OpenAI Launches Public Safety Bug Bounty Program
OpenAI launched a public Safety Bug Bounty program to identify AI abuse and safety risks across its product suite.
OpenAI launched a public Safety Bug Bounty program to identify AI abuse and safety risks across its products. The initiative operates alongside the company's existing Security Bug Bounty but specifically targets vulnerabilities that might not be traditional security flaws but could still enable meaningful abuse.
The program focuses on three primary areas: agentic risks, including third-party prompt injection and data exfiltration; the exposure of proprietary company data or reasoning information; and the evasion of platform integrity controls, such as anti-automation bans. To qualify for the agentic risk category, identified behaviors must be reproducible at least 50% of the time.
OpenAI excludes general content-policy bypasses and basic jailbreaks from the public scope. However, the company maintains separate private campaigns to address high-risk issues, including biorisks associated with ChatGPT Agent and GPT-5. The company is currently inviting ethical hackers and researchers to report findings to its safety and security teams.