OpenAI Doubles Bio Bug Bounty Rewards and Turns It Into an Ongoing Safety Programme

OpenAI Doubles Bio Bug Bounty Rewards and Turns It Into an Ongoing Safety Programme

OpenAI has expanded its biosafety red-teaming effort into a permanent private programme, offering up to $50,000 for researchers who can crack its frontier AI models’ biological safeguards.

Imagine an AI model that knows a great deal about biology — enough to be genuinely useful to researchers, doctors, and students. Now imagine someone finding a way to make that same model hand over information it was specifically designed to withhold. That’s the problem OpenAI is paying people to help solve.

The San Francisco-based company has announced that its GPT-5.5 Bio Bug Bounty, originally a time-limited red-teaming challenge, is being evolved into a permanent, ongoing initiative called the OpenAI Bio Bug Bounty programme. And to mark the shift, it has doubled the top reward — from $25,000 to $50,000, which works out at around £39,000 to £40,000 at current exchange rates.

What Was the Original GPT-5.5 Bio Bug Bounty?

The original challenge launched with applications opening on 23 April 2026 and closing on 22 June 2026, with the testing window running from 28 April through to 27 July 2026. It was focused squarely on GPT-5.5, accessed through Codex Desktop only, and asked vetted researchers to find a single so-called “universal jailbreak” — a prompt that could bypass biosafety safeguards across five specific biology-related questions in one clean chat session, without triggering the model’s protective mechanisms.

That’s a harder task than it might sound. The model is built to refuse certain requests involving potentially hazardous biological information. Finding one prompt that defeats those protections consistently, across all five questions, is the kind of work that requires real expertise in both AI systems and biosecurity.

The top prize of $25,000 was on offer for the first researcher to pull it off. Smaller awards remained possible at OpenAI’s discretion for partial progress.

Now It’s Permanent — and the Stakes Are Higher

OpenAI has now announced that the programme will continue beyond the original GPT-5.5 timeline, expanding its scope to cover GPT-5.6 and future frontier models as they are released. Both GPT-5.6 and GPT-5.5 currently carry a $50,000 reward for a confirmed universal jailbreak against their respective biosafety challenges. After 27 July 2026, the GPT-5.5 testing window closes and only GPT-5.6 remains in scope.

This is a meaningful shift. Rather than a one-off exercise, OpenAI is building continuous external safety testing into how it develops and monitors its most capable models.

The programme remains private and invite-based. Applicants need a background in AI red-teaming, security, or biosecurity, an existing ChatGPT account, and a willingness to sign a non-disclosure agreement. That NDA covers prompts, completions, findings, and all communications — meaning successful jailbreaks won’t be published. Past applicants to the GPT-5.5 programme don’t need to reapply.

How Does This Compare to OpenAI’s Wider Bug Bounty Work?

OpenAI already runs a general Bug Bounty Programme covering security vulnerabilities across its systems, with rewards ranging from $200 to $20,000 depending on severity. The Bio Bug Bounty sits well above that ceiling. The gap tells you something about how seriously the company treats biosafety risks compared with conventional software security issues.

Red-teaming — where external experts try to break systems in controlled conditions — is a well-established practice in cybersecurity. OpenAI is applying the same logic to one of the more sensitive questions in AI development: what happens when a powerful model encounters a request for information that could, in the wrong hands, cause serious harm?

Transparency Questions Remain

Not everyone is entirely comfortable with the approach. Critics have pointed out that NDA-bound programmes make it difficult for independent observers to assess whether identified problems are being properly fixed. If a researcher finds a genuine flaw, the public has no way of knowing whether it was patched, how quickly, or how serious it was.

There are also broader questions about whether prompt-based jailbreak testing captures the full picture. Some researchers argue that focusing on individual prompts may miss wider systemic risks — such as how model capabilities grow over time, or how sophisticated actors might exploit AI in ways that don’t rely on a single clever sentence.

OpenAI’s position is that structured, private red-teaming allows it to learn from real-world probing without creating a public library of working attack prompts. The NDA, in that framing, is a safety measure rather than a secrecy tactic.

What This Means for Kent Residents

For anyone in Kent working in AI, cybersecurity, or biosecurity — whether at one of the county’s universities, an NHS trust, or a private research firm — the OpenAI Bio Bug Bounty programme is worth knowing about. Participation is fully remote, requires no connection to any Kent-specific organisation, and carries a potential reward of around £39,000 to £40,000 for a top finding. More broadly, for Kent residents as everyday users of AI tools, programmes like this represent one of the main ways companies attempt to catch dangerous gaps in their models’ safety before those gaps are exploited by someone with less benign intentions.

Source: @OpenAI

OpenAI Doubles Bio Bug Bounty Rewards and Turns It Into an Ongoing Safety Programme Quiz

5 questions