OpenAI says its upgraded rolling Bio Bug Bounty will pay up to $50,000 for universal GPT-5.6 biosafety jailbreaks, potentially making external adversarial testing a continuing control against biological-weapons misuse.
state: expiredheat: lowuncertainty: mediumconvergesscott: mediummodel-safety jailbreaks biosecurityOpenAI
What is this?
OpenAI says it is converting its GPT-5.5-specific Bio Bug Bounty into an ongoing private program for testing whether universal jailbreaks can defeat predefined biosafety challenges on its frontier models. Vetted researchers in AI red teaming, security, or biosecurity can apply on a rolling basis, must sign an NDA, and may receive up to $50,000—double the previous maximum—for qualifying GPT-5.5 or GPT-5.6 jailbreaks, with smaller discretionary awards for partial results. The supplied snippets establish a continuing external-testing mechanism, but do not show its effectiveness or whether discovered exploits become a durable control against biological-weapons misuse.
Why it matters to Scott
OpenAI’s rolling external bounty operationalizes Scott’s position that changing model behavior needs repeatable adversarial evaluation and reviewers that fail differently, creating a dated-receipts publishing opportunity. However, the evidence does not show that findings bind deployment or add architectural containment, so it also reinforces his warning that tested guardrails remain probabilistic rather than permission boundaries.
ip:concept.evaluation-driven-developmentip:source.security-reviewer-method-ebookip:concept.mechanically-different-verifiersip:concept.guardrail-illusionradar:concept.ai-safetyradar:concept.model-safety
queries asked of Scott's wikis
- continuous adversarial testing as an operational safety control
- bug-bounty incentives for model jailbreak discovery
- universal jailbreaks and systemic safeguard failure
- private red teaming versus public vulnerability disclosure
- biosafety evaluations as model deployment gates
- model safeguards maintained through external feedback loops
Measured heat
no measured readings yet — the hourly heat pass fills this in
How the heat travelled
no chain yet — the hourly chain pass fills this in
Evidence (2) — ⭐ canonical anchor
Interpretation history
2026-09-02T05:29:01Z
The launch has produced no visible participation, findings, or deployment consequences within the observation window. The rolling bounty remains established, but its effectiveness as a continuing biosafety control is still unsupported and no near-term confirming event is expected.
2026-08-31T04:28:25Z
No new participation, findings, or deployment consequences have emerged; this remains an established program launch rather than evidence that the bounty is an effective continuing biosafety control.
2026-08-31T04:25:36Z
grounded: converges/medium — OpenAI’s rolling external bounty operationalizes Scott’s position that changing model behavior needs repeatable adversarial evaluation and reviewers that fail d
2026-08-31T04:23:27Z
case created — A first-party program change creates a concrete, security-relevant episode, though evidence of researcher participation and useful findings has not yet emerged.
Decision trace
- 09-02 15:29expireThe launch has produced no visible participation, findings, or deployment consequences within the observation window. The rolling bounty remains established, but its effectiveness as a continuing bios
- 09-02 15:29alert_silentThis recheck adds no consequential evidence beyond the already-routed program launch; engagement-only observations do not justify renewed attention.
- 09-02 15:29alert_routeThis recheck adds no consequential evidence beyond the already-routed program launch; engagement-only observations do not justify renewed attention.
- 09-01 07:21sensor_dirtyengagement_update
- 09-01 05:21sensor_dirtyengagement_update
- 09-01 03:21sensor_dirtyengagement_update
- 09-01 00:21sensor_dirtyengagement_update
- 08-31 22:21sensor_dirtyengagement_update
- 08-31 20:21sensor_dirtyengagement_update
- 08-31 18:21sensor_dirtyengagement_update
- 08-31 17:21sensor_dirtyengagement_update
- 08-31 14:28repriceNo new participation, findings, or deployment consequences have emerged; this remains an established program launch rather than evidence that the bounty is an effective continuing biosafety control.
- 08-31 14:28alert_silentThe first-party program change was already routed, and the latest observation adds no consequential delta beyond unchanged engagement.
- 08-31 14:28alert_routeThe first-party program change was already routed, and the latest observation adds no consequential delta beyond unchanged engagement.
- 08-31 14:27alert_shadowThe first-party program change is a concrete move toward continuous external adversarial testing, with applications open now and materially increased incentives. It is useful today as a dated example
- 08-31 14:27alert_routeThe first-party program change is a concrete move toward continuous external adversarial testing, with applications open now and materially increased incentives. It is useful today as a dated example
- 08-31 14:25groundOpenAI’s rolling external bounty operationalizes Scott’s position that changing model behavior needs repeatable adversarial evaluation and reviewers that fail differently, creating a dated-receipts pu
- 08-31 14:23createA first-party program change creates a concrete, security-relevant episode, though evidence of researcher participation and useful findings has not yet emerged.