Microsoft Expands Bug Bounty Program with AI, Hits $20M Record
Microsoft announced that its bug bounty program, bolstered by AI technologies, paid over $20 million to security researchers between July 2025 and June 2026. This marks a new record for the tech giant, surpassing the previous $17 million payout and engaging 562 researchers, as reported by The Register.
The jump in bounty payouts follows Microsoft's decision to expand its program in December 2025. This expansion included a policy that allows for "In Scope By Default" reports, enabling submissions involving third-party or open-source code affecting Microsoft's services. The change led to a considerable increase in eligible vulnerabilities.
AI advancements played a pivotal role in this achievement, aiding in the discovery of vulnerabilities both internally and by external participants. As per The Register, the introduction of AI has notably increased the frequency and volume of vulnerability submissions, contributing to a crowded Patch Tuesday with 622 vulnerabilities in July 2026.
Executives from Microsoft acknowledged that AI's involvement in security research has significantly impacted the company's operations. They have implemented automated patching tools to assist customers in managing the uptick in updates, although some issues with machines post-update remain unaddressed, according to TechCrunch.
Beyond the expanded participation, the program faced challenges such as handling submissions from individuals disgruntled with Microsoft's handling of their reports. A notable case involved a researcher, NightmareEclipse, who published vulnerabilities openly, bypassing responsible disclosure protocols to protest perceived mistreatment by Microsoft.
Microsoft's willingness to incorporate AI into their bug bounty program underscores a broader industry trend toward utilizing advanced technologies to enhance cybersecurity. This move aims to mitigate risks and capitalize on the community’s expertise through ethical hacking initiatives.
Looking ahead, Microsoft's approach appears to set the stage for continued integration of AI models in security research, potentially paving the way for larger scales of vulnerability management and ethical hacker collaboration.