Your daily read on AI, tech and business
AI Artificial Intelligence Bug Bounty Cybersecurity Google

Google bug bounty paused due to surge in AI submissions

X f in W

A conceptual representation of AI-generated digital code and bug reports cluttering a computer screen.

Google has suspended its Open Source Software Vulnerability Rewards Program after experiencing a massive surge in low-quality submissions generated by artificial intelligence. According to statements posted by the company on X and its program website, the freeze went into effect on October 1, 2026. Google plans to share an update on the program's status during the first quarter of 2027.

The company attributed the temporary halt to a "significant rise" in automated reports. Google clarified that the vast majority of these submissions are not valid. As reported by Tom's Hardware, the influx of flawed reports—many of which contained artificial intelligence hallucinations—had overwhelmed both Google engineers and open source maintainers tasked with reviewing them. While this specific program is on hold, Google is encouraging researchers to participate in its other active bug bounty programs.

The disruption highlights an escalating challenge within the cybersecurity landscape. TechCrunch previously reported that security experts had warned about the risks "AI slop" poses to traditional vulnerability reward initiatives. The current suspension of Google's open source program marks a concrete example of those warnings becoming reality, as automated tools enable users to generate and submit massive volumes of low-quality or entirely fabricated bug reports.

Why It Matters

This development underscores the growing strain that generative AI tools are placing on collaborative security efforts. While automated code generation and analysis software can assist legitimate researchers, the ease of generating bulk reports also allows low-effort participants to flood triage systems with noise. For open source projects, which often rely on limited developer resources, filtering through hundreds of hallucinated or invalid security reports could divert critical attention away from fixing genuine, high-severity flaws.

Google's decision to pause the program highlights a structural vulnerability in how platforms manage crowdsourced security. As AI tools become more sophisticated and accessible, organizations will likely need to redesign their ingestion pipelines to filter out automated spam. The pause suggests that current automated detection systems are insufficient, and the upcoming update in 2027 may reveal new standards for verifying the authenticity of researcher submissions.

Older Post
RelPulse
RelPulse