Google Freezes Bug Bounty Programme Over Rise in AI Generated Submissions
Google has paused its open source bug bounty programme following what it described as a “significant rise” in automated submissions, most of which were found to be invalid.
The programme, known as the Open Source Software Vulnerability Rewards Program, rewards security researchers who identify vulnerabilities in Google’s open source software.
The company announced that the programme was suspended from October 1 and said it would provide an update in the first quarter of 2027.
Google said the decision was necessary because engineers and open source maintainers had become overwhelmed by a growing number of reports generated through automated tools, including submissions containing inaccurate information and apparent AI hallucinations.
“This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” Google said in a statement.
The development highlights growing concerns within the cybersecurity industry about the increasing use of artificial intelligence to generate bug reports without adequate human verification.
Cybersecurity experts have previously warned that AI generated submissions could create significant challenges for bug bounty programmes by increasing the volume of low quality reports that security teams must review.
While artificial intelligence can assist researchers in identifying vulnerabilities, the large number of inaccurate submissions can make it more difficult for legitimate security issues to receive timely attention.
Google has encouraged participants to consider its other bug bounty programmes while the open source initiative remains suspended.
The company is expected to provide further information about the programme and its future in the first quarter of 2027.
Source: TechCrunch
news via inbox
Get the latest updates delivered straight to your inbox. Subscribe now!

