Google suspends open-source bug bounty program amid AI report surge
Google has temporarily halted its open-source bug bounty program due to an overwhelming influx of AI-generated submissions. The company reported that most of these reports contained inaccurate or fabricated information, making it difficult for engineers and project maintainers to sift through the noise. The program stopped accepting new submissions on October 1, 2026, and Google plans to announce its future status in the first quarter of 2027.
The suspension highlights an unexpected downside of AI-assisted security research: the sheer volume of low-quality reports has strained the resources of those reviewing vulnerability reports. Despite the pause, participants can still engage with Google’s other vulnerability bounty programs during this period.
This decision comes amidst broader discussions about the risks and benefits of AI in cybersecurity. While some experts believe AI could speed up bug fixes and reduce vulnerabilities, incidents like this demonstrate the challenges of managing AI-generated data in security research.