HackerOne announced a Good Faith AI Research Safe Harbor framework intended to give AI security and safety researchers clearer authorization and legal protections when testing AI systems in good faith. The initiative is positioned as an industry standard to reduce legal ambiguity that can deter responsible AI testing, and it builds on prior efforts such as the U.S. Department of Justice’s 2022 policy shift on “good faith” security research under the Computer Fraud and Abuse Act (CFAA) and HackerOne’s earlier Gold Standard Safe Harbor model for traditional vulnerability research.
Under the framework, participating organizations can publicly signal adoption (e.g., via a profile “banner”) and commit to specific protections, including refraining from legal action, offering limited exemptions from restrictive terms of service, and supporting researchers if third parties pursue claims tied to authorized research. HackerOne leadership argued that AI testing can involve techniques and outcomes that do not fit neatly into conventional vulnerability disclosure norms, making a dedicated safe-harbor approach necessary to accelerate identification and remediation of AI-related risks across products and services.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
HackerOne announced a new Good Faith AI Research Safe Harbor framework to give researchers explicit authorization and legal protections for testing AI systems in good faith. The framework extends safe-harbor concepts from traditional software security research to AI and commits adopting organizations to avoid legal action, limit restrictive terms enforcement, and support responsible disclosure.
The U.S. Department of Justice issued a 2022 charging policy stating it would not pursue Computer Fraud and Abuse Act cases against good-faith security research. The policy later served as a foundation for arguments that legal protections should extend to AI security testing.
HackerOne launched its Gold Standard Safe Harbor in 2022 to provide clearer authorization and legal protections for traditional software vulnerability research. This framework became the basis for its later AI-focused safe harbor model.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecyberscoop.com
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.