NCSC discusses how bug bounty programmes can help address AI safeguard bypasses

05/09/2025 | NCSC

The National Cyber Security Agency (NCSC) has published a blog article exploring how existing cybersecurity practices can help mitigate risks in generative AI systems (Gen AI). The article focuses on safeguard bypasses, such as jailbreaking, agent hijacking, and indirect prompt injection. 

As a solution, the article highlights that the use of Safeguard Bypass Bounty Programmes (SBBPs) and Safeguard Bypass Disclosure Programmes (SBDPs), which are similar to bug bounty and vulnerability disclosure programmes in cybersecurity, encourages researchers to find and report successful bypasses. The NCSC cautions that organisations must have robust security management and disclosure processes in place before implementing such a programme to ensure vulnerabilities are handled correctly and to maintain trust.


Training Announcement: Freevacy offers a range of independently recognised professional AI governance qualifications and AI Literacy short courses that enable specialist teams to implement robust oversight, benchmark AI governance maturity, and establish a responsible-by-design approach across the entire AI lifecycle. Find out more.

Read Full Story
artificial intelligence, ai security

What is this page?

You are reading a summary article on the Privacy Newsfeed, a free resource for DPOs and other professionals with privacy or data protection responsibilities helping them stay informed of industry news all in one place. The information here is a brief snippet relating to a single piece of original content or several articles about a common topic or thread. The main contributor is listed in the top left-hand corner, just beneath the article title.

The Privacy Newsfeed monitors over 300 global publications, of which more than 6,250 summary articles have been posted to the online archive dating back to the beginning of 2020. A weekly roundup is available by email every Friday.