OpenAI Launches Safety Bug Bounty and Fellowship
11 Jul 2026
OpenAI unveils a Safety Bug Bounty and a parallel Safety Fellowship to study AI misuse risks
On March 25, 2026, OpenAI announced a new public Safety Bug Bounty program aimed at surfacing AI abuse and safety risks across its products. The company describes the goal as ensuring its systems 'remain safe and secure against misuse or abuse that could lead to tangible harm.'
The program is designed to complement OpenAI's existing Security Bug Bounty program. Where the security bounty focuses on traditional vulnerabilities, the new Safety Bug Bounty covers meaningful abuse and safety risks that don't meet standard security vulnerability criteria. Safety and security researchers, along with ethical hackers, are invited to participate.
One concrete detail: third-party prompt injection attacks must be reproducible at least 50% of the time to qualify for a bounty submission—signaling that OpenAI is placing specific scrutiny on injection-based and agentic attack vectors.
A companion Fellowship for external safety talent
Alongside the bounty, OpenAI separately announced a Safety Fellowship program for external researchers, engineers, and practitioners. The fellowship includes a monthly stipend, compute support, and ongoing mentorship. Workspace will be available in Berkeley at Constellation, though remote participation is also possible.
Fellows are expected to produce substantial research output—a paper, benchmark, or dataset—by the program's end. Priority research areas include:
- Safety evaluation
- Ethics
- Robustness
- Scalable mitigations
- Privacy-preserving safety methods
- Agentic oversight
- High-severity misuse domains
The fellowship welcomes applicants from computer science, social science, cybersecurity, privacy, HCI, and related fields. Notably, fellows will receive API credits and resources but will not have internal system access—a distinction that could shape the depth of their findings.
Key dates
- March 25, 2026 — Safety Bug Bounty program announced
- May 3 — Fellowship applications close
- July 25 — Successful applicants notified
- September 14, 2026 — Fellowship program begins
- February 5, 2027 — Fellowship program ends
What's still unclear
The report leaves several open questions: OpenAI has not disclosed bounty reward amounts or payout structure, the full scope of qualifying issues beyond the prompt injection threshold, fellowship stipend amounts, the number of available slots, selection criteria, geographic restrictions on the bounty program, or how findings from either initiative will be publicly disclosed.
Why founders should care
For early-stage founders building on top of OpenAI's APIs or in the AI safety space, these programs likely carry several implications:
- Rising scrutiny of misuse vectors. The introduction of a dedicated safety bounty—separate from security bugs—suggests OpenAI is treating abuse and misuse as a distinct risk category. Founders building agentic or LLM-powered products may want to proactively audit their own systems for similar injection-based vulnerabilities, especially given the 50% reproducibility bar OpenAI has set.
- Possible talent and partnership signals. The parallel Fellowship suggests OpenAI is investing in an external safety talent pipeline. This could plausibly translate into future hiring pathways or collaboration opportunities for founders and researchers working in AI safety.
- Reputational exposure for API-dependent products. Publicized safety vulnerabilities discovered through the bounty program could create reputational risk not just for OpenAI, but for companies building products on its APIs—making it worth monitoring disclosures as they emerge.
- Limits on fellowship access. Because fellows won't have internal system access, the depth of resulting safety research may be constrained. Founders partnering with OpenAI on safety initiatives should factor this limitation into their expectations.
Risks worth watching
- Ambiguity around bounty payouts could dampen researcher participation if compensation terms aren't clarified.
- Publicized vulnerabilities may pose reputational risk to OpenAI and downstream companies building on its platform.
- Fellows' restricted access to internal systems may limit how actionable or applicable their research findings ultimately are.
OpenAI has not yet detailed reward structures, disclosure processes, or fellowship slot counts—details founders should watch for as the program rolls out toward its September 2026 start date.