English

Places to contact

Microsoft

Type
AI company
Place
United States — USA
Last checked
2026-09-22
Next check due
2027-03-21

Ways to reach them

  • MSRC Researcher Portal · Responsible disclosure programme
    Verification expired

    Evidence that this route accepts contact

    Security vulnerability submissions including AI systems, graded against the AI bug bar.

    Also reachable as aka.ms/secure-at per the Copilot bounty page.

  • Microsoft Copilot AI Bounty · Bug or safety bounty
    Limited contact route · 2026-09-22

    Who may use it: users-meeting-published-eligibility

    Restrictions: $250-$30,000. Security vulnerabilities in Copilot surfaces. Explicitly EXCLUDES 'AI prompt injection attacks that do not have a security impact on users other than the attacker', 'model hallucination where the model pretends to run arbitrary code', and 'attacks that aim to leak (part of) the system/meta prompt'. Content issues must be reported separately as 'AI derived harm'.

    Evidence that this route accepts contact · 2026-09-22

    $250-$30,000. Security vulnerabilities in Copilot surfaces. Explicitly EXCLUDES 'AI prompt injection attacks that do not have a security impact on users other than the attacker', 'model hallucination where the model pretends to run arbitrary code', and 'attacks that aim to leak (part of) the system/meta prompt'. Content issues must be reported separately as 'AI derived harm'.

    One of the clearest published statements anywhere that jailbreak-style findings are not a bounty item.

  • AI/ML Vulnerability Severity Classification (AI bug bar) · Responsible disclosure programme
    Limited contact route · 2026-09-22

    Who may use it: users-meeting-published-eligibility

    Restrictions: Splits AI issues into security vulnerabilities (CVSS-rated: inference manipulation, membership inference, model theft) and Responsible AI issues (hate speech, misinformation, sexual content, self-harm) classified only 'In Scope' or 'Out of Scope for investigation, without severity ratings'.

    Evidence that this route accepts contact · 2026-09-22

    Splits AI issues into security vulnerabilities (CVSS-rated: inference manipulation, membership inference, model theft) and Responsible AI issues (hate speech, misinformation, sexual content, self-harm) classified only 'In Scope' or 'Out of Scope for investigation, without severity ratings'.

    Notably says Microsoft 'actively welcome[s] submissions related to safety and societal harm' — a rare explicit invitation. CSEAM must go to Report a Concern instead.

  • Report a Concern (Digital Safety) · Web form
    Verification expired

    Evidence that this route accepts contact

    Harmful content across Microsoft services, including AI-generated.

    The consumer-facing route MSRC redirects content reports to.

  • Enterprise AI Services abuse report · Web form
    Limited contact route · 2026-09-22

    Who may use it: users-meeting-published-eligibility

    Restrictions: Reporting abusive, illegal or infringing use of a Microsoft AI Service.

    Evidence that this route accepts contact · 2026-09-22

    Reporting abusive, illegal or infringing use of a Microsoft AI Service.

    Published in the Code of Conduct for Microsoft AI Services.

  • Homepage · Homepage
    Verification expired

    Evidence that this route accepts contact

  • Frontier Governance Framework (February 2026; first version February 2025) · Published policy or framework
    Verification expired

    Evidence that this route accepts contact

What it does

Office of Responsible AI and a Chief Responsible AI Officer maintain the Responsible AI Standard and review revisions to the Frontier Governance Framework; MSRC handles security and an AI-specific severity bug bar.

Honest assessment

No large body of public complaints specific to Microsoft's AI safety intake, and the AI bug bar is unusually candid about what it will and will not investigate. The honest read: security-impacting AI bugs get a real, paid, well-run process through MSRC; pure model-behaviour findings get a 'Responsible AI' classification with no severity and no stated timeline, which is closer to a content-moderation queue than a safety review. Microsoft has publicly said it will pay out for high-impact bugs even outside formal bounty scope (The Register, Dec 2025).

Notes

Use the AI bug bar page first to decide which door you are at — it is the single most useful triage document published by any company here. Safe harbour exists as 'Legal Safe Harbor' in the bounty terms at https://www.microsoft.com/en-us/msrc/bounty-guidelines#safeharbor. The Frontier Governance Framework's whistleblower route is internal only, with anonymous reporting and anti-retaliation for employees; there is no external equivalent.

Sources

Something wrong here?