Google Puts Open-Source Bug Bounty Program on Hold as AI-Generated Reports Surge
Google has placed its open-source vulnerability rewards program on temporary hold after an influx of automated security reports created additional pressure on engineers and project maintainers.
The company suspended the Open Source Software Vulnerability Rewards Program starting October 1 and said it expects to provide an update on its future during the first quarter of 2027.
Automated Submissions Become a Growing Challenge
Google said the decision followed a substantial increase in automated vulnerability reports, with the overwhelming majority failing to identify valid security issues.
The surge is linked to the growing use of generative AI tools, which can produce security findings and reports at scale. However, some of these submissions may contain incorrect conclusions, fabricated information, or AI-generated hallucinations.
Google’s bug bounty program was designed to reward security researchers who discover legitimate vulnerabilities in open-source projects, allowing the company to address potential weaknesses before attackers can exploit them.
AI Makes Report Generation Easier
Generative AI has made it significantly easier to create and submit vulnerability reports, including reports that have not been supported by an actual security flaw.
For security engineers and developers, the problem is the time required to examine each submission. Teams must determine whether a reported issue is genuine before spending resources investigating or fixing it.
The growing number of low-quality submissions therefore risks turning a program intended to strengthen software security into an additional workload for development and security teams.
Google to Decide the Program’s Next Steps
Google has not announced when the vulnerability rewards program could resume. Instead, the company said it will provide further information about its future in the first quarter of 2027.
Until then, participants can take part in Google’s other vulnerability reward initiatives.
The suspension underscores a new challenge for the cybersecurity industry: AI can help security researchers identify vulnerabilities faster, but the same technology can also generate large volumes of unreliable findings, making it more difficult for experts to separate genuine threats from false reports.














