TL;DR: AI is compressing researcher workflow, increasing new submitter activity and raising total vulnerability volume, while Intigriti says validity ratios have remained broadly stable, according to INTIGRITI. The operational pressure shifts to triage, where context, duplication checking, and prioritisation now matter more than assuming AI automatically means worse submissions.
NHIMG editorial — based on content published by INTIGRITI: Common AI misconceptions debugged!
By the numbers:
- From 2022 to 2025, submissions grew by 328%.
- New researchers are producing almost double the submissions in their first 30 days compared with a year earlier.
- As of February 2026, Intigriti saw a peak driven primarily by higher per-user submission rates.
Questions worth separating out
Q: How should security teams handle faster submission volumes in bug bounty programmes?
A: They should treat faster submission volumes as a capacity and triage-design issue, not just a researcher-quality problem.
Q: Why do AI-assisted researchers change bug bounty operations more than submission quality?
A: AI mainly changes speed.
Q: What do security teams get wrong about AI-generated penetration testing findings?
A: The main mistake is treating AI output as proof rather than as a lead.
Practitioner guidance
- Rebaseline triage capacity against AI-driven throughput Measure submission volume, duplicate rate, and average time-to-decision separately for new and established researchers, then size reviewer coverage to the higher of the two paths.
- Segment newcomer handling from experienced-researcher handling Create a distinct review path for first-time submitters that emphasises scope validation, duplicate detection, and clearer feedback loops.
- Use AI to compress context gathering, not to replace judgment Deploy AI support to surface similar reports, extract key indicators, and prefill triage notes, but keep the final verdict with trained reviewers.
What's in the full article
INTIGRITI's full article covers the operational detail this post intentionally leaves for the source:
- Monthly submission metrics and growth curves that show how researcher throughput changed over time
- Intigriti’s internal triage workflow examples, including the way AI decision support is used in validation
- The company’s handling of first-time submitters, duplicates, and validation quality at scale
- Product-direction context on how the platform is being adapted for higher submission volumes
👉 Read INTIGRITI's analysis of how AI is changing bug bounty researcher behaviour →
AI in bug bounty: what higher throughput means for triage teams?
Explore further
AI-assisted research is a throughput problem before it is a quality problem. The article’s core claim is that more submissions do not automatically mean worse submissions, and that distinction matters for governance. For security leaders, the relevant issue is whether the programme can absorb faster human and tool-assisted activity without losing review discipline. The practical conclusion is that triage maturity now matters as much as bounty demand.
A question worth separating out:
Q: How do you know if bug bounty triage is actually working?
A: Look for stable or improving validity ratios alongside shorter time-to-decision, lower duplicate fallout, and consistent handling across new and established researchers. If submissions rise but closure quality falls, the workflow is not scaling its context and review capacity fast enough.
👉 Read our full editorial: AI-assisted bug bounty is increasing throughput, not degrading quality