TL;DR: AI is changing bug bounty work by helping researchers uncover new classes of flaws, but it is also raising the cost of participation through token consumption and competitive pressure, according to INTIGRITI’s discussion with Leo Racanelli. The bigger issue is that AI-assisted testing is becoming part of the security operating model, which forces teams to rethink how they scope, validate, and budget for discovery.
NHIMG editorial — based on content published by INTIGRITI: Securing the uncharted territories of AI systems, a discussion with Leo Racanelli
Questions worth separating out
Q: How should security teams validate AI-assisted bug bounty findings?
A: Security teams should require independent reproduction on the live or test target, with the researcher providing environment details, exact steps, and proof from the system itself.
Q: Why do AI-enabled applications create more security uncertainty than standard APIs?
A: AI-enabled applications accept unstructured input, produce probabilistic output, and often connect to other tools or data sources.
Q: What do security teams get wrong about AI safety testing?
A: The common mistake is treating AI safety testing as if it were just another security scan.
Practitioner guidance
- Define AI-assisted testing policy Set rules for when AI may be used in discovery, how findings are validated, and what evidence is required before triage accepts a report.
- Map AI touchpoints to privileged actions Identify where chatbots, assistants, or model outputs can trigger internal tools, data access, or workflow changes, then require explicit control gates at those points.
- Budget for model-assisted research Plan token and compute budgets for security testing so coverage does not depend on who can afford more iteration during live events or assessments.
What's in the full article
INTIGRITI's full blog covers the operational detail this post intentionally leaves for the source:
- Leo Racanelli’s first-hand examples of how AI changes live bug bounty workflow and target selection.
- More detail on invisible prompt injection techniques and the notes-based research method used during investigation.
- The discussion of token pricing, participation cost, and how that changes the economics of crowdsourced security.
- The source article's forward-looking commentary on where AI-assisted bug bounty programs may go next.
👉 Read INTIGRITI’s discussion on AI’s impact on bug bounty workflow and research →
AI bug bounty workflows: what changes for security teams now?
Explore further