Google’s AI bounty program pays bug hunters up to $30K
On Monday, Google launched a new reward program dedicated specifically to finding bugs in AI products. Google’s list of qualifying bugs includes examples of the kind of rogue actions it’s looking for, like indirectly injecting an AI prompt that causes Google Home to unlock a door, or a data exfiltration prompt injection that summarizes all of someone’s email and sends the summary to the attacker’s own account.
The new program clarifies what constitutes an AI bug, breaking them down as issues that use a large language model or a generative AI system to cause harm or take advantage of a security loophole, with rogue actions at the top of the list. This includes modifying someone’s account or data to impede their security or do something unwanted, like one flaw exposed previously that could open smart shutters and turn off the lights using a poisoned Google Calendar event.
Simply getting Gemini to hallucinate will not cut it. The company says that issues related to content produced by AI products — such as generating hate speech or copyright-infringing content — should be reported to the feedback channel within the product itself. According to Google, that way its AI safety teams can “diagnose the model’s behavior and implement the necessary long-term, model-wide safety training.”
Along with the new AI reward program, Google also announced on Monday an AI agent that patches vulnerable code called CodeMender. The company says it has used to patch “72 security fixes to open source projects” after vetting by a human researcher.
The $20,000 prize is awarded for rooting out rogue actions on Google’s “flagship” products Search, Gemini Apps, and core Workspace applications like Gmail and Drive. Multipliers for report quality and a novelty bonus are also available, which could bring the total amount up to $30,000. The price drops for bugs found on Google’s other products, like Jules or NotebookLM, and for lower-tier abuses, such as stealing secret model parameters.
On Monday, Google launched a new reward program dedicated specifically to finding bugs in AI products. Google’s list of qualifying bugs includes examples of the kind of rogue actions it’s looking for, like indirectly injecting an AI prompt that causes Google Home to unlock a door, or a data exfiltration…
Recent Posts
- Canada Prime Minister Mark Carney announces questionable national AI strategy
- Kevin O’Leary agrees to downsize massive Utah data center
- This HP Omen 16 deal with RTX 5050 graphics is a steal for video editing — and I can’t find it cheaper anywhere else
- Amazon’s new plan for games: James Bond and AI Snoop Dogg
- How to watch France vs Ivory Coast: FREE streams, TV channels for World Cup 2026 warm-up
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023