AI

AI found more Apple bugs than Apple could read. So Apple capped the inbox.

Apple quietly added a limit on how many bug reports a researcher can have open at once, plus a 30-day cool-off once you hit it, citing a deluge of AI-assisted submissions. An Italian startup that filed more than 50 findings in three weeks ran into the wall holding a privilege-escalation chain it priced at $100,000 to $200,000. It is the first major vendor to formally rate-limit AI-assisted disclosure.

N Noah · The Sharp Brief · August 2, 2026 · 4 min read

The Financial Times reported Sunday that Apple has put a ceiling on bug reporting. Researchers using Feedback Assistant now hit a cap on how many reports they can have open at one time, and running into it triggers a 30-day cool-off before they can file again. The portal was changed quietly, in June. Apple’s stated reason is the volume of AI-assisted submissions arriving faster than anyone can read them. Researchers who need more room can apply for a higher quota.

This is the part the security industry did not game out. Two years of argument about AI and vulnerability research assumed the fight would be over whether models could find real bugs. They can. The problem is that they also produce enormous quantities of confident, well-formatted reports describing flaws that do not exist — and a triage queue cannot tell the difference without a human reading each one. Apple is not drowning in attacks. It is drowning in paperwork that looks exactly like the real thing.

The cost showed up immediately. Bynario, an Italian security startup, filed more than 50 vulnerabilities to Apple in roughly three weeks using AI-assisted analysis. One of them was a privilege-escalation chain that its team says would hand an attacker full control of a Mac. Chief executive Alfredo Pesoli put the black-market value at $100,000 to $200,000. He could not report it: the account had already been throttled. Apple has since contacted the company directly.

Our take: A rate limit is a triage confession. It treats every report as identical because the reviewer cannot afford to look, which means the throttle lands on the researcher with the real exploit and the researcher with 40 hallucinated ones at exactly the same moment. The binding constraint was never submission volume — it is human verification capacity, and verification is the part of this job that scales the same way generation does. Apple met an automation problem with a manual-era lever. The vendor that fixes this ships an AI triage layer, not a quota.

Apple is late, not first

Open-source maintainers hit this wall a year ahead of the trillion-dollar company. The curl project and the Internet Bug Bounty both throttled submissions after AI-generated reports overwhelmed volunteer reviewers — the difference being that curl is run by a handful of people and Apple is not. What makes this week notable is scale: it is the first time a major commercial vendor has formally rate-limited AI-assisted disclosure rather than absorbing the cost.

Bug bounty programs have always run on an implicit trade. The vendor gets cheap security research; the researcher gets paid only for findings that hold up. That arithmetic worked because writing a plausible-looking vulnerability report was expensive. It is now nearly free, and the cost of separating signal from noise sits entirely on the vendor. Every incentive in the model just inverted.

What to watch

Advertisement

Get the day, decoded — at 7 PM ET

The Sharp Brief: AI, money, business & performance in five sharp minutes. Free.

Free bonus: subscribe today and The 2026 AI Playbook (PDF) lands with your welcome email.

Recommended by 5+ newsletters across AI, markets & business.