Google AI Vulnerability Reward Program (AI VRP)
- Type
- Public reporting channel
- Lieu
- International — Global
- Dernière vérification
- 2026-09-22
- Prochaine vérification
- 2027-03-21
Pas encore traduit — affiché en anglais.
Comment les joindre
- Submission page
- Homepage
Ce qu'il fait
Eight categories of AI security flaw: rogue actions (account/data modification via indirect prompt injection), sensitive data exfiltration, phishing enablement (persistent HTML injection), model theft (parameter exfiltration), cross-account context manipulation, access control bypass, unauthorised product usage, and cross-user denial of service.
Évaluation franche
Effective and well-funded for security-shaped findings. The single most useful fact in this entry is the exclusion: it is the clearest public statement by a major lab that model-behaviour and alignment concerns are procedurally not vulnerabilities and will be rejected by a security intake. Route those to in-product reporting, FLARE-AI, AIID or a regulator instead.
Comment déposer
Submit via bughunters.google.com under the AI VRP rules. Content and alignment issues go through the thumbs-down / report flows inside Gemini, Search and Workspace.
Format
Standard Google VRP report: product, reproduction steps, security impact mapped to one of the eight abuse categories.
Calendrier
Rolling. Program launched October 2025.
Ce qui se passe ensuite
Triage and reward: up to $20,000 base with up to $10,000 in quality multipliers (max ~$30,000). Flagship products (Search, Gemini, Workspace core) $20,000–$500; Standard (AI Studio, Jules, non-core Workspace) $15,000–$100; Other tier up to $10,000 or Google credit. Google paid ~$12M to 600+ researchers across its VRP in 2024.
Ce qu'il accepte
Eight categories of AI security flaw: rogue actions (account/data modification via indirect prompt injection), sensitive data exfiltration, phishing enablement (persistent HTML injection), model theft (parameter exfiltration), cross-account context manipulation, access control bypass, unauthorised product usage, and cross-user denial of service.
Ce qu'il n'accepte pas
Explicitly out of scope: direct prompt injection, jailbreaks, and alignment issues. Google's stated position is that 'we don't believe a Vulnerability Reward Program is the right format for addressing content-related issues' — these must go to in-product reporting channels instead.
Géré par
Google (Bug Hunters / VRP team)