"Abuse Risks are Often Inherent to Product Features": Exploring AI Vendors' Bug Bounty and Responsible Disclosure Policies
This paper analyzes the vulnerability disclosure policies of 264 AI vendors, revealing that many lack clear guidelines or explicitly exclude critical AI-specific risks like jailbreaking and hallucinations, while identifying three distinct vendor profiles and highlighting a significant gap between current industry practices and the urgency of real-world AI incidents.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine the world of Artificial Intelligence (AI) as a massive, bustling city where companies are building new, magical tools every day. Some of these tools can write stories, others can diagnose diseases, and some can even drive cars. But like any new technology, these tools have cracks in their foundations—vulnerabilities.
When a regular software tool breaks, there's a well-established system to fix it: Bug Bounty Programs. Think of these as "Wanted Posters." Companies put up a reward (money) for anyone who finds a hole in their wall and tells them about it, rather than letting a thief sneak in.
This paper is a report card on how well AI companies are putting up these "Wanted Posters" for their new, magical tools. The researchers, from the University of Edinburgh, looked at 264 different AI companies to see if they are ready to handle these new kinds of cracks.
Here is what they found, broken down simply:
1. The "Silent Majority" and the "No-Show"
The researchers found that 36% of AI companies have no "Wanted Poster" at all.
- The Analogy: Imagine walking up to a shop to tell the owner, "Hey, your front door is unlocked," but the owner has no mailbox, no phone number, and no sign saying "Report Issues Here." You just have to guess who to tell, or worse, they might ignore you.
- The Reality: Only 18% of these companies explicitly say, "We accept reports about AI-specific problems." The rest either have generic rules that don't mention AI, or they are completely silent.
2. What Counts as a "Bug"? (The Scope)
The paper discovered that companies are very picky about what they consider a "bug" worth paying for. They drew a line in the sand:
- The "Yes, We'll Pay" List (In-Scope):
- The Analogy: If someone steals your keys, breaks your lock, or sneaks into your bank vault, that's a crime.
- The Reality: Companies are happy to pay for things like stealing data, breaking into the system, or copying their secret AI models. These are traditional security crimes, just happening inside an AI.
- The "No, Not Our Problem" List (Out-of-Scope):
- The Analogy: If you ask a robot to write a poem and it accidentally writes something rude, or if it starts hallucinating (making things up), the company says, "That's just how the robot thinks, not a broken lock."
- The Reality: Companies frequently reject reports about Jailbreaking (tricking the AI into breaking its rules), Hallucinations (AI lying), or Harmful Output (AI being mean or spreading lies). They often claim these are "inherent features" of the product, not bugs.
3. The Three Types of AI Companies
The researchers grouped the 264 companies into three distinct "personalities":
- 🌟 The Proactive Clarifiers (17%):
- Who they are: The big players like Google, Microsoft, and Meta.
- What they do: They have clear signs saying, "Here is exactly what we will pay for, here is what we won't, and here is how much." They even have special guides on how to test their AI safely. They treat AI bugs as a serious, distinct category.
- 🤐 The Silent Ones (44%):
- Who they are: Mostly apps that use AI (like a chatbot in a customer service app).
- What they do: They have a "Wanted Poster," but it's written for old-school software. It doesn't mention AI at all. If you find an AI bug, they might fix it, but they won't tell you if you're eligible for a reward or how they'll judge it. It's like walking into a store where the manager is in the back room and won't come out to talk.
- 🚫 The Restrictive Ones (39%):
- Who they are: Smaller vendors or those who just don't want the hassle.
- What they do: They either have no contact method at all, or they explicitly say, "We do not accept AI bug reports." They might say, "If you try to break our AI, we won't pay you, and we might even get angry."
4. The "Lag" Problem
The paper found a significant time delay, or a "lag," in how the industry reacts.
- The Analogy: Imagine scientists in a lab discovering that a new type of bridge is shaky (Academic Research). Then, people start falling off the bridge (Real-world Incidents). Finally, years later, the bridge company updates their safety manual to say, "Yes, this bridge is shaky, and here is how to report it" (Vendor Policies).
- The Reality: Academic researchers have been studying AI weaknesses for years. Real-world accidents with AI have been happening for a long time. But AI companies are only just now (mostly in 2023 and 2024) starting to update their official rules to acknowledge these specific problems. They are reacting slower than the researchers and the accidents.
5. The Big Disconnect
There is a mismatch between what the public worries about and what companies care about.
- Public Fear: People are mostly worried about AI being mean, spreading lies (misinformation), or being biased (discrimination). These are "Content Safety" issues.
- Company Focus: Companies are mostly worried about "Technical Security" issues like hackers stealing their code or data.
- The Result: If you report that an AI is spreading hate speech, a company might say, "That's not a security bug, that's a safety issue, and we don't pay for that." But if you report that a hacker stole the AI's brain, they will pay you a lot of money.
Summary
The paper concludes that while the AI industry is growing fast, its "safety net" (the bug bounty programs) is still being knitted. Many companies haven't started knitting yet, and the ones that have are mostly focused on catching thieves, not fixing the fact that the AI might be rude or wrong. The researchers suggest that for AI to be truly safe, companies need to stop treating these "rude AI" problems as just "features" and start treating them as bugs that need to be reported and fixed.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.