---
title: "AI Bug Bounty: why human hackers still find what AI misses"
description: "We asked the UNGUESS Security community how they use AI: 90% use it daily, almost none for vulnerability hypotheses. What that means for bug bounty."
image: https://blog.unguess.io/hubfs/1-Aug-18-2026-02-49-13-3140-PM.png
---

[![Vai alla homepage di UNGUESS](https://blog.unguess.io/hubfs/Imported%20images/unguess-logo.svg)](https://unguess.io/it)

- PRODUCTS BY INDUSTRY
  
    - [Retail & Ecommerce](https://unguess.io/services/industry/retail-ecommerce/)
    - [Fast-Moving Consumer Goods](https://unguess.io/services/industry/fast-moving-consumer-goods/)
    - [Banking, Insurance & Financial Services](https://unguess.io/services/industry/banking-insurance-financial-services/)
    - [Travel & Hospitality](https://unguess.io/services/industry/travel-hospitality/)
    - [Utilities](https://unguess.io/services/industry/utilities/)
    - [Healthcare](https://unguess.io/services/industry/healthcare/)
    - [Media & Entertainment](https://unguess.io/services/industry/media-entertainment/)
    - [Automotive](https://unguess.io/services/industry/automotive/)
- PRODUCTS BY USE CASE
  
    - [Ai Training](https://unguess.io/services/ai-training-testing/)
    - [User Experience](https://unguess.io/services/use-case/user-experience/)
    - [Software Quality](https://unguess.io/services/use-case/software-quality/)
    - [Cyber Security](https://unguess.io/services/use-case/cyber-security/)
    - [Accessibility](https://unguess.io/services/accessibility/)
- [HOW IT WORKS](https://unguess.io/how-it-works/)
- [OUR CROWD](https://unguess.io/our-crowd/)
- COMPANY
  
    - [About us](https://unguess.io/about-us)
    - [Life at UNGUESS](https://unguess.io/life-at-unguess/)
    - [Partners](https://unguess.io/unguess-partners/)
- [SHOWCASES](https://unguess.io/showcases/)
  
    - [Case Study](https://unguess.io/showcases/all-showcases/?jsf=jet-engine:shocase-listing-grid&tax=resource-category:76/#readmore)
    - [Unguess Challenges](https://unguess.io/showcases/all-showcases/?jsf=jet-engine:shocase-listing-grid&tax=resource-category:74/#readmore)
    - [White Paper](https://unguess.io/showcases/all-showcases/?jsf=jet-engine:shocase-listing-grid&tax=resource-category:75/#readmore)
- [BLOG](https://blog.unguess.io)
- - <https://blog.unguess.io/?hsLang=it>
    - <https://blog.unguess.io/?hsLang=es>
    - <https://blog.unguess.io/?hsLang=fr>

- [PRODUCTS](https://unguess.io/services/)
  
    - BY INDUSTRY 
          - [Retail & Ecommerce](https://unguess.io/services/industry/retail-ecommerce/)
          - [Fast-Moving Consumer Goods](https://unguess.io/services/industry/fast-moving-consumer-goods/)
          - [Banking, Insurance & Financial Services](https://unguess.io/services/industry/banking-insurance-financial-services/)
          - [Travel & Hospitality](https://unguess.io/services/industry/travel-hospitality/)
          - [Utilities](https://unguess.io/services/industry/utilities/)
          - [Healthcare](https://unguess.io/services/industry/healthcare/)
          - [Media & Entertainment](https://unguess.io/services/industry/media-entertainment/)
          - [Automotive](https://unguess.io/services/industry/automotive/)
    - BY USE CASE 
          - [Ai Training](https://unguess.io/services/ai-training-testing/)
          - [User Experience](https://unguess.io/services/use-case/user-experience/)
          - [Software Quality](https://unguess.io/services/use-case/software-quality/)
          - [Cyber Security](https://unguess.io/services/use-case/cyber-security/)
          - [Accessibility](https://unguess.io/services/accessibility/)
          - [VIEW ALL PRODUCTS](https://unguess.io/services/)
- [HOW IT WORKS](https://unguess.io/how-it-works/)
- [OUR CROWD](https://unguess.io/our-crowd/)
- COMPANY
  
    - [About us](https://unguess.io/about-us/)
    - [Life at UNGUESS](https://unguess.io/life-at-unguess/)
    - [Partners](https://unguess.io/partners/)
- [SHOWCASES](https://unguess.io/showcases/)
  
    - [Case Study](https://unguess.io/showcases/case-study/)
    - [Unguess Challenges](https://unguess.io/showcases/unguess-challenges/)
    - [White Paper](https://unguess.io/showcases/white-paper/)
    - [Webinar](https://unguess.io/showcases/webinar/)
- [BLOG](https://blog.unguess.io)
- - <https://blog.unguess.io/?hsLang=it>
    - <https://blog.unguess.io/?hsLang=es>
    - <https://blog.unguess.io/?hsLang=fr>

[CONTACT US](https://unguess.io/it/inizia-ora/) [SIGN UP](https://app.unguess.io/)

Cybersecurity

# AI Bug Bounty: why human hackers still find what AI misses

We asked the UNGUESS Security community how they use AI: 90% use it daily, almost none for vulnerability hypotheses. What that means for bug bounty.

[Luca Manara](https://blog.unguess.io/author/luca-manara)

 Aug 25, 2026

---

## **Key takeaways**

- 90% of researchers in the UNGUESS Security community use AI daily, but almost none use it to generate vulnerability hypotheses.
- AI's two recurring failures: it misses business logic context and it hallucinates vulnerabilities.
- AI offensive tooling is priced per token, so you pay for process. Bug bounty is priced per validated finding: no finding, no invoice.
- NIS2, DORA and the Cyber Resilience Act turn human validation and audit trails into a legal requirement, not a preference.

 

Since late 2025 a new class of frontier models, Claude Mythos, GPT Cyber and their peers, has pushed AI vulnerability discovery to the top of every CISO's agenda. The question everyone is asking is the same one: will AI make ethical hackers and bug bounty programs obsolete?

We saw many claims, from what I know still not verified by independent researchers, that these models are able to find large numbers of zero-day vulnerabilities in a seasoned code base. And this is true. And is where AI is very capable: scanning large amounts of code.

By the way, **the same models that help you find latent flaws before release will, inevitably, end up in the hands of the people trying to break in**.

A whole category of AI-native attacks are coming, leaving CISOs with two practical questions:

• How do we actually capture the benefit of all this?

• And what’s the most efficient way to do it in money, time, and risk?

**We asked researchers from the** [**UNGUESS Security community**](https://security.unguess.io/) **how they use AI in everyday jobs. This helped us to picture the real situation (at the end, they replicate what a criminal would do).**

 

## The survey: how ethical hackers actually use AI (and what they don't use it for) 

We asked the community of ethical hackers how they use AI in their everyday job. Not surprisingly, 90% of researchers use AI regularly and intensely. But here is the interesting part: across the eight activity families we mapped, vulnerability hypothesis generation is the one where AI is used least of all. 

Among these families:

*Reconnaissance & asset discovery, Understanding unfamiliar code or tech, Vulnerability hypothesis generation, Payload/exploit generation, Writing or refining PoCs, Report writing, Learning/upskilling and Automating repetitive tasks.*

They use AI mostly for Understanding unfamiliar code or tech, Writing or refining PoCs and Report writing way less in Reconnaissance & asset discovery and in particular **very few use AI for Vulnerability hypothesis generation. Because it is the place where creativity and connecting the dots is important.**

**Problems from AI usually are on Misses business-logic context and Hallucinated / false vulnerabilities.**

Hackers mostly say that AI will raise the bar: easy bugs vanish, only hard bugs pay. **They think that AI will reduce earning opportunities for hunters but also that autonomous agents will not compete directly with human hunters.**

Counterintuitively they are neutral on this question *“Would strong AI-native tooling make you more likely to hunt on a platform?”*

## AI vulnerability discovery: the problem isn't too few findings, it's too many 

Let’s start with the obvious effect: AI lowers the cost of findings. Frontier models read enormous codebases, help to know how to create a payload, help to chain things together, and increasingly produce working exploits.

**As that capability spreads, to your team, to vendors, to attackers, the volume of reported vulnerabilities climbs sharply, even for products that have been pentested for years. The number of CVEs increases everyday more.**

 

![Chart showing the growth of globally published CVEs in 2025](https://blog.unguess.io/hs-fs/hubfs/undefined-Aug-18-2026-02-06-36-1505-PM.png?width=445&height=670&name=undefined-Aug-18-2026-02-06-36-1505-PM.png)

 That sounds like progress, and partly it is. **But most security teams passed the limit of *fix everything we find* a long time ago. A longer list only helps if each item arrives with reliable context: is it real, is it reachable, does it matter *here*? Without that, you’ve simply grown the backlog.**

Pure-AI offensive tooling struggles on this last mile:

• **Validation and context.** Models are very good at flagging things that *resemble* vulnerabilities. They are far less dependable at confirming a flaw is genuinely exploitable in your specific environment. Which, today, means a lot of false positives. And false positives quietly burn your most expensive resource: analyst and tech time.

• **Unpredictable cost.** Token-based pricing scales with how much the system runs, not with what it finds. Point a model at a large codebase for testing and the bill grows whether or not anything useful comes back. Traditional pentesting has the same flaw, but on-demand AI makes overruns easier to trigger and harder to cap.

• **Explainability and control.** Most scanning agents still can’t give a clear, auditable account of what they did and didn’t touch, so coverage is hard to guarantee. Worse, some agentic tools take actions on the systems they’re aimed at that you didn’t anticipate, and wouldn’t have authorised.

• **Sovereignty.** Handing a third-party AI deep access to source code and sensitive systems isn’t always legally or politically acceptable; especially for regulated sectors and European organisations operating under stricter data-protection and supply-chain rules.

None of this means the upside is fake. It means the operational stakes are real, and that getting value out of AI offence requires a delivery model that filters signal from noise rather than amplifying both.

 

## CISOs don’t want AI. They want outcomes.

Step away from the tooling for a second. **When a security leader says *I want to use AI for vulnerability discovery*, what they almost always mean is: *more coverage, faster, at a lower and more predictable cost per real finding, with higher confidence in each one.***

**That’s an outcome. The frontier model is just one possible means to it – and not necessarily the one you should be buying directly.**

The distinction matters because it puts the spotlight on cost structure. Frontier-model APIs and native AI offensive platforms price the way traditional pentesting does: you pay for the process, not the result. You pay for the scan, the tokens, the engagement – including every false positive and every minute of misdirected activity when the configuration is slightly off.

Bug bounty turns that upside down.

 

## Bug bounty vs pentest vs AI tooling: pay for results, not activity 

**In a [bug bounty program](https://security.unguess.io/bug-bounty) you pay when a researcher delivers a validated, exploitable vulnerability – and only then. No finding, no invoice. Cost-per-finding doesn’t swing wildly, because there’s no cost at all when there’s nothing to report.**

And you can teach hunters what is important for your context. So that every vulnerability is a real complex attack chain, real exploitable and something to prioritize.

That’s been bug bounty’s differences over traditional pentesting for years. The newly interesting [comparison](http://nguess.io/services/use-case/cyber-security/)is against AI offensive tooling – and the same economics hold.

 

## The researchers already have the AI

Here’s the part the “AI replaces bug bounty” narrative misses entirely: bug-bounty researchers are among the fastest and most ruthless adopters of new technology anywhere in security. Frontier models are already standard equipment in their toolkits: used daily to accelerate reconnaissance, automate the repetitive work, run scans at scale, and probe black-box targets. Each researcher pairs that with their own methodology, intuition, prompting, and frequently their own custom-built tooling.

So the choice was never AI *or* bug bounty. It’s “yes, and.”

Run a program gives access to independent agentic pentesters, each running a different AI stack against your scope, from a different angle, with different expertise. You get the full reach of frontier models and AI-enabled tools, with two things no raw model gives you:

• **A human validates every finding.** The researcher who submits it stakes their reputation on it, and an expert triage team independently confirms exploitability and assesses real-world risk before anything reaches your team.

• **You only pay for results.** No finding, no fee. Outcomes, not activity.

This is also where the *less* flattering side of the AI boom gets handled. The same tools that help skilled researchers also flood platforms with low-quality, machine-generated submissions. AI slop that looks plausible and wastes everyone’s time. **Volume is up; so is the share of it that’s noise. In that environment, human triage and a vetted researcher community are the thing standing between you and a backlog of confident-sounding garbage.**

 

## NIS2, DORA and the Cyber Resilience Act: why this matters more in Europe 

For European organisations the calculus is sharper still. NIS2, DORA and the Cyber Resilience Act are converting “good security hygiene” into legal obligation and the CRA in particular requires manufacturers to operate coordinated vulnerability disclosure and handle reports against a clock.

**A delivery model that produces validated findings, keeps a clear audit trail, and doesn’t require handing your source code to an opaque foreign AI service it’s increasingly the only model that fits the regulatory and sovereignty constraints European boards are now accountable for.**

 

## Bug bounty is more relevant in the AI era, not less

**Frontier models change the volume and sophistication of what can be found. They don’t change the actual job facing a security team: separating signal from noise, proving exploitability, prioritising the fixes that matter, and not drowning in the process.**

A bug bounty program means you pay only for validated vulnerabilities while researchers point their own AI arsenals at your scope, capturing the value of the very latest models and tools without having to run, govern, or pay for any of them yourself.

You wanted the outcomes AI promised. Bug bounty has been delivering them all along. AI just made it better at the job.

 

***Do you want to see what a hacker sees? Try our new app, built from the hacker experience:*** [***https://security.unguess.io/app***](https://security.unguess.io/app)

 

## **FAQ**

## Frequently Asked Questions

### Will AI replace penetration testers and bug bounty hunters?

Not replace, but reshape. In the UNGUESS Security survey, 90% of researchers already use AI daily, mostly to understand unfamiliar code, write proofs of concept and draft reports. Very few use it to generate vulnerability hypotheses, which remains the part of the job that depends on creativity and connecting the dots. Researchers themselves expect easy bugs to disappear and only hard bugs to pay.

### What is the difference between a bug bounty and a penetration test?

A penetration test is priced per process: a dedicated team works on a defined scope for a defined period and is paid regardless of what it finds. A bug bounty is priced per result: dozens of independent researchers work on the same scope continuously and are paid only for validated, exploitable findings. The two models are complementary rather than alternative.

### Can AI find zero-day vulnerabilities?

Yes. Frontier models are very effective at reading large codebases and flagging patterns that resemble vulnerabilities. The limitation isn't discovery, it's validation: models struggle to confirm that a flaw is genuinely exploitable in a specific environment, they lack business logic context, and they produce a significant volume of false positives.

### Which security testing models combine human experts with AI?

Bug bounty programs already do, by design. Researchers run their own AI stacks against the scope, then a human validates every submission and an expert triage team independently confirms exploitability before anything reaches the customer's team. The customer gets the reach of frontier models with human accountability on each finding.

### How much does a bug bounty program cost compared to AI penetration testing?

AI offensive tooling is priced per token, which scales with how much the system runs rather than with what it finds: the bill grows even when nothing useful comes back. In a bug bounty program cost is tied to validated vulnerabilities only. No finding means no cost, which makes cost per real finding far more predictable.

### What do NIS2 and the Cyber Resilience Act require on vulnerability handling?

The Cyber Resilience Act requires manufacturers of products with digital elements to operate a coordinated vulnerability disclosure process and to handle reports against a defined clock. NIS2 extends risk management and incident notification obligations, with direct accountability for management bodies. Both push organisations towards models that produce validated findings and a verifiable audit trail.

[Cybersecurity](https://blog.unguess.io/tag/cybersecurity)

[Share via Facebook](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fblog.unguess.io%2Fai-bug-bounty-human-researchers) [Share via Twitter](https://twitter.com/intent/tweet?url=https%3A%2F%2Fblog.unguess.io%2Fai-bug-bounty-human-researchers&text=AI+Bug+Bounty%3A+why+human+hackers+still+find+what+AI+misses) [Share via Email](mailto:?subject=AI+Bug+Bounty%3A+why+human+hackers+still+find+what+AI+misses&body=https%3A%2F%2Fblog.unguess.io%2Fai-bug-bounty-human-researchers) [Share via LinkedIn](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fblog.unguess.io%2Fai-bug-bounty-human-researchers&title=AI+Bug+Bounty%3A+why+human+hackers+still+find+what+AI+misses&summary=We+asked+the+UNGUESS+Security+community+how+they+use+AI%3A+90%25+use+it+daily%2C+almost+none+for+vulnerability+hypotheses.+What+that+means+for+bug+bounty.)

## Similar posts

<https://blog.unguess.io/en/cybersecurity-the-rise-of-ethical-hacking?hsLang=en>

Cybersecurity

### [Cybersecurity: the Rise of Ethical Hacking](https://blog.unguess.io/en/cybersecurity-the-rise-of-ethical-hacking?hsLang=en)

Business leaders must push to educate their staff about simple social engineering scams like phishing. But they can do more: hire an ethical hacker. 

 Angela Meduri  May 19, 2021

<https://blog.unguess.io/en/penetration-testing-vs-bug-bounty-whats-the-difference?hsLang=en>

Cybersecurity

### [Penetration Testing vs Bug Bounty: what’s the difference](https://blog.unguess.io/en/penetration-testing-vs-bug-bounty-whats-the-difference?hsLang=en)

Both are used to detect and fix vulnerabilities. But what's the difference between Penetration testing and Bug bounty and which one should you use? 

 Angela Meduri  Oct 27, 2021

<https://blog.unguess.io/en/what-you-need-to-know-about-bug-security-bounty?hsLang=en>

Cybersecurity

### [What You Need To Know About Bug Security Bounty](https://blog.unguess.io/en/what-you-need-to-know-about-bug-security-bounty?hsLang=en)

A bug bounty or bug security bounty or bug bounty program, refers to a crowdsourcing initiative in which ethical hackers discover and report software...

 Newsroom  Jan 12, 2022

<https://blog.unguess.io/policymakers-enabling-bug-bounty?hsLang=en>

Cybersecurity

### [How policymakers are enabling Bug Bounty for a safer digital landscape](https://blog.unguess.io/policymakers-enabling-bug-bounty?hsLang=en)

Policymakers play a crucial role in spreading the adoption of bug bounty programs, one of the most efficient and innovative ways to address...

 Newsroom  Jun 8, 2023

![unguess-logo-1](https://blog.unguess.io/hubfs/unguess-logo-1.svg)

**© 2023 UNGUESS S.r.l.**

UNGUESS is a registered trademark of UNGUESS S.r.l.

 

- [![U2Y - Verified Carbon Footprint](https://blog.unguess.io/hs-fs/hubfs/U2Y%20-%20Verified%20Carbon%20Footprint.png?width=50&height=50&name=U2Y%20-%20Verified%20Carbon%20Footprint.png)](https://app.u2y.io/brands/314)
- [![UNGUESS is a leader in Crowd Testing Tools on G2](https://images.g2crowd.com/uploads/report_medal/image/1004327/medal.svg)](https://www.g2.com/products/unguess/reviews?utm_source=rewards-badge)
- [![UNGUESS is a leader in Test Management on G2](https://images.g2crowd.com/uploads/report_medal/image/1004327/medal.svg)](https://www.g2.com/products/unguess/reviews?utm_source=rewards-badge)
- [![UNGUESS is a leader in Crowd Testing Tools on G2](https://images.g2crowd.com/uploads/report_medal/image/1004379/medal.svg)](https://www.g2.com/products/unguess/reviews?utm_source=rewards-badge)
- [![UNGUESS is a leader in Europe Test Management on G2](https://images.g2crowd.com/uploads/report_medal/image/1004391/medal.svg)](https://www.g2.com/products/unguess/reviews?utm_source=rewards-badge)
- [![UNGUESS is a leader in EMEA Test Management on G2](https://images.g2crowd.com/uploads/report_medal/image/1004447/medal.svg)](https://www.g2.com/products/unguess/reviews?utm_source=rewards-badge)

#### SERVICES

- [AI Training](https://unguess.io/services/ai-training-testing/)
- [User Experience](https://unguess.io/services/use-case/user-experience/)
- [Software Quality](https://unguess.io/services/use-case/software-quality/)
- [Cyber Security](https://unguess.io/services/use-case/cyber-security/)
- [Accessibility](https://unguess.io/services/accessibility/)

#### SHOWCASE

- [Blog](https://blog.unguess.io)
- [Our Crowd](https://unguess.io/our-crowd/)
- [Tryber.me](https://tryber.me/)
- [Integrations](https://unguess.io/integrations/)
- [Partners](https://unguess.io/partners/)

#### COMPANY

[Work with us](https://unguess.io/life-at-unguess/#job-positions)  
[Get in touch](https://unguess.io/get-started/)

**General inquires:**  
[info@unguess.io](mailto:info@unguess.io)

<https://www.linkedin.com/company/app-quality><https://www.youtube.com/channel/UCyjAktfUKxitSp4IRrjUfOA><https://www.g2.com/products/unguess/reviews><https://www.facebook.com/tryber.me><https://www.instagram.com/tryber.me/>

 

[Privacy Policy](https://unguess.io/privacy-policy/)  | [ESG Policy](https://unguess.io/esg-policy/)  | [Personal Data Processing Notice: Customers and Suppliers](https://unguess.io/personal-data-processing-notice-customers-and-suppliers/) | [Model 231](https://unguess.io/model-231/) | [Ethical Code](https://unguess.io/ethical-code/) | [Cookies Settings](https://www.iubenda.com/privacy-policy/833252/full-legal)  |  [Terms & Conditions](https://unguess.io/terms-and-conditions/)  
UNGUESS S.r.l. – VAT 01603290196

 

© 2022 Kalungi, Inc. - All Rights Reserved. [Powered by Atlas - a B2B SaaS HubSpot theme](https://www.kalungi.com/atlas-hubspot-theme-for-b2b-saas-software)