In short
Google has paused its open source bug bounty program because a surge of AI-generated submissions overwhelmed reviewers, most of them invalid. The company plans to revisit the program in early 2027.
- Google paused its open source vulnerability rewards program on October 1.
- The company says the surge in automated AI submissions is mostly invalid.
- Reviewers were overwhelmed by hallucinated or low-quality reports.
- Google will provide an update in the first quarter of 2027.
- The move highlights a growing cybersecurity problem for bug bounty programs.
Google has paused its Open Source Software Vulnerability Rewards Program after a sharp increase in AI-generated submissions overwhelmed reviewers and left most reports invalid. The suspension took effect on October 1, and Google says it will provide an update in the first quarter of 2027.
The decision matters because bug bounty programs depend on high-signal reports from security researchers, but automated and hallucinated submissions can bury real vulnerabilities under a wave of noise. Google’s move underscores a growing problem across cybersecurity: generative AI is making it easier to file reports faster, but not necessarily better.
What Google announced
Google said it has temporarily frozen the open source arm of its vulnerability rewards program because it has seen a “significant rise” in automated submissions. According to the company, the vast majority of those reports are not valid.
The company shared the notice on its program website and on X, telling participants that the pause began on October 1. Google added that it plans to revisit the program and provide an update in the first quarter of 2027.
In the meantime, researchers are being pointed toward Google’s other bug bounty offerings, which remain available.
Why the program was paused
Google says the core issue is volume. The company described an influx of AI-assisted or AI-generated submissions that created too much work for engineers and maintainers tasked with reviewing reports.
Open source vulnerability programs rely on careful triage. Each submission must be checked to determine whether the issue is real, reproducible and within scope. When a flood of low-quality reports arrives, the review process slows down for everyone, including researchers who are doing legitimate work.
Google said the pause was driven by a significant increase in automated submissions, most of which were not valid.
That description aligns with a problem security researchers have been warning about for months: AI tools can generate plausible-looking vulnerability write-ups that sound technical but fail basic verification. Some reports may describe issues that do not exist at all, while others may misidentify a bug’s cause, impact or severity.
How AI is changing bug bounty programs
AI is making bug bounty work both easier and harder. It can help researchers scan code, spot patterns and draft reports quickly. But it also lowers the barrier for people to submit large numbers of superficial or fabricated findings.
Why hallucinated reports are a problem
Hallucinated reports are a problem because they consume scarce reviewer time without improving security. Every invalid submission has to be screened out before maintainers can focus on genuine vulnerabilities.
For open source projects in particular, that extra burden can be significant. Many of these programs are not staffed like large enterprise security operations centers. They often depend on engineers and maintainers who already balance bug triage with product development and code maintenance.
What makes open source especially vulnerable
Open source programs are especially vulnerable because they are designed to welcome broad participation. That openness is a strength, but it also makes them a target for automated abuse when AI systems can produce endless variations of polished-looking submissions.
Unlike some tightly controlled internal security workflows, open source bounty programs often receive reports from a global pool of contributors. The result is a large and diverse intake that can be difficult to filter when the signal-to-noise ratio drops sharply.
Timeline of the pause
The key dates in Google’s announcement are straightforward, but they mark an important shift in how the company is handling its open source security intake.
| Date | Event | Why it matters |
|---|---|---|
| October 1, 2026 | Google pauses its Open Source Software Vulnerability Rewards Program | New submissions to the open source bounty track are temporarily halted |
| October 4, 2026 | News of the pause spreads publicly | The move draws attention to the growing burden of AI-generated reports |
| Q1 2027 | Google plans to provide an update | The company has not yet said whether the program will reopen in its current form |
What this means for security researchers
For legitimate researchers, the pause is both a disruption and a warning. It signals that companies may tighten rules, slow intake or redesign bounty systems if AI spam continues to rise.
Researchers who focus on open source targets may need to adjust how they package evidence, documentation and reproducibility steps. As AI-generated noise becomes more common, higher-quality reporting will likely matter even more.
The move may also encourage bounty operators to change their review processes. Possible responses include stricter submission templates, stronger identity verification, reputation systems for contributors or automated pre-screening tools that can detect low-value reports before humans review them.
Possible industry responses
- Require more detailed reproduction steps before accepting a report
- Use automated filters to flag obvious AI spam or duplicate submissions
- Limit the number of submissions from new contributors
- Expand reputation-based rewards for proven researchers
- Separate AI-assisted drafting from human validation requirements
Why this issue goes beyond Google
Google is not the only company facing the challenge. The pressure on security teams reflects a broader pattern across online platforms, support channels and research workflows: AI can dramatically increase output without guaranteeing accuracy.
In bug bounty programs, that is especially costly because the entire model depends on trust. Companies pay for credible findings. Researchers expect fast, fair evaluation. When automated submissions swamp the queue, both sides lose time and confidence.
This is also a reminder that AI’s operational impact is no longer limited to chatbot answers or content moderation. It is affecting the basic infrastructure of software security, including how vulnerabilities are discovered, reported and prioritized.
How Google’s other bounty programs fit in
Google said participants should consider its other bug bounty programs while the open source track is paused. That suggests the company still sees value in external vulnerability research, but wants to narrow the scope where the AI-driven flood has become unmanageable.
That distinction is important. A pause in one program does not mean Google is abandoning bug bounties altogether. Instead, it appears to be making a targeted response to a specific operational problem in its open source channel.
For a company of Google’s scale, the choice may also serve as a test case for the rest of the industry. If AI noise can force a pause in one of the world’s largest tech companies’ open source security programs, smaller organizations may face the same issue with fewer resources and less room to adapt.
What happens next?
Google has not announced a permanent shutdown, only a pause with a future review. That leaves open several possibilities: a redesigned intake process, stricter validation rules, or a more selective reopening once the volume of automated reports becomes manageable.
Between now and early 2027, the company is likely to evaluate how much of the burden comes from AI-generated content, how much is simple spam, and whether new filters or policy changes can restore the program’s usefulness.
For now, the takeaway is clear. AI is not only helping security researchers find bugs; it is also creating a new class of operational overhead that can overwhelm the systems meant to reward them. Google’s pause is an early sign that bug bounty programs may need to be redesigned for the AI era.
Key facts at a glance
| Item | Details |
|---|---|
| Company | |
| Program affected | Open Source Software Vulnerability Rewards Program |
| Reason for pause | Sharp rise in automated AI submissions, most of them invalid |
| Pause start date | October 1, 2026 |
| Next expected update | First quarter of 2027 |
Frequently asked questions
Why did Google pause its bug bounty program?
Google paused its bug bounty program because it saw a significant rise in automated submissions, and the company said most of them were not valid. The influx created too much review overhead for engineers and open source maintainers.
When did the pause take effect?
The pause took effect on October 1, 2026. Google said it would provide an update in the first quarter of 2027, but it has not yet said whether the program will reopen in its current form.
Which bug bounty program was affected?
The affected program is Google’s Open Source Software Vulnerability Rewards Program. Google said participants can still consider its other bug bounty programs while the open source track is temporarily paused.
How is AI affecting bug bounty programs?
AI is making it easier to produce large numbers of submissions, but many of those reports are low quality, duplicated or hallucinated. That floods review queues and makes it harder for security teams to identify real vulnerabilities quickly.
Will Google’s bug bounty program return?
Google has not announced a permanent shutdown. It has described the move as a pause and said it plans to issue an update in the first quarter of 2027, which suggests the company is still evaluating next steps.









