OpenAI Makes Its GPT-5.6 Bio Bounty Permanent and Doubles Prize to $50,000
OpenAI doubles its biosafety jailbreak reward to $50K and turns a one-time bounty into a permanent program, as GPT-5.6 earns a 'High' bio-risk rating across all three model tiers for the first time.

- $50K prize: OpenAI doubles its bio jailbreak reward from $25K to $50K and makes the program permanent, covering GPT-5.6 and beyond.
- The challenge: Find one universal prompt that defeats all five predefined biosafety questions in a single clean chat session without triggering moderation.
- GPT-5.6 rated High bio-risk: All three GPT-5.6 models (Sol, Terra, Luna) carry a "High" Biological and Chemical risk rating -- the first time every tier of a model family hits this level.
- Invite-only with NDA: Researchers apply via a rolling process; all findings are confidential and covered by NDA.
- GPT-5.5 scope ends July 27: After that date, only GPT-5.6 will be in scope for the ongoing program.
- Industry-wide pressure: OpenAI, Google DeepMind, Anthropic, and Meta are all racing to formalize biosafety evaluations as frontier models approach expert-level biological knowledge.
OpenAI has upgraded its Bio Bug Bounty from a time-limited experiment into a permanent, ongoing private program -- and doubled the prize money to $50,000. The move is not a routine security update. It is a direct response to a new generation of frontier models that OpenAI itself classifies as posing a meaningfully higher biological risk than anything it has shipped before.
From one-off to permanent fixture
OpenAI is evolving its GPT-5.5 Bio Bug Bounty into an ongoing private program -- the OpenAI Bio Bounty Program -- which will remain focused on universal jailbreaks that can defeat its predefined biosafety challenge against frontier models, starting with GPT-5.6 and going forward. The original program was a bounded experiment. This one has no end date.
The reward for a universal jailbreak has been raised from $25,000 to $50,000 for both GPT-5.6 and GPT-5.5. Smaller awards may be granted for partial wins at OpenAI's discretion. GPT-5.5 testing ends July 27, 2026, after which only GPT-5.6 will be in scope.
What the challenge actually asks you to do
A "universal jailbreak" in this context means something very specific. The challenge is to identify one universal jailbreaking prompt that can successfully answer all five bio safety questions from a clean chat session without prompting moderation. You cannot brute-force it question by question -- a single prompt has to defeat all five guardrails in one shot.
The five questions themselves are not public, which is intentional. ChatGPT's safety mechanisms are normally supposed to detect and prevent such attempts -- for example, if a user asks for the detailed manufacturing process of a biological weapon, the model would very likely refuse and explain that the information is dangerous. The bounty tests whether those refusals are truly robust or whether a clever enough prompt can route around all of them at once.
To participate:
- Applicants provide their name, affiliation, and experience through a rolling process. Those selected must have a ChatGPT account, sign a nondisclosure agreement, and use OpenAI's bounty platform.
- All prompts, completions, findings, and communications are covered by NDA.
- Past GPT-5.5 applicants do not need to reapply.
- OpenAI will invite a vetted group of trusted bio red-teamers and also review applications from new researchers with relevant experience in AI red teaming, security, or biosecurity.
Why GPT-5.6 changes the stakes
The timing of this upgrade is not coincidental. Under OpenAI's Preparedness Framework, GPT-5.6's Sol, Terra, and Luna models are all treated as High capability in both Cybersecurity and Biological and Chemical risk -- none of them reach the High threshold in AI Self-Improvement -- and OpenAI has implemented a tailored set of safeguards adapted to each model's capability profile.
All three GPT-5.6 models are rated High capability in both Cybersecurity and Biological/Chemical risk under the Preparedness Framework -- the first time small, fast models have hit High. None reach Critical. That last point matters: under the current Preparedness Framework, the High capability threshold assesses whether models can provide meaningful assistance to "novice" actors to create known severe threats. This is not a theoretical concern.
Sam Altman has warned that an adversary could use superintelligence to "design a bioweapon," and OpenAI has noted that capabilities such as "reasoning over biological data" could be misused and could help "people with minimal expertise" create biological threats. The International AI Safety Report 2026 concludes that AI systems now match or exceed expert-level performance on benchmarks measuring knowledge relevant to biological weapons development, citing OpenAI's o3 outperforming 94% of domain experts at troubleshooting virology lab protocols.
The real story: safety as a continuous red-team operation
What OpenAI is doing here is structurally different from a traditional software bug bounty. In a normal bounty, you are looking for implementation bugs -- memory errors, injection flaws, logic mistakes in code. Here, the "bug" is a property of the model's learned behavior, and the attack surface is the entire space of possible natural language prompts.
In an industry rich with traditional software bounties, OpenAI's initiative stands out due to its focus on universal exploits rather than isolated bugs. A jailbreak that works on one question but not another is not a win. The program is specifically designed to surface systemic weaknesses -- the kind that a determined adversary would actually exploit.
OpenAI is applying a similar model to AI safety by asking experts to actively probe its defenses and identify prompt-based weaknesses before threat actors do. The focus on biology is especially important because powerful AI models could be misused to support harmful scientific tasks if safeguards fail.
OpenAI's safety architecture for GPT-5.6 builds safeguards directly into the core model behavior rather than relying on a separate filter layer -- a design choice explicitly made to avoid the false-positive issues that created user backlash with other recent frontier model releases. The bounty program is the stress test for that architectural bet.
Who wins and what comes next
The biosecurity research community gets a well-funded, structured channel to do work that matters. The program gives outside specialists an ongoing way to test safeguards that enterprises may rely on when deploying advanced AI models in sensitive research environments. For the broader industry, a permanent program sets a precedent that biosafety red-teaming should be continuous, not a checkbox before launch.
The risks are real on both sides. If a researcher finds a working universal jailbreak, that information is covered by NDA and goes directly to OpenAI's safety team -- which is the point. In the past, there have been various methods to bypass safeguards, known as jailbreaks -- for example, the Timebandit loophole, where ChatGPT, through targeted user requests, lost its temporal context and readily provided instructions for illegal activities. Finding the next version of that, before bad actors do, is exactly what this program is designed to accomplish.
The broader industry is watching. Google DeepMind has expanded Gemini governance through an updated Frontier Safety Framework, Anthropic has formalized Claude safeguards with constitutional methods and deployment restrictions for high-risk domains including biosafety, and Meta released its Muse Spark model claiming a 98% bioweapons refusal rate. OpenAI making its bio bounty permanent raises the bar for what "serious biosafety" looks like across the field. If you have the right background, the application is rolling and open now.