Apple has started limiting how many software vulnerabilities security researchers can report to the company, according to the Financial Times, whose reporting was highlighted by Techmeme.

The iPhone maker has introduced a cap on bug report submissions along with a 30-day cool-off period. Apple cited a deluge of AI-assisted reports as the reason for the change, describing the move as a way to manage a wave of incoming submissions. Researchers who hit the ceiling can request higher quotas, the Financial Times reported.

The context here is worth spelling out. Companies like Apple run bug bounty programs that pay outside researchers to find and report security flaws before criminals do. Those programs depend on a rough balance: researchers submit real findings, and a security team has enough time to triage each one. AI coding and analysis tools have made it dramatically cheaper to produce something that looks like a vulnerability report, which shifts that balance. Every submission still has to be read by a human, whether or not it turns out to hold up.

Apple's fix is essentially a rate limit — the same tool websites use against traffic floods, applied to a human review pipeline. The cap slows the overall flow, the cool-off period stops any one submitter from firing off report after report, and the quota-request path is meant to leave room for prolific researchers doing genuine work.

The source item does not specify the size of the cap, how many reports Apple received, or what share of them were AI-assisted.

It matters because the systems that keep everyday devices secure were built around human-scale effort, and AI tools are now generating work faster than the people on the receiving end can process it.