The constraint in Apple's security review pipeline is triage capacity, not discovery. Researchers equipped with AI tools are surfacing vulnerabilities faster than Apple's internal team can process them, and the iPhone maker has responded by limiting how many reports a single researcher can submit.

The triage wall behind the policy

Bug bounty programs are built around an implicit ratio: the number of incoming reports should stay within the range a security team can actually review. AI has disrupted that ratio on the discovery side. A researcher running automated analysis can produce candidate vulnerabilities at a pace that would once have required a small team working for weeks. When the input rate scales faster than the review rate, the queue grows without bound.

Apple is managing that problem at the intake valve. By capping submission volume per researcher, it is trading report throughput for reviewable throughput. The company has not publicly specified what the new limits are.

What a submission cap costs the research community

The tradeoff is real. Limits on submission volume can slow the rate at which genuine, high-severity vulnerabilities reach Apple's security team. A researcher who has already hit the cap cannot submit additional findings, regardless of severity, until the next cycle.

That friction matters most for researchers using AI to do broad coverage scans. The tools are good at generating volume. The researcher still has to triage their own output before submitting, but even filtered results can exceed whatever cap Apple has set.

The economics driving the decision

Processing a vulnerability report is not free inside Apple's engineering organization. Each submission requires reproduction, severity scoring, and a patch timeline decision. Multiply a large per-researcher volume by a growing pool of AI-assisted researchers and the internal cost per quarter compounds quickly.

Whether the cap is temporary or reflects a permanent change to how Apple structures its researcher program has not been disclosed.

Related reading