OpenAI Doubles the Bio Bounty Reward to $50K and Makes the Program Permanent — Here's What Changed on July 9
OpenAI upgraded its Bio Bug Bounty to an ongoing private program on July 9, adding GPT-5.6 to scope and doubling the reward to $50,000.
On July 9, 2026, the same day GPT-5.6 became publicly available, OpenAI updated its Bio Bug Bounty program in a few meaningful ways: the reward doubled, GPT-5.6 joined the scope, and what was previously a model-specific challenge has been rebranded as an ongoing private program. This is the first time OpenAI has framed biosafety red teaming as a permanent fixture rather than a per-launch event.
Here is what changed and why it matters.
From One-Off Campaign to Ongoing Program
The Bio Bug Bounty has been running alongside each major model generation since GPT-5. The original GPT-5 program ran a ten-question bio and chemistry challenge with up to $25,000 on offer. GPT-5.5 tightened that to five biosafety questions and kept the $25K ceiling. Each of those was a time-limited, model-specific engagement.
The July 9 update changes the structure. OpenAI is now calling this the OpenAI Bio Bounty Program — an ongoing private program that will roll forward with each frontier model, starting with GPT-5.6. The GPT-5.5 challenge remains open and honoured through July 27, 2026, after which GPT-5.6 becomes the sole model in scope. Researchers who participated in the GPT-5.5 program do not need to reapply; they are automatically carried over.
The Reward Is Now $50,000
The top reward for a successful universal jailbreak has been raised from $25,000 to $50,000, covering both GPT-5.5 (until July 27) and GPT-5.6 going forward. Partial wins remain eligible for smaller discretionary awards, though OpenAI has not published a fixed partial-win tier.
That jump to $50K is a reasonable signal of how seriously OpenAI is treating this. The models being tested are meaningfully more capable on biology benchmarks than anything that came before them.
What the Challenge Actually Asks You to Do
The core task is unchanged: craft a single universal jailbreak prompt that can answer all five biosafety questions from a clean chat session without triggering any moderation response. The five questions are not disclosed publicly; accepted applicants see them only after onboarding to the bounty platform.
The emphasis on universal is deliberate. OpenAI is not hunting for narrow single-session exploits. A universal prompt can be embedded in automation, shared across communities, or packaged into tooling in ways that point vulnerabilities cannot. Finding one tells you something meaningful about the robustness of the safety stack across contexts, not just in a single carefully constructed conversation.
Why GPT-5.6 Raises the Stakes
GPT-5.6’s biology-related capabilities are notably higher than its predecessor. On SecureBio evaluations, GPT-5.6 Sol scores approximately nine percentage points above GPT-5.5 across benchmarks: 53.5% on the Virology Capabilities Test, 60.0% on Molecular Biology, 68.4% on Human Pathogen Capabilities, and 68.3% on World-Class Bio.
All three GPT-5.6 tiers, including Luna, the budget model, carry OpenAI’s “High” classification under the Preparedness Framework for both cybersecurity and biological risk. That is the first time the budget tier of any GPT family has triggered the highest non-Critical safety classification. More capable models with the same safety stack need harder scrutiny, which is the direct reason the bounty exists and why it has now been made permanent.
Who Can Apply
OpenAI is running a rolling application process. The program is private, so researchers are either directly invited from a vetted list of trusted bio red teamers or can apply through the official portal by providing their name, organisational affiliation, and relevant experience in AI security or biology. A ChatGPT account is required, and all accepted participants must sign a Non-Disclosure Agreement before accessing the platform.
The NDA is strict. It covers engineered prompts, model completions, security findings, and direct communications with the OpenAI team. Given that the challenge questions touch on biological threat intelligence, the restriction on public disclosure is not surprising, but it is worth being clear-eyed about before you apply. Nothing you find in this program can be published or discussed publicly.
What This Means for You
If you work in AI red teaming or biosecurity research, this is one of the most well-scoped and well-compensated public-facing safety programs available right now. The challenge is hard by design. The NDA is real. But $50,000 for a verifiable universal jailbreak is serious money, and the work is consequential.
If you participated in the GPT-5.5 program, you are already in. No action needed on your part to be eligible for the doubled reward before July 27.
If you are a developer building on the OpenAI API, the outcomes of this program will influence how biosafety filters are tuned across the platform. That is a double-edged situation: tighter guardrails reduce misuse risk, but they can also clip legitimate research or educational use cases that currently sit close to the boundary. It is worth monitoring how the safety stack evolves as findings from this program feed back into model behaviour.
For the broader public safety picture, the timing is notable. OpenAI is now supplying frontier AI to the Pentagon, and GPT-5.6 shipped first to a small group of trusted government partners before general availability. Running a permanent, independently staffed adversarial biosafety program alongside that trajectory is the kind of structural accountability that was largely absent in earlier model generations.
How to Apply
Applications go through OpenAI’s official portal. You will need to provide your name, organisational affiliation, and a summary of your relevant technical background. Once accepted, you will be onboarded to the bounty platform where the five challenge questions are disclosed.
The full program details and application link are at openai.com/index/bio-bug-bounty.