Culture

Google Suspends Bug Bounty Program Over AI Submissions

Google has paused its open-source bug bounty program after a surge of low-quality, AI-generated vulnerability reports overwhelmed its security engineers.

TechCrunch AI3 days agoCulture
Image: TechCrunch AI

Google has officially paused its Open Source Software Vulnerability Rewards Program as of October 1. The company announced that the freeze will remain in place until it provides an update, which is currently scheduled for the first quarter of 2027. The decision highlights a growing challenge in the cybersecurity landscape, where artificial intelligence tools are being used to flood triage systems with low-quality reports.

According to Google, the suspension was triggered by a "significant rise" in automated submissions. Security engineers and open-source maintainers found themselves overwhelmed by a massive influx of reports that were either completely invalid or filled with AI-generated hallucinations. Instead of helping secure open-source projects, the automated tools created a bottleneck of noise that distracted human reviewers from genuine security threats.

This development confirms warnings from cybersecurity experts who have previously flagged the risks of AI-generated content polluting bug bounty platforms. When researchers use large language models to scan code and draft reports without manual verification, the resulting output often lacks technical accuracy. For security practitioners, this pause means a temporary loss of a major incentive program for open-source auditing, though Google is directing researchers to its other active bug bounty initiatives in the interim.

The situation underscores a critical shift for security researchers and developers alike. While AI can accelerate code analysis, its unvetted application in vulnerability reporting threatens the viability of crowdsourced security. To restore these programs, organizations will likely need to implement stricter filtering mechanisms or revise their submission guidelines to penalize automated spam, forcing practitioners to focus on high-quality, human-verified findings rather than volume.

This is our own summary of reporting by TechCrunch AI

More in Culture