Google pauses open-source bug bounty program due to AI slop submissions
Google has announced a temporary pause on its open-source bug bounty program, citing a surge in automated submissions that are largely invalid. The pause took effect on October 1, 2026, and is expected to last until at least the first quarter of 2027. In a statement, Google explained that the decision was driven by a significant rise in AI slop submissions, which have overwhelmed the program.
The tech giant clarified that it will still accept some product vulnerability reports through its Cloud VRP and that the changes do not affect reports submitted before October 1, 2026. Google also emphasized its commitment to reformatting and improving the program, promising an update in Q1 2027. Meanwhile, the company encouraged participants to submit reports through other VRP programs or the Patch Rewards Program.
This move follows a broader trend in the open-source community, where AI-generated submissions have become a growing problem. Earlier this year, the Curl bug bounty program was shut down due to an influx of AI-generated contributions. Daniel Stenberg, lead maintainer at Curl, described the situation as placing a high load on security practitioners and aiming to reduce the noise created by these submissions.
In response to the widespread issue, a consortium of tech companies, including Google, Microsoft, OpenAI, and AWS, pledged $12.5 million to support security initiatives like Alpha-Omega and the Open Source Security Foundation (OpenSSF). The funding aims to develop sustainable security solutions and address the challenges posed by AI-generated reports.