Apple has introduced submission caps and a 30-day cool-off period for its security bug reporting, citing a deluge of AI-assisted reports that claim serious flaws but arrive without human validation, the Financial Times reports. Researchers can request higher quotas; repeat filers of ineligible AI-generated reports face 180-day pauses and, after multiple strikes, permanent removal from the bounty program.