Recommended Free Tools
Google’s dedicated AI Vulnerability Reward Program (AI VRP) is real, but the headline needs context. Google announced it on October 6, 2025. The highest listed base reward is $20,000 for a flagship-product “S1: Rogue Actions” vulnerability. Report-quality and novelty bonuses can raise an individual payment to as much as $30,000 under Google’s rules. The program targets demonstrable security or abuse impact—not ordinary model mistakes or generic jailbreaks.
What Google actually launched
Google created a dedicated AI VRP instead of leaving AI findings inside its general Abuse VRP. The new program combines qualifying AI abuse and security findings in one reward framework, with a unified panel deciding the applicable category and final amount. Google says researchers had already received more than $430,000 for AI-product-related reports before the dedicated program began.
The announcement is at Google’s AI VRP announcement. Because the launch was in 2025, it is more accurate in 2026 to call this Google’s dedicated AI VRP rather than a newly launched bounty.
How much can a researcher receive?
Google’s published figures describe a base schedule, not a guaranteed price list. The top base reward is $20,000; applicable report-quality and novelty multipliers can increase an individual payment to up to $30,000. Google retains discretion to reject, downgrade, group, or otherwise adjust a report.
#1 Best Overall
| Category | Flagship | Standard | Other |
|---|---|---|---|
| S1: Rogue Actions | $20,000 | $15,000 | $10,000 |
| S2: Sensitive Data Exfiltration | $15,000 | $15,000 | $10,000 |
| A1: Phishing Enablement | $5,000 | $500 | Credit |
| A2: Model Theft | $5,000 | $500 | Credit |
| A3: Context Manipulation | $5,000 | $500 | Credit |
| A4: Access Control Bypass | $2,500 | $250 | Credit |
| A5: Unauthorized Product Usage | $1,000 | $100 | Credit |
| A6: Cross-user Denial of Service | $500 | $100 | Credit |
These amounts come from the announcement. “Flagship,” “standard,” and “other” refer to Google’s product tiers, so the same technical weakness can have a very different base value depending on where it occurs.
Why the ceiling can reach $30,000
Google says it uses report-quality and novelty multipliers from its broader VRP. The general framework lists 0.8× for low-quality reports, 1× for good reports, and 1.2× for exceptional reports. The AI announcement also references novelty bonuses. Those factors do not mean every $20,000 report automatically receives a 1.5× increase; the exact application is discretionary and governed by Google’s current rules.
See the general Google and Alphabet VRP rules for the quality framework.
Which Google products are covered?
Google divides eligible products into broad tiers. The live rules can change, so verify the current product and hostname before testing.
Rank #2
Flagship products
- Google Search
- Gemini applications
- Core Google Workspace applications, including Gmail, Drive, Meet, Calendar, Docs, Sheets, Slides, and Forms
Standard products
- AI Studio
- Jules
- Non-core Workspace products such as NotebookLM and AppSheet
Other AI integrations
Other Google-owned AI integrations may qualify in the “other” tier if they meet the rules and exclusions. A service using a Google model is not automatically eligible: the target must be a Google-owned product or service within the program’s scope.
When should you use the Cloud VRP instead?
Google specifically routes vulnerabilities in Vertex AI and gemini-cli to the Google Cloud Vulnerability Reward Program, not automatically to the AI VRP. Use the Cloud VRP rules when the finding concerns those products or another Cloud-scoped service.
Cloud customer resources are not authorized targets. A Google-hosted hostname may belong to a customer application rather than Google itself; the Cloud rules call out restrictions involving domains such as *.bc.googleusercontent.com and *.appspot.com. Do not treat a Google domain alone as permission to test.
What kinds of AI vulnerabilities qualify?
The categories focus on an exploitable boundary and a meaningful consequence. A model producing an offensive, biased, or inaccurate answer is not by itself a bounty vulnerability.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Rank #3
S1: Rogue Actions
This is the highest-paying category. It covers an AI system—particularly an integrated assistant or agent—taking an unauthorized or dangerous action. A useful report identifies the attacker’s starting access, the affected product, the interaction or exploit chain, the unauthorized action, the violated security boundary, and the impact on an account, data set, or workflow.
S2: Sensitive Data Exfiltration
The report must show a credible way to obtain sensitive information the attacker should not be able to access. Demonstrate only with accounts and data you control, and stop once the issue is proven.
A1: Phishing Enablement
Google’s AI rules describe this as persistent, cross-user HTML injection on a Google-branded site that lacks a user-generated-content warning and presents a convincing phishing vector at the panel’s discretion. A theoretical malicious prompt is not enough.
A2: Model Theft
This concerns unauthorized extraction or theft of a model or model functionality. Ordinary use that reveals general behavior does not automatically establish model theft.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallA3: Context Manipulation
Context manipulation becomes relevant when an attacker changes information supplied to an AI system and creates a qualifying security or abuse impact. A prompt-injection demonstration that reaches protected context or causes an unauthorized consequence is materially stronger than a prompt that merely changes an answer.
A4: Access Control Bypass
You must show an actual bypass of a permission or authorization boundary. A model claiming it can see a file is not proof that the file was accessed.
A5: Unauthorized Product Usage
This covers AI-enabled use of a Google product that the attacker is not authorized to perform, subject to the program’s impact requirements.
A6: Cross-user Denial of Service
The availability impact must reach other users or a shared service. A failure confined to your own account or a self-induced rate limit is not equivalent.
Best Value
The category definitions are set out in the AI VRP rules.
Are jailbreaks and prompt injections rewarded?
Not automatically. Google’s earlier guidance explains that merely eliciting a harmful answer—including content already available elsewhere—is not necessarily reward-eligible, and known issues generally do not qualify. The current test is whether the technique produces an in-scope security or abuse impact.
- An AI agent sends an email, edits a file, or changes a setting without authorization.
- A prompt chain exposes another user’s private document or protected context.
- A persistent injection creates a credible cross-user phishing path.
- Manipulation crosses a real access-control boundary or enables model extraction.
Read Google’s earlier explanation of AI reward criteria, while treating the current AI VRP rules as authoritative.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to submit a report safely
- Open Google’s Bug Hunters vulnerability report form.
- Select the AI VRP when the affected target is an eligible Google AI product. Route Vertex AI and gemini-cli findings to the Cloud VRP.
- Name the product, hostname or URL, feature, version, and date tested.
- Describe the vulnerability, prerequisites, deterministic reproduction steps, and a safe proof of concept.
- Explain the attacker, victim, trust boundary, unauthorized action or data, and cross-user impact.
- Use only accounts and data you control. Stop testing once the minimum evidence is collected.
- Respond to Google’s technical follow-up and avoid public disclosure before remediation discussions are complete.
What a high-quality report contains
- Specific title: product plus security impact, not just “Gemini jailbreak.”
- Prerequisites: account type, permissions, invitations, and setup.
- Reproducible steps: a sequence another engineer can repeat.
- Proof of concept: safe payloads, screenshots, logs, HTTP traces, or a small demonstration.
- Impact analysis: what an attacker can actually do, rather than what the model claims.
- Novelty: why the root cause is distinct from a known behavior.
- Safety boundaries: confirmation that testing used your own accounts and data.
Google’s broader rules say report quality can affect the reward multiplier and evaluate the description, prerequisites, reproduction, target information, output, impact, and communication.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteEligibility, conduct, and common routing mistakes
External security researchers and AI red-teamers can submit reports, but participation is subject to Google’s legal, geographic, sanctions, and conduct restrictions. The broader rules say Google cannot pay people or entities on sanctions lists or in certain sanctioned territories, and it no longer issues rewards to individuals or entities located in Russia or Belarus. Newly acquired companies can also have a six-month blackout period under the broader VRP rules.
Do not:
- Access another person’s files, email, prompts, or account.
- Send phishing messages or target Google employees.
- Run denial-of-service tests, high-volume scans, or disruptive automation.
- Extract more data than necessary to prove the issue.
- Test Google Cloud customer infrastructure without authorization.
- Assume a third-party application using a Google model is a Google target.
The general VRP rules govern these restrictions and state that rewards are discretionary and programs may change or end.
Practical examples: strong versus weak submissions
| Finding | Why it is stronger or weaker |
|---|---|
| A Gemini-connected Workspace agent sends an email or changes a file without the user’s authorization. | Potentially strong: it demonstrates an unauthorized action across a real product boundary. |
| An AI feature reveals a private document belonging to another account using only the researcher’s controlled test setup. | Potentially strong: it shows sensitive-data exposure with a reproducible path. |
| A persistent injection produces a credible cross-user phishing page without an appropriate warning. | Potentially eligible under A1 if the AI rules’ conditions are met. |
| A prompt causes an offensive answer, bias, hallucination, or a refusal bypass with no security consequence. | Usually weak: model behavior alone does not establish an in-scope vulnerability. |
| A theoretical prompt chain, automated scanner alert, or issue already known to Google. | Weak or ineligible without validated impact and novelty. |
What determines the final payment?
- Impact category: S1 and S2 are the highest base categories.
- Product tier: flagship, standard, or other.
- Report quality: clarity, reproducibility, evidence, and communication.
- Novelty: whether the root cause is distinct from known reports.
- Panel discretion: Google may adjust, combine, downgrade, or reject reports.
- Correct program: Cloud-scoped findings may be moved to or expected in the Cloud VRP instead.
Bottom line for researchers
Google’s headline is broadly accurate but incomplete: $20,000 is the top base reward, not the absolute all-in ceiling, and bonuses can lift an individual payment to $30,000. The opportunity is aimed at reproducible attacks against Google-owned AI products that cross a security boundary or create meaningful abuse impact. If your evidence is only a strange answer or a generic jailbreak, strengthen the case with a demonstrated unauthorized action, data exposure, access-control failure, cross-user effect, or other qualifying consequence—without touching anyone else’s accounts or data.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →




