Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions

Google has suspended its Open Source Software Vulnerability Rewards Program effective 1 October due to a sharp increase in automated submissions. The…

By Vane October 4, 2026 1 min read
Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions

Google has suspended its Open Source Software Vulnerability Rewards Program effective 1 October due to a sharp increase in automated submissions. The company states that the vast majority of these reports are invalid or contain hallucinations, overwhelming both engineers and open source maintainers. Last year, cybersecurity experts warned that artificial intelligence generated noise posed a serious risk to such schemes, and that warning now appears to be the primary issue confronting Google. The pause remains in place until the first quarter of 2027, when the firm promises to provide an update on its plans. Participants are currently encouraged to consider other bug bounty programs offered by the company instead.

This move highlights a growing friction between traditional vulnerability disclosure models and automated testing tools. While automated scanning can improve coverage, it currently generates too much false data for human reviewers to process efficiently. Google’s decision suggests that maintaining a functional open source security program requires stricter filtering mechanisms before accepting AI-generated reports.

  • The pause affects only the open source component, not other Google bounty schemes.
  • Researchers should expect no new updates before early 2027.
  • Invalid reports are being rejected in bulk rather than reviewed individually.
Scroll to Top