DEV Community

Mikhail Savchenko
Mikhail Savchenko

Posted on Originally published at inite.ai

Google Pauses Bug Bounty Program as AI-Generated Reports Flood the Pipeline

Google has paused its Open Source Software Vulnerability Rewards Program as of October 1, citing a "significant rise" in automated submissions. The company said the vast majority of these AI-generated reports were not valid, and engineers and open source maintainers had been overwhelmed trying to sort genuine vulnerabilities from hallucinated ones. Google has not given a resumption date beyond promising "an update" in the first quarter of 2027.

The program rewarded researchers for finding vulnerabilities in Google's open source software. It is now suspended indefinitely, with participants redirected to the company's other bug bounty programs in the meantime.

This follows earlier warnings from cybersecurity experts, reported by TechCrunch last year, that AI-generated "slop" posed a serious risk to bug bounty programs generally — the concern being that automated tools can generate plausible-looking but false vulnerability reports faster than humans can verify them.

For companies that rely on any open intake channel — not just bug bounties, but support queues, sales inquiry forms, vendor onboarding, or RFP submissions — the lesson is structural rather than specific to security research. When submission cost approaches zero (as it does with AI-generated content) and review cost stays high (because a human must still judge validity), volume alone can break a process that worked fine at smaller scale. Google's response was to stop accepting submissions entirely. Most smaller companies don't have that option because the channel in question is how they get deals, support requests, or hires in the first place.

The practical move for an operations team is to build validation before the human step: automated checks for duplication, internal consistency, specificity and plausibility that can flag or de-prioritize low-quality submissions before they consume reviewer time. That's a narrower, more defensible use of AI than the submissions problem it's solving — screening content rather than generating it.

Top comments (0)