Microsoft's AI Red-Team Alliance Skips Its Own CVD Rule
Microsoft's new EXTRA program invokes coordinated disclosure to justify funding outside AI-safety labs, but builds none of CVD's reporting duty in.
On 27 July 2026, Microsoft's AI Red Team announced the External Red Team Alliance (EXTRA): unrestricted gifts to 18 university labs across six continents, plus a network of outside specialists who can be pulled into red-teaming AI systems for specific attack classes, languages, and cultural contexts an internal team won't fully cover. The announcement explains why this matters by reaching for a familiar analogy: "today's cybersecurity ecosystem depends on coordinated vulnerability research, responsible disclosure programs, academic inquiry, and global communities of independent security researchers." That's coordinated vulnerability disclosure (CVD) - the decades-old norm where a researcher reports a flaw to the vendor privately and holds it until a fix ships. Read the announcement's own text in full, though, and none of CVD's actual mechanics are in it. The funding Microsoft is describing doesn't come with the rule it's named after.
What the post says, and what it doesn't
EXTRA's structure is deliberate about one thing: the money comes with no strings. "The funding is unrestricted," the post states, "because the objective is not to direct research outcomes toward product requirements or predefined deliverables. The goal is to strengthen independent safety research capacity globally and create stronger long-term collaboration between academia and operational AI security teams." That's a real design choice, and a defensible one - Microsoft is explicitly not trying to buy specific findings or steer 18 independent labs toward its own product roadmap.
But a full-text search of the announcement turns up zero occurrences of "CVD," "bounty," "confidential," or "safe harbor." Nowhere does the post say what a funded lab should do if its research surfaces a live vulnerability or safety issue in an actual Microsoft AI product. That's a checkable absence, not a reading between the lines: the words simply aren't there.
Compare that to Microsoft's own Coordinated Vulnerability Disclosure principle, where "the researcher gives the vendor the opportunity to diagnose the issue and provides fully tested updates, workarounds, or other corrective measures before any party discloses detailed vulnerability or exploit information to the public." The Bug Bounty Program Guidelines, a separate document on the same microsoft.com/msrc property, state plainly: "You must follow Coordinated Vulnerability Disclosure (CVD) when reporting all Vulnerabilities to Microsoft. Submissions that do not follow CVD may not be eligible for Bounties and not following CVD could disqualify you from participating in the Program in the future." The guidelines go further - submissions "remain confidential and cannot be disclosed to third parties or as part of paper reviews or conference submissions," and exploit details must stay under wraps for 30 days after a fix, with disqualification and clawback as the stated penalty for jumping the gun. Microsoft's Copilot Bounty Program alone pays $250 to $30,000 per qualifying report, conditioned on exactly this process. Microsoft also runs a separate, non-monetary "AI Safety Acknowledgements" channel for researchers who submit AI safety findings and want public credit for it.
None of that machinery is referenced in the EXTRA announcement. This is this Article's own reading of what the post's language does, not a claim about what Microsoft intended: EXTRA invokes CVD's name and legitimacy to explain why external AI-safety research matters, without building CVD's actual rule - report first, publish later - into the terms of the program it's describing.
The gap that opens
Nothing in the text says this outright - it follows from reading the funding terms against Microsoft's own CVD and Bounty rules. Because EXTRA's grants are explicitly built to avoid "predefined deliverables," nothing in the announcement obligates a funded lab that finds a serious issue in a Microsoft AI product to route it through CVD, or through AI Safety Acknowledgements, before publishing. On the text available, that choice sits with the lab.
That tension is not stated anywhere in the post; it is this Article's own reading of what publishing academics and vendor disclosure regimes are each built to do. Academic research runs on open, prompt publication - that's the currency of the field, and it's precisely what CVD's confidentiality window is designed to delay. A funding structure built to keep Microsoft's hands off a university lab's research agenda has not, on the public record, been reconciled with Microsoft's own disclosure regime for exactly the kind of finding this program exists to produce. This is not a hypothetical that requires a specific incident to matter - it is a description of what the grant terms do and do not say today.
Why this cuts differently depending on where you sit
For the 18 funded labs, the absence is closer to freedom than risk: nothing in EXTRA's terms compels a researcher to sit on a finding, negotiate a disclosure timeline, or route a paper through Microsoft's review before submitting it to a conference. That is, for a university lab, mostly a feature.
For an organization that treats "Microsoft funds external AI-safety research" as a signal that Microsoft's AI products get independently vetted before problems become public, the reading has to be narrower. EXTRA funds independent research capacity. It does not, on its own published terms, guarantee that a finding travels back through Microsoft's existing reporting channels before it travels anywhere else. Those are different claims, and the announcement's own language - reaching for "coordinated vulnerability disclosure" as its justification - makes it easy to conflate them.
What a well-run AI operation checks instead of assumes
A well-run AI operation doesn't take a vendor's safety-research funding announcement as a proxy for a defined disclosure pipeline. It checks whether the announcement's own terms create one. Here, they don't: the two governing documents - the EXTRA post and the Bug Bounty Program Terms - sit on the same corporate property, use overlapping language, and were not, on this Run's research, connected to each other by Microsoft or by any of the coverage this Run located. Whether Microsoft's private grant agreements with each of the 18 labs contain disclosure language the public post doesn't restate is a separate, unverified question - this Article makes no claim about what isn't public. What is public is a program that borrows a well-established practice's name without stating that it follows the practice's central rule.
This is the same gap this outlet flagged from the other direction when OpenAI's GPT-Red paper reported a robustness claim with no named external verifier: one paper described an evaluation loop with no outside party in it at all; this program funds outside parties without stating what happens after they find something. Both are questions about what "external" actually buys an organization that reads a safety announcement and assumes the checking is already built in.
Source note: This Article is drawn from Microsoft's own published pages - the EXTRA announcement on the Microsoft Security Blog, the Coordinated Vulnerability Disclosure principle page, and the Bug Bounty Program Guidelines, all at microsoft.com/msrc. No AI vendor other than Microsoft is named. This Article does not address whether any private agreement between Microsoft and an individual funded lab contains disclosure terms beyond what the public announcement states.
Map your disclosures against AI & Technology.
Noa reads your disclosures, traces every number to its source, and flags what's missing.