Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Google’s AI Bug Bounty Offers Up to $20,000—Potentially $30,000 With Bonuses

Google’s dedicated AI Vulnerability Reward Program launched October 6, 2025. Learn why $20,000 is the top base reward, how bonuses can reach $30,000, which AI flaws qualify, and where to report them.
From TheFinanceBase Team7 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Google’s dedicated AI Vulnerability Reward Program (AI VRP) is real, but the headline needs context. Google announced it on October 6, 2025. The highest listed base reward is $20,000 for a flagship-product “S1: Rogue Actions” vulnerability. Report-quality and novelty bonuses can raise an individual payment to as much as $30,000 under Google’s rules. The program targets demonstrable security or abuse impact—not ordinary model mistakes or generic jailbreaks.

What Google actually launched

Google created a dedicated AI VRP instead of leaving AI findings inside its general Abuse VRP. The new program combines qualifying AI abuse and security findings in one reward framework, with a unified panel deciding the applicable category and final amount. Google says researchers had already received more than $430,000 for AI-product-related reports before the dedicated program began.

The announcement is at Google’s AI VRP announcement. Because the launch was in 2025, it is more accurate in 2026 to call this Google’s dedicated AI VRP rather than a newly launched bounty.

How much can a researcher receive?

Google’s published figures describe a base schedule, not a guaranteed price list. The top base reward is $20,000; applicable report-quality and novelty multipliers can increase an individual payment to up to $30,000. Google retains discretion to reject, downgrade, group, or otherwise adjust a report.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Category Flagship Standard Other
S1: Rogue Actions $20,000 $15,000 $10,000
S2: Sensitive Data Exfiltration $15,000 $15,000 $10,000
A1: Phishing Enablement $5,000 $500 Credit
A2: Model Theft $5,000 $500 Credit
A3: Context Manipulation $5,000 $500 Credit
A4: Access Control Bypass $2,500 $250 Credit
A5: Unauthorized Product Usage $1,000 $100 Credit
A6: Cross-user Denial of Service $500 $100 Credit

These amounts come from the announcement. “Flagship,” “standard,” and “other” refer to Google’s product tiers, so the same technical weakness can have a very different base value depending on where it occurs.

Why the ceiling can reach $30,000

Google says it uses report-quality and novelty multipliers from its broader VRP. The general framework lists 0.8× for low-quality reports, 1× for good reports, and 1.2× for exceptional reports. The AI announcement also references novelty bonuses. Those factors do not mean every $20,000 report automatically receives a 1.5× increase; the exact application is discretionary and governed by Google’s current rules.

See the general Google and Alphabet VRP rules for the quality framework.

Which Google products are covered?

Google divides eligible products into broad tiers. The live rules can change, so verify the current product and hostname before testing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Flagship products

  • Google Search
  • Gemini applications
  • Core Google Workspace applications, including Gmail, Drive, Meet, Calendar, Docs, Sheets, Slides, and Forms

Standard products

  • AI Studio
  • Jules
  • Non-core Workspace products such as NotebookLM and AppSheet

Other AI integrations

Other Google-owned AI integrations may qualify in the “other” tier if they meet the rules and exclusions. A service using a Google model is not automatically eligible: the target must be a Google-owned product or service within the program’s scope.

When should you use the Cloud VRP instead?

Google specifically routes vulnerabilities in Vertex AI and gemini-cli to the Google Cloud Vulnerability Reward Program, not automatically to the AI VRP. Use the Cloud VRP rules when the finding concerns those products or another Cloud-scoped service.

Cloud customer resources are not authorized targets. A Google-hosted hostname may belong to a customer application rather than Google itself; the Cloud rules call out restrictions involving domains such as *.bc.googleusercontent.com and *.appspot.com. Do not treat a Google domain alone as permission to test.

What kinds of AI vulnerabilities qualify?

The categories focus on an exploitable boundary and a meaningful consequence. A model producing an offensive, biased, or inaccurate answer is not by itself a bounty vulnerability.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

S1: Rogue Actions

This is the highest-paying category. It covers an AI system—particularly an integrated assistant or agent—taking an unauthorized or dangerous action. A useful report identifies the attacker’s starting access, the affected product, the interaction or exploit chain, the unauthorized action, the violated security boundary, and the impact on an account, data set, or workflow.

S2: Sensitive Data Exfiltration

The report must show a credible way to obtain sensitive information the attacker should not be able to access. Demonstrate only with accounts and data you control, and stop once the issue is proven.

A1: Phishing Enablement

Google’s AI rules describe this as persistent, cross-user HTML injection on a Google-branded site that lacks a user-generated-content warning and presents a convincing phishing vector at the panel’s discretion. A theoretical malicious prompt is not enough.

A2: Model Theft

This concerns unauthorized extraction or theft of a model or model functionality. Ordinary use that reveals general behavior does not automatically establish model theft.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A3: Context Manipulation

Context manipulation becomes relevant when an attacker changes information supplied to an AI system and creates a qualifying security or abuse impact. A prompt-injection demonstration that reaches protected context or causes an unauthorized consequence is materially stronger than a prompt that merely changes an answer.

A4: Access Control Bypass

You must show an actual bypass of a permission or authorization boundary. A model claiming it can see a file is not proof that the file was accessed.

A5: Unauthorized Product Usage

This covers AI-enabled use of a Google product that the attacker is not authorized to perform, subject to the program’s impact requirements.

A6: Cross-user Denial of Service

The availability impact must reach other users or a shared service. A failure confined to your own account or a self-induced rate limit is not equivalent.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The category definitions are set out in the AI VRP rules.

Are jailbreaks and prompt injections rewarded?

Not automatically. Google’s earlier guidance explains that merely eliciting a harmful answer—including content already available elsewhere—is not necessarily reward-eligible, and known issues generally do not qualify. The current test is whether the technique produces an in-scope security or abuse impact.

  • An AI agent sends an email, edits a file, or changes a setting without authorization.
  • A prompt chain exposes another user’s private document or protected context.
  • A persistent injection creates a credible cross-user phishing path.
  • Manipulation crosses a real access-control boundary or enables model extraction.

Read Google’s earlier explanation of AI reward criteria, while treating the current AI VRP rules as authoritative.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to submit a report safely

  1. Open Google’s Bug Hunters vulnerability report form.
  2. Select the AI VRP when the affected target is an eligible Google AI product. Route Vertex AI and gemini-cli findings to the Cloud VRP.
  3. Name the product, hostname or URL, feature, version, and date tested.
  4. Describe the vulnerability, prerequisites, deterministic reproduction steps, and a safe proof of concept.
  5. Explain the attacker, victim, trust boundary, unauthorized action or data, and cross-user impact.
  6. Use only accounts and data you control. Stop testing once the minimum evidence is collected.
  7. Respond to Google’s technical follow-up and avoid public disclosure before remediation discussions are complete.

What a high-quality report contains

  • Specific title: product plus security impact, not just “Gemini jailbreak.”
  • Prerequisites: account type, permissions, invitations, and setup.
  • Reproducible steps: a sequence another engineer can repeat.
  • Proof of concept: safe payloads, screenshots, logs, HTTP traces, or a small demonstration.
  • Impact analysis: what an attacker can actually do, rather than what the model claims.
  • Novelty: why the root cause is distinct from a known behavior.
  • Safety boundaries: confirmation that testing used your own accounts and data.

Google’s broader rules say report quality can affect the reward multiplier and evaluate the description, prerequisites, reproduction, target information, output, impact, and communication.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Eligibility, conduct, and common routing mistakes

External security researchers and AI red-teamers can submit reports, but participation is subject to Google’s legal, geographic, sanctions, and conduct restrictions. The broader rules say Google cannot pay people or entities on sanctions lists or in certain sanctioned territories, and it no longer issues rewards to individuals or entities located in Russia or Belarus. Newly acquired companies can also have a six-month blackout period under the broader VRP rules.

Do not:

  • Access another person’s files, email, prompts, or account.
  • Send phishing messages or target Google employees.
  • Run denial-of-service tests, high-volume scans, or disruptive automation.
  • Extract more data than necessary to prove the issue.
  • Test Google Cloud customer infrastructure without authorization.
  • Assume a third-party application using a Google model is a Google target.

The general VRP rules govern these restrictions and state that rewards are discretionary and programs may change or end.

Practical examples: strong versus weak submissions

Finding Why it is stronger or weaker
A Gemini-connected Workspace agent sends an email or changes a file without the user’s authorization. Potentially strong: it demonstrates an unauthorized action across a real product boundary.
An AI feature reveals a private document belonging to another account using only the researcher’s controlled test setup. Potentially strong: it shows sensitive-data exposure with a reproducible path.
A persistent injection produces a credible cross-user phishing page without an appropriate warning. Potentially eligible under A1 if the AI rules’ conditions are met.
A prompt causes an offensive answer, bias, hallucination, or a refusal bypass with no security consequence. Usually weak: model behavior alone does not establish an in-scope vulnerability.
A theoretical prompt chain, automated scanner alert, or issue already known to Google. Weak or ineligible without validated impact and novelty.

What determines the final payment?

  1. Impact category: S1 and S2 are the highest base categories.
  2. Product tier: flagship, standard, or other.
  3. Report quality: clarity, reproducibility, evidence, and communication.
  4. Novelty: whether the root cause is distinct from known reports.
  5. Panel discretion: Google may adjust, combine, downgrade, or reject reports.
  6. Correct program: Cloud-scoped findings may be moved to or expected in the Cloud VRP instead.

Bottom line for researchers

Google’s headline is broadly accurate but incomplete: $20,000 is the top base reward, not the absolute all-in ceiling, and bonuses can lift an individual payment to $30,000. The opportunity is aimed at reproducible attacks against Google-owned AI products that cross a security boundary or create meaningful abuse impact. If your evidence is only a strange answer or a generic jailbreak, strengthen the case with a demonstrated unauthorized action, data exposure, access-control failure, cross-user effect, or other qualifying consequence—without touching anyone else’s accounts or data.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.