Home / News / Google Pauses Open Source Bug Bounty as Invalid AI Reports Surge
AI Security

Google Pauses Open Source Bug Bounty as Invalid AI Reports Surge

Oct 5, 20264 min read
Google Pauses Open Source Bug Bounty as Invalid AI Reports Surge

News Summary

Google has paused its Open Source Software Vulnerability Rewards Program, a bug bounty scheme that paid researchers for finding security flaws in open source projects. The pause took effect on October 1, 2026, and Google cited "a significant rise in automated submissions, the vast majority of which are not valid." TechCrunch reported the move on October 4, 2026, at 1:31 PM Pacific Time. The episode is an early, concrete example of how AI-generated reports can strain the human review systems that software security depends on.

What Google Announced

The program is paused as of October 1, 2026. Google said it would share an update in the first quarter of 2027. In its notice, the company said the pause is due to a significant rise in automated submissions, and that the vast majority of them are not valid.

Google engineers and open source maintainers had been overwhelmed by reports that were invalid or contained hallucinated details, such as vulnerabilities that do not exist or code paths that cannot be triggered. Participants are encouraged to use Google's other bug bounty programs while the open source program is on hold.

What Is and Is Not Affected

According to coverage of the notice, the freeze is not a full shutdown. Reports filed before October 1 continue to be processed. Supply chain reports are not affected by the suspension, and certain cloud-related submissions can still be sent through Google's Cloud Vulnerability Rewards Program.

Why AI Submissions Strain Bug Bounties

Bug bounty programs depend on manual triage. A human reviewer has to read each report, try to reproduce the issue, and decide whether it is a real vulnerability and how severe it is. Language models can produce reports that look polished and technical in seconds, but a model can also describe a flaw that is not real. Each fake report costs a reviewer time to disprove, and that time cannot be spent on genuine findings.

When submission volume rises sharply while the share of valid reports falls, the cost of review grows faster than the value of what is found. The open source setting adds another layer, because many affected projects are maintained by small teams or volunteers who may have little capacity to sort through large queues.

A Problem That Was Anticipated

The pause follows earlier warnings. A TechCrunch report in July 2025 noted that cybersecurity experts saw AI-generated "slop" as a serious risk to bug bounty programs. Google had also tried a softer fix first. In March 2026, the company adjusted its vulnerability reward criteria to slow the flow of low-quality reports. The October 2026 pause suggests those changes were not enough for this particular program.

What This Means for Researchers and Maintainers

Security researchers who rely on rewards for open source work will need to look at other programs until Google provides its update. Maintainers of open source projects may see fewer incoming reports tied to this program in the short term, though invalid reports sent directly to projects can continue.

The larger lesson is about workflow design. AI tools can genuinely help find vulnerabilities, but a report is only useful if a person has verified it and can explain how to reproduce it. Programs may move toward stricter submission requirements, such as working proof-of-concept code, reproduction steps, or reputation-based limits on who can file.

What to Watch Next

The key date is the first quarter of 2027, when Google has promised an update. Observers will be looking for whether the program returns with new rules, such as tighter verification, rate limits, or a different reward structure, and whether other bug bounty operators adopt similar measures as AI-generated submissions continue to grow.

Sources

This report draws on TechCrunch's October 4, 2026 article by Anthony Ha, along with follow-up coverage from Yahoo Tech, daily.dev, Cryptobriefing, Mezha, NewsBytes, Tech AI Magazine, TechBuzz and Complete AI Training.

AI SecurityGoogle