Google Suspends Open-Source Bug Bounty Program Due to Wave of AI-Generated Submissions

Google has temporarily halted submissions to its Open Source Software Vulnerability Rewards Program after experiencing a surge of invalid, automated reports generated by artificial intelligence systems. The company maintains its other bounty programs, including patch rewards and cloud vulnerability reporting, while working to redesign the suspended program to filter out low-quality submissions. Google plans to provide updates on program reforms in the first quarter of 2027.
Google's decision affects only one component of its vulnerability rewards ecosystem. The company maintains active incentive programs for software patches and cloud-specific vulnerabilities, meaning security researchers have alternative channels for reporting findings. The OSS VRP suspension represents a targeted pause rather than a complete program shutdown, with Google committing to structural improvements by the first quarter of 2027 to implement filtering mechanisms against low-quality submissions.
This suspension reflects a broader industry challenge that has affected multiple organizations recently. Both curl's maintainers and Intel have taken similar actions within the past year, citing overwhelming volumes of AI-generated reports that consume resources without yielding legitimate security disclosures. The volume of invalid submissions has apparently become severe enough that pausing new submissions is considered preferable to continued operational strain.
The suspension could create friction between Google and the security research community that relies on bug bounty programs for income and professional reputation. Researchers may redirect efforts toward competing programs, potentially reducing the diversity of vulnerability discoveries across Google's open-source portfolio. Conversely, the pause may ultimately strengthen the program by forcing development of better validation systems. The broader implication suggests that AI-assisted security tooling, while potentially increasing vulnerability discovery overall, may simultaneously degrade the efficiency of crowdsourced security reporting mechanisms that organizations depend upon.