
Google has suspended its Open Source Software Vulnerability Rewards Program after experiencing a massive surge in low-quality submissions generated by artificial intelligence. According to statements posted by the company on X and its program website, the freeze went into effect on October 1, 2026. Google plans to share an update on the program's status during the first quarter of 2027.
The company attributed the temporary halt to a "significant rise" in automated reports. Google clarified that the vast majority of these submissions are not valid. As reported by Tom's Hardware, the influx of flawed reports—many of which contained artificial intelligence hallucinations—had overwhelmed both Google engineers and open source maintainers tasked with reviewing them. While this specific program is on hold, Google is encouraging researchers to participate in its other active bug bounty programs.
The disruption highlights an escalating challenge within the cybersecurity landscape. TechCrunch previously reported that security experts had warned about the risks "AI slop" poses to traditional vulnerability reward initiatives. The current suspension of Google's open source program marks a concrete example of those warnings becoming reality, as automated tools enable users to generate and submit massive volumes of low-quality or entirely fabricated bug reports.
Why It Matters
This development underscores the growing strain that generative AI tools are placing on collaborative security efforts. While automated code generation and analysis software can assist legitimate researchers, the ease of generating bulk reports also allows low-effort participants to flood triage systems with noise. For open source projects, which often rely on limited developer resources, filtering through hundreds of hallucinated or invalid security reports could divert critical attention away from fixing genuine, high-severity flaws.
Google's decision to pause the program highlights a structural vulnerability in how platforms manage crowdsourced security. As AI tools become more sophisticated and accessible, organizations will likely need to redesign their ingestion pipelines to filter out automated spam. The pause suggests that current automated detection systems are insufficient, and the upcoming update in 2027 may reveal new standards for verifying the authenticity of researcher submissions.
Source: TechCrunch
Original source: https://techcrunch.com/2026/10/04/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai-submissions/