Microsoft paid $20M in bug bounties as AI boosts report volume
Microsoft's annual review lists 2,531 eligible reports and 562 rewarded researchers. We examine what the numbers mean for VDPs, AI and triage.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 4 August 2026
- READING TIME
- 9 min read
- TOPIC
- Penetration Testing and AppSec
Microsoft has reported the biggest year for its bug bounty programmes, paying more than $20 million between 1 July 2025 and 30 June 2026. A total of 562 researchers received rewards, with the largest single payout reaching $200,000. The company attributes a rise in submissions during the second half of the period to both community engagement and growing use of AI in security research.
The numbers matter beyond bounty hunters. Automation is moving the bottleneck from discovery toward validation, deduplication, prioritisation and safe patch delivery. An organisation that publishes a form without building triage does not yet have a mature disclosure programme.
What the review covers
Microsoft Security Response Center reports 2,531 eligible submissions across 15 programmes. Researchers participated from 64 countries. The total includes $2.3 million awarded through Zero Day Quest and $800,000 through new initiatives covering areas such as third-party and open-source code.
For comparison, Microsoft paid roughly $17 million in 2024 and 2025 and approximately $13 million annually from 2020 to 2023. A larger budget alone does not prove that products became more or less secure. Programme scope, reward levels, product count and researcher recruitment all changed.
SecurityWeek also notes public disputes over the handling of some reports. A programme should measure not only payouts but also first-response time, decision consistency, duplicate rate, patch latency and communication quality.
How AI changes submission economics
Models can review large repositories, create test variants, reduce cases and explain data flow. That can increase valuable discoveries, but it also creates low-quality reports, automated duplicates and incorrect impact claims.
A useful report still needs a defined asset and version, prerequisites, reproducible evidence, real impact and safe remediation advice. “The model says this code is vulnerable” is not validation. Conversely, a programme should not reject a report merely because its author used AI for analysis or writing.
AI can help the receiving team cluster similar reports, identify missing evidence, route a finding to the component owner and track regression. A competent human should still oversee severity decisions and researcher communication.
Lessons for an internal VDP or bounty
- Start with clear
security.txt, scope and safe-harbour terms. - Provide an urgent route for critical findings and acknowledge receipt.
- Define risk-based triage SLAs rather than only processing arrival order.
- Separate a duplicate from “not a vulnerability” and explain decisions technically.
- Minimise researcher data and restrict access to unpatched vulnerability details.
- Measure time to reproduce, decide, fix and disclose—not just report count.
- Regression-test the patch and inspect sibling components instead of fixing only the supplied example.
- Set AI-use rules on both sides, but judge evidence and impact rather than the author’s tool.
Our guide to VDPs versus bug bounties explains programme choice, while AI coding-agent supply-chain security covers internal engineering controls.
Primary facts versus Breachroad analysis
Microsoft confirms the payout, submission, researcher and country counts, along with its own assessment that AI contributed to volume. The review does not publish a quality breakdown for AI-assisted reports. The data therefore cannot show what percentage of vulnerabilities was “found by AI”.
Breachroad’s conclusion is to prepare triage for higher volume without lowering the evidence standard. Secure software training builds a shared language across development and security, while an IT security audit can assess disclosure, patching and protection of vulnerability information.


