Skip to content

Google Pauses Bug Bounty Program as AI-Generated Reports Flood the Pipeline

Short answer

Google paused its Open Source Software Vulnerability Rewards Program on October 1, citing a 'significant rise' in automated AI submissions, most of them invalid or hallucinated. The program stays frozen until at least Q1 2027, showing how AI-generated noise can overwhelm an intake system faster than teams can triage it.

What this means for operators

Any 10-200 person company with a public-facing intake channel — support tickets, RFP forms, vendor applications, bug reports — should treat this as a preview of what happens when submission volume scales faster than review capacity. If your team hasn't built automated pre-screening (validity checks, duplicate detection, confidence scoring before a human ever looks) you're one viral AI tool away from the same bottleneck Google just hit, except without the option to simply pause the business function for over a year.

Google has paused its Open Source Software Vulnerability Rewards Program as of October 1, citing a "significant rise" in automated submissions. The company said the vast majority of these AI-generated reports were not valid, and engineers and open source maintainers had been overwhelmed trying to sort genuine vulnerabilities from hallucinated ones. Google has not given a resumption date beyond promising "an update" in the first quarter of 2027.

The program rewarded researchers for finding vulnerabilities in Google's open source software. It is now suspended indefinitely, with participants redirected to the company's other bug bounty programs in the meantime.

This follows earlier warnings from cybersecurity experts, reported by TechCrunch last year, that AI-generated "slop" posed a serious risk to bug bounty programs generally — the concern being that automated tools can generate plausible-looking but false vulnerability reports faster than humans can verify them.

For companies that rely on any open intake channel — not just bug bounties, but support queues, sales inquiry forms, vendor onboarding, or RFP submissions — the lesson is structural rather than specific to security research. When submission cost approaches zero (as it does with AI-generated content) and review cost stays high (because a human must still judge validity), volume alone can break a process that worked fine at smaller scale. Google's response was to stop accepting submissions entirely. Most smaller companies don't have that option because the channel in question is how they get deals, support requests, or hires in the first place.

The practical move for an operations team is to build validation before the human step: automated checks for duplication, internal consistency, specificity and plausibility that can flag or de-prioritize low-quality submissions before they consume reviewer time. That's a narrower, more defensible use of AI than the submissions problem it's solving — screening content rather than generating it.

Source: TechCrunch AI

Next step

Discovery Sprint

If that argument holds for your operation, the next step is measuring it. Thirty minutes on one process, and we say whether the arithmetic is likely to close.

Put a time in the calendar

Thirty minutes, free. The sprint is what the call is about.

Fee
$2,500
Length
1-2 weeks

Ends in one of two answers: build this, or do not. The process map, the numbers and the ranked backlog are yours either way.