What happened

Google has paused its Open Source Software Vulnerability Rewards Program, the bug bounty scheme that pays researchers for finding security flaws in the company's open source code. The pause took effect on October 1, and Google says it will provide an update in the first quarter of 2027. The company announced the decision in posts on X and on the program's official website.
According to Google, the reason for the freeze is a "significant rise" in automated submissions, the vast majority of which turned out to be invalid. Reporting from Tom's Hardware adds detail to this picture, saying Google engineers and the maintainers of open source projects were overwhelmed by reports that were either wrong or contained outright hallucinated vulnerabilities, the kind of fabricated or nonsensical findings that AI tools can produce when used carelessly.

Why it matters

Bug bounty programs depend on a basic exchange: researchers spend time finding real vulnerabilities, and companies spend money and staff time verifying and fixing them. That exchange only works if the submissions are genuine. When AI tools make it cheap and fast to generate reports that look plausible but are not, the balance breaks down. Engineers and maintainers end up spending their limited time sorting through noise instead of fixing actual security problems, which is the opposite of what a bounty program is supposed to achieve.
This is not a new worry. TechCrunch reported last year that cybersecurity experts were already warning that so-called AI slop, low-quality, machine-generated content submitted as if it were genuine research, posed a serious risk to bug bounty programs across the industry. Google's decision to pause one of its own programs suggests that warning has become a concrete operational problem rather than a theoretical one.

The details

The announcement does not say how many submissions were affected, what proportion came from automated tools specifically, or which AI systems were involved in generating the reports. It also does not explain exactly how Google plans to address the problem before relaunching the program, whether that might mean new verification steps, stricter submission requirements, or some other filtering mechanism. Google has simply said an update will come in the first quarter of 2027, with no further specifics offered in the material reviewed.
  • The Open Source Software Vulnerability Rewards Program was paused as of October 1
  • Google cites a 'significant rise' in automated submissions, most of which are invalid
  • Reports reaching Google reportedly included hallucinated vulnerabilities, not just low-quality ones
  • An update on the program's status is promised for the first quarter of 2027
  • Participants are being pointed toward Google's other, still-active bug bounty programs
In the meantime, Google is directing researchers who want to keep submitting findings and earning rewards toward its other bug bounty programs, which remain operational. The company has not said whether those programs are seeing a similar increase in AI-generated submissions or whether they use different safeguards.

What to watch

The pause raises a broader question for the security research community: how bug bounty programs, many of which were designed around the assumption that a human researcher is behind each submission, adapt to a world where AI tools can generate large volumes of plausible-looking but unreliable vulnerability reports. Google's response, freezing the program rather than attempting a quick fix, suggests the company sees this as a structural problem that needs more than a minor policy tweak.
Whether other companies running similar programs face the same pressure, and whether they respond with pauses, new verification tools, or something else, is not addressed in Google's announcement. For now, the open source program sits in limbo until at least early 2027, and the broader industry conversation about AI slop in security research that began last year looks set to continue.

Sources