On Monday, Google launched a new bug bounty program specifically dedicated to finding bugs in artificial intelligence (AI) products. Google's list of eligible bugs includes examples such as indirectly inserting an AI prompt that causes Google Home to unlock a door or inserting a data extraction command that summarizes all of someone's emails and sends the summary to the attacker's account .
See also: Zeroday Cloud: Hacking contest with bug bounties of $4.5 million.

The new program clarifies what constitutes an AI bug, separating them into issues that use a large language model or generative AI system to cause harm or exploit a security vulnerability (with malicious actions at the top of the list). This includes modifying someone’s account or data to compromise their security or do something undesirable (e.g., a previously disclosed flaw that could open smart shutters and turn off lights using a poisoned Google Calendar event).
Bug hunters have already raised over $430,000 over the course of two years, since the company officially began inviting AI researchers to identify potential ways to abuse AI features in its products.
See also: HackerOne: $81 million in bug bounties in the last year

Google AI bug bounty: Clarifications
Creating “hallucinations” in Gemini isn’t enough. The company says that issues related to content generated by AI products — such as the creation of hate speech or content that infringes copyright — should be reported to the feedback channel within the product itself. According to Google, this way AI security teams can “diagnose the model’s behavior and implement the necessary long-term, large-scale security training.”
The $20,000 prize is awarded for finding malicious actions in Google's top products, such as Search, Gemini apps, and core Workspace apps like Gmail and Drive. There are also multipliers for report quality and an innovation bonus, which could bring the total up to $30,000. The price is reduced for bugs found in other Google products, such as Jules or NotebookLM, and for lower-level abuses, such as stealing secret model parameters.
See also: ARGUS Robot: Prevents cyber threats and physical intrusions

Along with the new AI bounty program, Google also announced on Monday an AI agent that fixes vulnerable code called CodeMender. The company says it has used it to make “72 security fixes to open source projects” after being reviewed by a human researcher.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
