Google pauses open source bug bounty program over flood of AI-generated submissions
Google has suspended its Open Source Software Vulnerability Rewards Program as of October 1, citing a sharp increase in automated submissions, most of which were invalid. The company said it plans to provide an update in the first quarter of 2027 and is directing researchers to its other bug bounty programs in the meantime.
GoKawiil's interpretation of the reporting above, not reported fact.
The pause suggests AI tools are making it easy to generate large volumes of low-quality vulnerability reports, which could be straining the human reviewers who vet them, according to reporting from Tom's Hardware describing overwhelmed engineers and maintainers. This echoes earlier warnings from cybersecurity experts that AI-generated 'slop' threatens the viability of bug bounty programs industry-wide, potentially forcing other companies to reconsider how they manage crowdsourced security research.
- Google paused its Open Source Software Vulnerability Rewards Program starting October 1.
- The company cites a significant rise in automated, mostly invalid AI-generated submissions.
- Google says it will provide an update on the program in the first quarter of 2027.
Source: techcrunch.com — Anthony Ha, 2026-10-04
Published there as: “Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.