Google Pauses Open Source Bug Bounty as Invalid AI Reports Surge

News Summary
Google has paused its Open Source Software Vulnerability Rewards Program, a bug bounty scheme that paid researchers for finding security flaws in open source projects. The pause took effect on October 1, 2026, and Google cited "a significant rise in automated submissions, the vast majority of which are not valid." TechCrunch reported the move on October 4, 2026, at 1:31 PM Pacific Time. The episode is an early, concrete example of how AI-generated reports can strain the human review systems that software security depends on.
What Google Announced
The program is paused as of October 1, 2026. Google said it would share an update in the first quarter of 2027. In its notice, the company said the pause is due to a significant rise in automated submissions, and that the vast majority of them are not valid.
Google engineers and open source maintainers had been overwhelmed by reports that were invalid or contained hallucinated details, such as vulnerabilities that do not exist or code paths that cannot be triggered. Participants are encouraged to use Google's other bug bounty programs while the open source program is on hold.
What Is and Is Not Affected
According to coverage of the notice, the freeze is not a full shutdown. Reports filed before October 1 continue to be processed. Supply chain reports are not affected by the suspension, and certain cloud-related submissions can still be sent through Google's Cloud Vulnerability Rewards Program.
Why AI Submissions Strain Bug Bounties
Bug bounty programs depend on manual triage. A human reviewer has to read each report, try to reproduce the issue, and decide whether it is a real vulnerability and how severe it is. Language models can produce reports that look polished and technical in seconds, but a model can also describe a flaw that is not real. Each fake report costs a reviewer time to disprove, and that time cannot be spent on genuine findings.
When submission volume rises sharply while the share of valid reports falls, the cost of review grows faster than the value of what is found. The open source setting adds another layer, because many affected projects are maintained by small teams or volunteers who may have little capacity to sort through large queues.
A Problem That Was Anticipated
The pause follows earlier warnings. A TechCrunch report in July 2025 noted that cybersecurity experts saw AI-generated "slop" as a serious risk to bug bounty programs. Google had also tried a softer fix first. In March 2026, the company adjusted its vulnerability reward criteria to slow the flow of low-quality reports. The October 2026 pause suggests those changes were not enough for this particular program.
What This Means for Researchers and Maintainers
Security researchers who rely on rewards for open source work will need to look at other programs until Google provides its update. Maintainers of open source projects may see fewer incoming reports tied to this program in the short term, though invalid reports sent directly to projects can continue.
The larger lesson is about workflow design. AI tools can genuinely help find vulnerabilities, but a report is only useful if a person has verified it and can explain how to reproduce it. Programs may move toward stricter submission requirements, such as working proof-of-concept code, reproduction steps, or reputation-based limits on who can file.
What to Watch Next
The key date is the first quarter of 2027, when Google has promised an update. Observers will be looking for whether the program returns with new rules, such as tighter verification, rate limits, or a different reward structure, and whether other bug bounty operators adopt similar measures as AI-generated submissions continue to grow.
Sources
This report draws on TechCrunch's October 4, 2026 article by Anthony Ha, along with follow-up coverage from Yahoo Tech, daily.dev, Cryptobriefing, Mezha, NewsBytes, Tech AI Magazine, TechBuzz and Complete AI Training.