Google AI Vulnerability Reward Program (AI VRP)
- Type
- Public reporting channel
- Place
- International — Global
- Last checked
- 2026-09-22
- Next check due
- 2027-03-21
Ways to reach them
- Submission page
- Homepage
What it does
Eight categories of AI security flaw: rogue actions (account/data modification via indirect prompt injection), sensitive data exfiltration, phishing enablement (persistent HTML injection), model theft (parameter exfiltration), cross-account context manipulation, access control bypass, unauthorised product usage, and cross-user denial of service.
Honest assessment
Effective and well-funded for security-shaped findings. The single most useful fact in this entry is the exclusion: it is the clearest public statement by a major lab that model-behaviour and alignment concerns are procedurally not vulnerabilities and will be rejected by a security intake. Route those to in-product reporting, FLARE-AI, AIID or a regulator instead.
How to file
Submit via bughunters.google.com under the AI VRP rules. Content and alignment issues go through the thumbs-down / report flows inside Gemini, Search and Workspace.
Format
Standard Google VRP report: product, reproduction steps, security impact mapped to one of the eight abuse categories.
Timing
Rolling. Program launched October 2025.
What happens after
Triage and reward: up to $20,000 base with up to $10,000 in quality multipliers (max ~$30,000). Flagship products (Search, Gemini, Workspace core) $20,000–$500; Standard (AI Studio, Jules, non-core Workspace) $15,000–$100; Other tier up to $10,000 or Google credit. Google paid ~$12M to 600+ researchers across its VRP in 2024.
What it accepts
Eight categories of AI security flaw: rogue actions (account/data modification via indirect prompt injection), sensitive data exfiltration, phishing enablement (persistent HTML injection), model theft (parameter exfiltration), cross-account context manipulation, access control bypass, unauthorised product usage, and cross-user denial of service.
What it does not accept
Explicitly out of scope: direct prompt injection, jailbreaks, and alignment issues. Google's stated position is that 'we don't believe a Vulnerability Reward Program is the right format for addressing content-related issues' — these must go to in-product reporting channels instead.
Operated by
Google (Bug Hunters / VRP team)