OpenAI
- Type
- AI company
- Place
- United States — USA
- Last checked
- 2026-09-22
- Next check due
- 2027-03-21
Ways to reach them
- Coordinated Vulnerability Disclosure Policy
- OpenAI Bug Bounty (Bugcrowd)
- OpenAI Safety Bug Bounty (Bugcrowd)
- Report Content
- Researcher Access Program
This route is retained as reference only. Its verification is missing, more than 180 days old, or the contact window is not currently open; do not rely on it until it is re-checked.
- Red Teaming Network
This route is retained as reference only. Its verification is missing, more than 180 days old, or the contact window is not currently open; do not rely on it until it is re-checked.
- Model behavior feedback form
- Model Spec feedback form
- Homepage
- Preparedness Framework v2.0 (15 April 2025); Frontier Governance Framework (May 2026); Model Spec (updated continuously)
- Submission page
- Homepage
What it does
Safety Systems, Preparedness and Alignment teams, with a Safety and Security Committee at board level; Preparedness runs capability thresholds and the Model Spec defines intended model behaviour.
Honest assessment
Mixed and worsening for unpaid routes. Two named public feedback channels — the model behavior feedback form and the Model Spec feedback form — are both now closed or deprecated, so a citizen's only open door is the content-report form. OpenAI's September 2026 model misalignment reporting framework is explicitly internal: 'Any OpenAI employee may flag a misalignment example for investigation' — it creates no external intake. Researchers in the Trusted Access for Cyber / Daybreak program publicly complained in August 2026 (TechCrunch, 19 Aug 2026) that access was revoked with messages saying their identity 'could not be verified', disproportionately affecting researchers outside the US and Europe. The Safety Bug Bounty is reported to be NDA-bound, so findings cannot be published.
How to file
Security: bugcrowd.com/engagements/openai. Model behaviour: OpenAI now directs ChatGPT users to the thumbs-down control under any response or the content reporting form; API customers to enable thumbs-down feedback in the Playground via the API dashboard; everything else to customer support.
Format
Security: Bugcrowd vulnerability report. Model behaviour: an in-product thumbs-down with free text — there is no structured external report format any more.
Timing
Rolling.
What happens after
Security reports are triaged and may be rewarded (historically up to $20,000). Model-behaviour feedback disappears into product telemetry with no case number, no acknowledgment and no route back to the reporter.
What it accepts
Bugcrowd program: security vulnerabilities in OpenAI's systems and products.
What it does not accept
The Bugcrowd engagement page states model safety issues, jailbreaks and hallucinations are excluded from the bug bounty and directs them elsewhere. The dedicated 'Model behavior feedback' web form (openai.com/form/model-behavior-feedback) has been deprecated and no longer accepts submissions.
Operated by
OpenAI, security program run on Bugcrowd
Notes
If you have a model-behaviour concern and are not a paid bounty participant, the Report Content form is the only reliable open channel and it is framed around content policy, not alignment. OpenAI's security page says the bug bounty 'provides safe harbor for good-faith testing' but no verbatim safe-harbour clause is published on the policy page itself. No public whistleblower channel for outsiders.
Sources
- https://openai.com/policies/coordinated-vulnerability-disclosure-policy/
- https://openai.com/form/report-content/
- https://openai.com/form/researcher-access-program/
- https://openai.com/index/red-teaming-network/
- https://openai.com/form/model-behavior-feedback/
- https://openai.com/form/model-spec-feedback/
- https://openai.com/form/model-behavior-feedback/