OpenAI doubles its bio-jailbreak bounty to $50,000 and makes the program ongoing
OpenAI announced on July 9, 2026, that it is converting its GPT-5.5 Bio Bug Bounty into a standing program — the OpenAI Bio Bounty Program — and doubling the reward for a successful universal jailbreak.
What's new
OpenAI says it is "evolving our GPT-5.5 Bio Bug Bounty to become an ongoing private program—the OpenAI Bio Bounty Program," with the same focus: paying red-teamers who find a universal jailbreak able to defeat OpenAI's predefined biosafety challenge against its frontier models. Per OpenAI, "we're increasing reward amounts. The reward for a universal jailbreak for the OpenAI Bio Bounty Program has been raised from $25,000 to $50,000" for both GPT-5.6 and GPT-5.5, with smaller awards possible for partial wins at OpenAI's discretion.
Scope is shifting forward in time along with the model lineup: testing for GPT-5.5 continues on its original schedule through July 27, 2026, after which only GPT-5.6 remains in scope going forward. OpenAI says it will keep applying the program to future frontier models as they ship, rather than standing up a new bounty from scratch each time.
Participation stays limited and vetted: applicants submit a short application (name, affiliation, relevant experience), accepted researchers get onboarded to OpenAI's bio bug bounty platform, and must have an existing ChatGPT account and sign an NDA. Researchers who already applied to the original GPT-5.5 program don't need to reapply.
Context
This is the second bio-risk bounty program OpenAI has run, following a GPT-5 bio bug bounty and then the GPT-5.5-specific version launched earlier in 2026. Biosecurity red-teaming has become a standard pre-release step for frontier labs as models get better at domains — like biology and chemistry — where uplift to a bad actor is a specific, named risk category rather than a diffuse safety concern. Anthropic and Google DeepMind both run comparable red-teaming and responsible-disclosure programs targeting CBRN (chemical, biological, radiological, nuclear) risks in their own frontier models, and industry framework commitments like the White House's voluntary AI safety commitments and the EU AI Act's high-risk provisions increasingly expect this kind of testing as baseline practice, not a differentiator.
Why it matters
Converting a time-boxed bounty into an ongoing program signals OpenAI expects bio-risk red-teaming to be a permanent line item for every future frontier release, not a one-off response to a specific model's capabilities. Tying the program explicitly to "OpenAI's frontier models, starting with GPT-5.6 and going forward" means each new flagship model inherits bounty coverage automatically, rather than requiring OpenAI to relaunch the program and rebuild its vetted researcher pool each time.
The reward increase — doubling from $25,000 to $50,000 — is also a signal about how OpenAI is pricing this specific risk internally. A universal jailbreak that defeats biosafety guardrails is a narrow, high-severity failure mode, and raising the bounty suggests either that the existing reward wasn't attracting enough serious attempts, or that OpenAI judges the stakes for GPT-5.6-generation models to be higher than for its predecessors. Either reading points to biosecurity remaining one of the few risk categories where frontier labs are willing to pay real money for adversarial testing before problems reach production.
Corroborating sources
- Openai
https://openai.com/index/gpt-5-5-bio-bug-bounty/
“We're also excited to announce that we're increasing reward amounts. The reward for a universal jailbreak for the OpenAI Bio Bounty Program has been raised from $25,000 to $50,000”