. From there, they may mention that they might blog about the defect or otherwise expose it publicly, ask about the company’s plans to remediate the issue, ask to speak to a company official, and raise the question of payment.
This is not a new concept and should not be dismissed as the work of criminals. Responsible disclosure of security vulnerabilities is important to cybersecurity, and many companies run vulnerability disclosure programs, also known as “bug bounty” programs, to establish guardrails for external researchers and provide a framework for disclosure and compensation.
WIRED Magazine recently reported that the emergence of ever-more-capable agentic AI models has “flooded” companies’ existing vulnerability disclosure programs and quoted one researcher who estimated that he had submitted three times as many “bugs” this year as he did the year before. The same researcher predicted a surge in submissions of “low- and medium-hanging fruit” in the near term.
This substantial uptick has several consequences for the private sector. Companies that already have bug-bounty programs are faced with a higher volume and faster pace of disclosures. And those disclosures may be a mix of a lot of low-quality submissions and some potentially highly consequential vulnerabilities. As the cost of entry and skill required to conduct security research drop, individuals representing themselves as “researchers” may be less professional or responsible than their more established peers. As a result, companies with existing bug-bounty programs may have to rework their internal processes and external incentive structures to manage these changes.
Companies that have no bug-bounty program face particular risk. They can be caught flat-footed when a researcher contacts them to report a vulnerability and suggests (or demands) payment. The company will not have set any ground rules (such as what methods and actions are and are not authorized when searching for vulnerabilities) or established expectations about its response or payment, which gives the researcher latitude to try to set their own terms. At the same time, if a company lacks internal processes and a game plan for managing incoming vulnerability disclosures, it will have to create a process and standards on the fly. That not only takes the time and resources of executive, legal, technical, and communications personnel but also unnecessarily forces decisions to be made under time and other pressures.
Companies should quickly move to review and update existing vulnerability disclosure programs in light of the surge in disclosures that has already begun. Companies that have no program should design, implement, and publicize those programs carefully but without undue delay.
Several priorities warrant particular attention:
Vulnerability disclosure programs that can handle AI-enabled security research are critical. As vulnerability reports grow more numerous, varied, and difficult to assess, and as security researchers’ tools improve, companies should set clear expectations and be ready to respond.
The information provided is not intended to be a comprehensive review of all developments in the law and practice, or to cover all aspects of those referred to.
Readers should take legal advice before applying it to specific issues or transactions.