Google pauses bug bounty submissions amid AI-driven vulnerability report surge
Google has temporarily paused accepting certain bug bounty submissions due to an overwhelming influx of largely invalid, AI-generated reports. The surge highlights a growing challenge for security teams as AI-driven vulnerability discovery outpaces human validation capacity. Earlier this year, Google tightened rules for its open-source vulnerability program after seeing a sharp rise in low-quality AI submissions. Some reports contained incorrect claims or identified coding defects with little practical security impact.
While high report volumes don't always mean low-value findings, the sheer volume of AI-assisted submissions is straining security teams. Vercel, for example, received 1,285 vulnerability reports during a two-week security challenge, with dozens ultimately validated. However, the problem extends beyond bug bounty programs as enterprises adopt AI-assisted tools, potentially overwhelming their ability to validate and remediate findings.
Security experts warn that AI can generate convincing but poorly substantiated reports, forcing teams to verify whether the affected code exists and whether the claimed attack path is reachable. This imposes a direct cost on enterprises, as unassessed findings may consume engineering time unnecessarily. CISOs are advised to focus on actionable findings rather than the raw number of vulnerabilities identified.
The next major concern is that even confirmed vulnerabilities compete for limited engineering capacity. Teams must prioritize based on deployment context and evidence of exploitation rather than relying solely on scanner-generated severity ratings. Organizations should treat large volumes of low-quality reports as a resilience risk and implement measures like requiring reproducible evidence and grouping duplicate reports.