DMR News

Advancing Digital Conversations

Google Pauses Open Source Bug Bounty Program After Surge In AI-Generated Reports

ByJolyen

Oct 8, 2026

Google Pauses Open Source Bug Bounty Program After Surge In AI-Generated Reports

Google has suspended its Open Source Software Vulnerability Rewards Program after a sharp increase in AI-generated submissions, many of which the company said were invalid. The pause took effect on October 1 and is expected to remain in place until at least the first quarter of 2027.

The program rewards security researchers who identify vulnerabilities in Google’s open source software projects. According to announcements published on Google’s bug bounty website and the company’s official X account, the suspension was prompted by a substantial increase in automated submissions.

Invalid AI Reports Overwhelm Review Process

Google said the overwhelming majority of the automated reports submitted to the program were not valid.

“This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” the company said.

According to reporting from Tom’s Hardware, Google engineers and open source maintainers faced growing difficulty managing the influx of submissions, many of which reportedly contained hallucinated vulnerabilities or incorrect findings.

The volume of low-quality reports increased the workload for reviewers responsible for determining whether security issues were legitimate.

Growing Challenge For Bug Bounty Programs

The development reflects concerns raised by cybersecurity researchers about the impact of AI-generated content on vulnerability disclosure programs.

Last year, industry experts warned that large volumes of AI-generated reports were creating challenges for bug bounty operators by flooding systems with inaccurate or fabricated findings. The issue has increasingly affected programs that rely on human reviewers to verify vulnerability claims before rewards are issued.

As generative AI tools become more widely available, security teams have reported spending more time filtering invalid submissions before identifying genuine security vulnerabilities.

Google’s decision represents one of the most prominent examples of a major technology company temporarily halting a bug bounty initiative because of the growing volume of AI-assisted submissions.

Other Google Programs Remain Available

While the open source program is suspended, Google said participants can continue contributing through the company’s other vulnerability reward programs.

The company did not provide details on any changes that may be introduced before the program resumes. Instead, Google said it plans to provide an update during the first quarter of 2027.

Until then, researchers seeking bug bounty rewards are being encouraged to submit findings through Google’s remaining active programs.


Featured image credits: Wikimedia Commons

For more stories like it, click the +Follow button at the top of this page to follow us.

Jolyen

As a news editor, I bring stories to life through clear, impactful, and authentic writing. I believe every brand has something worth sharing. My job is to make sure it’s heard. With an eye for detail and a heart for storytelling, I shape messages that truly connect.

Leave a Reply

Your email address will not be published. Required fields are marked *