Apple is limiting some bug-bounty submissions after unvalidated AI findings increased the volume of reports in its review queue. Introduced in June, the restriction limits how many vulnerability reports each researcher can keep open at once. AI-assisted findings still require proofAI slop reports can look polished while relying on hallucinated, theoretical, or poorly tested findings. These submissions reach bug-bounty programs without enough evidence for reviewers to reproduce the issue or assess its impact. Under those rules, the company can pause a researcher’s open reports for 180 days after repeated unvalidated AI submissions.