Google has announced it is suspending its open source bug bounty program due to a dramatic increase in AI-generated vulnerability reports, most of which have been found invalid. The pause, effective from October 1, 2026, will last until at least the first quarter of 2027 as the company reassesses the program's submission process.
- Significant rise in automated and invalid AI-generated bug reports
- Google’s open source bug bounty program paused until early 2027
- Participants urged to consider other Google bounty initiatives
What happened
Google announced the suspension of its Open Source Software Vulnerability Rewards Program starting October 1, 2026. This pause comes as the program experiences an overwhelming surge of bug submissions generated by artificial intelligence systems. Reports flooded in at a volume and quality that Google described as mostly invalid or hallucinatory, which made it difficult for engineers and open source maintainers to effectively triage and address them.
The company communicated the decision through posts on its official channels and its program website, promising to reassess and provide an update in the first quarter of 2027. In the meantime, Google encouraged security researchers and participants to focus their efforts on its other bug bounty programs, which remain active and open for submissions.
Why it matters
This development highlights the growing challenge posed by AI-generated content in cybersecurity, particularly for programs relying on human-led verification of vulnerabilities. The rise of automated submissions has increased operational burdens for security teams, introducing large volumes of noise and false positives that can dilute efforts to identify genuine threats.
The temporary suspension of Google’s open source bounty program not only affects the ecosystem of researchers focused on open source software but also signals the need for stronger tools and strategies to manage AI-driven inputs. It underscores a broader industry concern about balancing automation benefits with the risks of decreased data quality and trust in crowdsourced security efforts.
What to watch next
Security professionals and the open source community will be watching closely as Google reviews and updates its process for accepting and validating AI-generated bug reports. Potential enhancements may include new filtering technologies, stricter submission criteria, or integrations of AI assistance to better vet incoming vulnerabilities.
Additionally, the impact on other bug bounty programs, both within Google’s portfolio and across the tech industry, will be important to monitor. The evolution of submission workflows and community engagement could set precedents for how similar programs handle the influx of AI-generated data in the future.