Microsoft
- Type
- AI company
- Place
- United States — USA
- Last checked
- 2026-09-22
- Next check due
- 2027-03-21
Ways to reach them
- MSRC Researcher Portal
- Microsoft Copilot AI Bounty
- AI/ML Vulnerability Severity Classification (AI bug bar)
- Report a Concern (Digital Safety)
- Enterprise AI Services abuse report
- Homepage
- Frontier Governance Framework (February 2026; first version February 2025)
What it does
Office of Responsible AI and a Chief Responsible AI Officer maintain the Responsible AI Standard and review revisions to the Frontier Governance Framework; MSRC handles security and an AI-specific severity bug bar.
Honest assessment
No large body of public complaints specific to Microsoft's AI safety intake, and the AI bug bar is unusually candid about what it will and will not investigate. The honest read: security-impacting AI bugs get a real, paid, well-run process through MSRC; pure model-behaviour findings get a 'Responsible AI' classification with no severity and no stated timeline, which is closer to a content-moderation queue than a safety review. Microsoft has publicly said it will pay out for high-impact bugs even outside formal bounty scope (The Register, Dec 2025).
Notes
Use the AI bug bar page first to decide which door you are at — it is the single most useful triage document published by any company here. Safe harbour exists as 'Legal Safe Harbor' in the bounty terms at https://www.microsoft.com/en-us/msrc/bounty-guidelines#safeharbor. The Frontier Governance Framework's whistleblower route is internal only, with anonymous reporting and anti-retaliation for employees; there is no external equivalent.