Google Pauses Bug Bounty Program Over AI Generated Reports

Oct 5, 2026
Google paused its Open Source Software Vulnerability Rewards Program after a surge in automated reports, most of which it said were invalid. The company plans to provide an update in the first quarter of 2027.

Google paused its Open Source Software Vulnerability Rewards Program on October 1 following a sharp rise in AI generated submissions, according to TechCrunch. The company said most of the automated reports were invalid, and researchers and maintainers had previously warned that AI slop posed a risk to bug bounty programs.

The program rewards researchers who identify vulnerabilities in Google's open source software. Google plans to provide an update on the program in the first quarter of 2027.

During the pause, researchers can submit eligible findings through Google's other vulnerability reward programs.

We hope you enjoyed this article

Consider subscribing to one of our newsletters like Cybersecurity AI Weekly or Daily AI Brief.

Also, consider following us on social media:

Free newsletter

Cybersecurity AI Weekly

Weekly newsletter about AI in Cybersecurity.

Industry analysis

2025 Global Business Services Agenda: Gen AI Takes Center Stage

The Hackett Group

This industry analysis by The Hackett Group explores the transformative impact of generative artificial intelligence (Gen AI) on global business services (GBS) in 2025. The study highlights the shift from exploration to acceleration of Gen AI initiatives, with 89% of executives advancing these projects to improve customer satisfaction, innovate products, and reduce costs. The report also discusses the challenges and strategies for successful Gen AI adoption, emphasizing the need for a technology-enabled operating model and the importance of reskilling the workforce.

Read more
Free, six days a week

Daily AI Brief: the AI news that matters, in your inbox.