Take transparency. The claim this article makes is that commercial bounty programs work against transparency by paying researchers only when they agree to NDAs. But transparency isn't a norm in software security to begin with; most vulnerability researchers work for labs and consultancies that rarely if ever disclose vulnerabilities. Disclosure of findings is not a norm on commercial software security assessments. Meanwhile, for any target an independent researcher can lawfully assess, the researcher retains the ability to ignore the bounty program and publish straight to Twitter.
My sense of it is that HackerOne has probably increased transparency, in the sense that I've read a lot of published reports on H1 that I don't expect I would have seen if the platform didn't exist, and, in my commercial work, haven't seen a lot of private reports that cut the other way.
Or this "Safe Harbor" argument, that commercial bounties force researchers to sign NDAs to be immunized from CFAA suits and prosecutions. Sure, but in the absence of H1, most of those CFAA immunizations weren't available on any terms. H1 doesn't enforce CFAA liability; CFAA liability is a natural default under US law. If anything, H1 is mitigating CFAA concerns, not amplifying them.
I don't know what to say about the labor law concerns here. I know that the people offering legal opinions here are lawyers and are versed in California labor law. But knowing what I know about how bug bounty people work: there is no way the median bug bounty "participant" would qualify for minimum wage and benefits at the various companies they interact with. The modal bounty participant has a grab bag of a couple dozen scripts they spam against hundreds of different companies with bounties. Is the claim here that H1 owes them a wage? Is the argument here simply that H1 needs to move out of California?
The minimum wage thing doesn't ring true either, since it implies that all project-based consulting --- that is, non-T&M consulting where clients pay an agreed-upon rate for an outcome regardless of the time a project takes to complete --- is susceptible to the "ABC" test as well. But project contracts are very common in California. I'm sure there's a subtlety I'm missing.
The "ISO compliance" thing is just silly. By the logic in this article, practically none of the thousands of commercial application pentests performed in 2020 to date will be "ISO compliant".
Ultimately: I think if you have to ask, you shouldn't run a bounty program. But that's mostly because I think bounty programs don't work very well, and generate an avalanche of noise. I don't think many of the reasons in this article matter.