Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Google’s October 6, 2025 security announcement introduced three complementary AI initiatives: a dedicated AI Vulnerability Reward Program (AI VRP) for external reports, SAIF 2.0 guidance for securing AI agents, and CodeMender, an AI-powered agent intended to help find and fix code vulnerabilities. They address different parts of the security problem; Google’s announcement describes their approach, not independently measured results.

What Google announced

In “How we’re securing the AI frontier,” published October 6, 2025, Google Vice President for Privacy, Safety & Security Evan Kotsovinos and Google DeepMind VP of Security Four Flynn presented the initiatives as a portfolio:

Initiative Who or what it involves Purpose described by Google
AI Vulnerability Reward Program (AI VRP) External security researchers Provide a dedicated route and rules for qualifying AI-related security and abuse reports.
SAIF 2.0 Practitioners designing and securing AI systems Extend Google’s Secure AI Framework with agent-focused guidance and a risk map.
CodeMender An AI-powered coding agent Analyze software vulnerabilities and propose fixes that undergo review.

The measures are distinct: one invites reports from outside researchers, one provides design guidance, and one aims to assist with code remediation. Google describes them as complementary, but the announcement does not establish that they have produced a particular security outcome.

What is Google’s AI bug bounty program?

The AI VRP is Google’s dedicated vulnerability reward program for eligible AI-related issues. Google said it created a single set of rules and reward tables to make scope clearer and reporting simpler. AI-related abuse issues previously covered by Google’s Abuse VRP were moved into the new program, according to the announcement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What kinds of issues may be in scope?

Google Bug Hunters’ current high-level Rules & Rewards overview describes the program as covering security and abuse issues in a Google-owned or Alphabet subsidiary AI-based product or service that handles reasonably sensitive user data. This is an overview, not a substitute for the detailed live AI VRP rules. Google also identifies separate routes, including Cloud VRP for relevant Google Cloud issues and OSS VRP for qualifying open-source software.

Do not assume that every unwanted, inaccurate, or unsafe model response is a bounty-eligible vulnerability. Google says content-based safety feedback should go through the feedback mechanism in the relevant product. That channel can give AI Safety teams context such as the user’s situation and the model version. Security or abuse findings should be checked against the applicable current program rules.

How much does Google pay for AI bugs?

Google’s October 6, 2025 announcement said its vulnerability reward programs had paid over $430,000 for AI-related issues by that date. This is a company-reported cumulative figure across AI-related issues, not the standalone payout total for the newly launched AI VRP. The announcement does not provide a current, verified reward schedule here; consult the live program rules for reward amounts and eligibility before testing or submitting a report.

What is SAIF 2.0, and how does it address AI agents?

SAIF is Google’s Secure AI Framework. In the 2025 announcement, Google said SAIF 2.0 expands its guidance to address risks from autonomous agents. The update includes an agent risk map, security capabilities rolling out across Google agents, and a contribution of risk-map data to the Coalition for Secure AI Risk Map initiative.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Google summarized its agent design principles as:

  • Define human controllers: agents should have well-defined human controllers.
  • Limit powers: an agent’s permissions and capabilities should be carefully constrained.
  • Make behavior observable: agent actions and planning should be visible.

These are principles Google says guide its approach, not a universal certification standard or verification that every deployed Google agent follows them in practice.

What is CodeMender?

Google describes CodeMender as an AI-powered agent that uses Gemini’s reasoning capabilities to analyze software vulnerabilities and propose code fixes. Its announced workflow includes root-cause analysis, fuzzing and theorem provers, and self-validated patch generation. Specialized critique agents then review proposed patches for correctness, security implications, and coding standards before a human gives final sign-off.

The announcement describes an intended workflow; it does not establish general availability or provide independent performance benchmarks. Its account of human sign-off also means CodeMender should not be treated as a reason to apply generated security patches without review.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How the initiatives build on Google’s earlier AI security work

The 2025 AI VRP was not Google’s first AI-related bounty effort. On October 26, 2023, Google said it was expanding its Vulnerability Rewards Program to cover attack scenarios specific to generative AI and publishing additional scope guidance. The post discussed issues including unfair bias, model manipulation, and hallucinations, and described work to secure AI software supply chains.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Google’s 2023 supply-chain work included using SLSA and Sigstore to protect AI supply-chain integrity, with early prototypes for model signing using Sigstore and attestation verification using SLSA. The later dedicated AI VRP can be understood as a clarification and consolidation of that earlier bounty activity—not the start of Google’s AI vulnerability rewards.

The distinction between security reporting and safety feedback matters here: a reliability or content concern is not automatically a security vulnerability. Google’s 2025 announcement directs content-based concerns to product feedback and qualifying security or abuse reports to the relevant VRP rules.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.