agentsastLast reviewed 2026-09-13

Responsible disclosure of AI-found bugs

Direct answerThe same coordinated-disclosure rules as human findings, plus a duty to send only validated, reproducible reports so maintainers are not flooded.

In more detail

The curl bounty shutdown is the consequence of ignoring the second half. zkSecurity's CIRCL and Bron Labs disclosures, with minimised proofs of concept and bounty coordination, are the model.

False positive rate, Precision vs recall, Agentic scanning, LLM plus fuzzing, LLM plus symbolic execution or formal verification, Hallucinated vulnerabilities, Triage burden, Benchmark contamination, Human-in-the-loop, AI-assisted audit vs AI audit, Prompt injection in auditing pipelines, Continuous scanning and run-count coverage, Proof-of-concept harness, Threat model file, Severity calibration

Getting help

Firms on this index that handle this in practice: zkSecurity, Trail of Bits, Zellic, Nethermind Security.