Data Security, AI/ML, Bug Bounties

HackerOne clarifies AI training stance amid researcher concerns

Innovative ai showcase global tech summit 2025 digital innovations futuristic environment interactive viewpoint advancements in ai technology

HackerOne has addressed concerns from security researchers regarding the use of their submissions to train artificial intelligence models. The company clarified its position following the launch of its Agentic PTaaS, which combines autonomous agents with human expertise, as reported by The Register.

The controversy began when researchers questioned if their bug bounty submissions were being used to train HackerOne's AI agents. HackerOne CEO Kara Sprague stated unequivocally that the company does not train generative AI models on researcher submissions or confidential customer data, either internally or through third parties. She emphasized that their AI system, Hai, is designed to accelerate outcomes like validated reports and rewards, not to replace researchers.

Other platforms like Intigriti and Bugcrowd have also affirmed their policies against using researcher data for AI model training, while also holding researchers accountable for their use of AI tools and ensuring automated outputs meet submission standards.

Source: The Register

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds