Back to articles
Open Source

Google Pauses Open-Source Bug Bounty Program After Surge in AI Submissions

3 min read

Introduction

Bug bounty programs depend on outside researchers to identify, explain, and validate security problems that internal teams may miss. The growing use of generative AI is now putting pressure on that model. Google has paused its Open Source Software Vulnerability Rewards Program as of October 1, saying that automated submissions have risen significantly and that most of them are not valid. The company says it will provide an update in the first quarter of 2027.

Key points

  • The affected program is specific: Google’s open-source software vulnerability rewards program paid researchers for finding security vulnerabilities in the company’s open-source projects.
  • Submission quality is the central issue: Google said the vast majority of the increased automated submissions were invalid. TechCrunch, citing Tom’s Hardware, reported that Google engineers and open-source maintainers were also dealing with reports containing hallucinations.
  • There is no announced restart date: Google has not committed to a specific date for resuming the program, promising only an update during the first quarter of 2027.
  • Other programs remain available: While the open-source program is paused, Google is encouraging participants to consider its other bug bounty programs.

Why it matters

The incident highlights a distinction between automating security research and improving it. AI systems can scan code, suggest possible weaknesses, and produce a polished report quickly. But a plausible description is not the same as a confirmed vulnerability. Without a reproducible test, evidence of impact, and an understanding of the relevant code path, an AI-generated hypothesis can become additional triage work rather than a useful security signal.

That cost is especially important in open-source security. Engineers and maintainers already have to divide their time between development, patching, release work, and responding to researchers. A large stream of low-quality reports can make it harder to identify legitimate findings, even if the reports are submitted with good intentions. In that sense, the problem is not simply that AI can make mistakes; it is that automation can make those mistakes arrive at a scale that changes how the program must operate.

Google’s pause also suggests that established bounty rules may need new safeguards. Programs may place greater emphasis on reproducibility, evidence, and human validation before a report enters the main review queue. Such changes would not necessarily exclude AI-assisted research. They would instead distinguish between tools used to investigate a hypothesis and unverified output submitted as a finding.

The decision is not evidence that AI has no role in vulnerability discovery. A carefully reviewed report that demonstrates a real issue can still be valuable. But Google’s experience is a warning to other bounty operators: as automated submissions increase, filtering and verification are becoming central parts of the security program itself, not merely administrative steps around it.

Source: TechCrunch AI

Comments

Checking sign-in status...

Loading comments...

Related articles