AI models are getting so good at finding security vulnerabilities that companies are calling them just as capable as "elite security researchers." Just last week, we covered how security researchers used Anthropic's Claude to help break into OpenAI's systems. As a result, Intel has now suspended its bug bounty program, which once paid human researchers up to $100,000 per vulnerability.
The original program launched as an invite-only initiative before opening to all security researchers in 2018, covering hardware, firmware, software, and open-source projects. In 2020 alone, nearly half of the CVEs Intel addressed, 105 out of 231, came through the bounty program.
Popular Now: GTA 6 map recreated in GTA 5 using assets from Rockstar's 2022 breach
The old bounty board split vulnerabilities into four tiers. Tier 1 paid between $2,000 and $100,000, Tier 2 offered $1,000 to $30,000, Tier 3 ranged from $500 to $10,000, and Tier 4 paid between $250 and $5,000. As recently as January 2026, Intel said it was evaluating enhanced bounty criteria. Eight months later, those bounties have gone from evaluation to suspension.
Intel has not provided an official explanation for why it suspended the bug bounty program, but the timing suggests AI-assisted vulnerability research as a possible factor. AI tools can now scan hardware and software protection layers, identify weaknesses, and flag them at a scale and speed that makes traditional human-researcher bounty programs difficult to manage. If Intel's internal tooling can already run that kind of analysis continuously, paying external researchers to do what machines can do faster could start to look like an unnecessary expense.

That said, the Linux kernel has seen CVEs surge from around 500 per release to nearly 2,000, with Linus Torvalds saying that duplicate AI-generated reports have made the kernel security list "almost entirely unmanageable." Curl shut down its bug bounty program after being flooded with low-quality automated submissions. HackerOne's Internet Bug Bounty program paused new submissions earlier this year, explicitly citing AI-assisted research as expanding vulnerability discovery faster than the system can process it.

Frequently Asked Questions
Open a question for an answer from TweakTown's coverage of this news, or ask your own below.
What kinds of Intel products are covered by the new Intigriti disclosure program?
How does Intel’s no-reward disclosure program differ from its old paid bug bounty in practice?
Are security researchers still allowed to report hardware, firmware, software, and open-source vulnerabilities to Intel?
What happened to Intel’s bounty tiers and payout ranges after the suspension?
Have a question that isn't listed here? Ask below, and TweakBot will answer it.
Researchers can still submit vulnerabilities through Intel's new Intigriti program. They just should not expect to be paid for them.







