Safety

AI-generated text

Google pauses open-source bug bounty program amid surge of AI-generated, invalid reports

Google has suspended its Open Source Software Vulnerability Rewards Program effective October 1, citing a ‘‘significant rise’’ in automated, AI-generated submissions—most of which the company says are invalid.

Google pauses open-source bug bounty program amid surge of AI-generated, invalid reports

Google announced it has paused its Open Source Software Vulnerability Rewards Program effective October 1, 2026, and said it will provide an update on the program’s status in the first quarter of 2027.

Reason given: a ‘‘significant rise’’ in automated submissions

According to Google’s posts on X and on the program website, the suspension was prompted by what the company called ‘‘a significant rise in automated submissions, the vast majority of which are not valid.’’ Engineers and open-source maintainers were reportedly overwhelmed by reports that were invalid or contained AI "hallucinations."

Context and prior warnings

Last year TechCrunch reported that cybersecurity experts had warned artificial-intelligence–generated content could pose serious risks to bug bounty programs. Tom’s Hardware has reported that Google’s engineers and project maintainers were struggling under the volume of invalid reports.

What will happen next and Google's advice

  • The program was paused as of October 1, 2026.
  • Google expects to publish an update in the first quarter of 2027.
  • Meanwhile, participants are encouraged to submit findings to Google’s other bug bounty programs.

Why this matters

Finding and fixing vulnerabilities in open-source software is a key part of software security. When submission channels are clogged with automated, invalid or AI-hallucination reports, maintainers’ capacity to identify real issues is reduced and resources are diverted. Google’s decision to suspend the program highlights how large tech companies are confronting the operational challenges posed by automated AI submissions.

The company and program are named in the announcement as Open Source Software Vulnerability Rewards Program.