AI news ·
Google suspends open-source bug bounty after AI-generated reports overwhelm engineers
Google suspended its OSS bug bounty program after thousands of AI-hallucinated reports overwhelmed engineers. The pause leaves open-source projects without a key vulnerability reward channel until reforms land by Q1 2027.

Google suspended its Open Source Software Vulnerability Reward Program (OSS VRP) on October 1, 2026, after thousands of AI-generated bug reports flooded the system. The low-effort, often hallucinated submissions overwhelmed engineers and maintainers, pulling their attention away from real security vulnerabilities. The suspension affects product vulnerability reports while the company works on reforms, with updates expected by Q1 2027.
The company said many of the invalid reports were poorly written and required time-consuming manual validation. "Thousands of low-effort, poorly written submissions-many hallucinated-that overwhelmed engineers and maintainers, diverting focus from real vulnerabilities," Google stated. The program had been a key channel for identifying flaws in open-source projects, but the volume of noise made it unworkable.
The wider industry problem
Google is not alone. Linux maintainers reported being "completely overwhelmed" by AI-generated Common Vulnerabilities and Exposures (CVEs), with some release cycles hitting 2,000 reported vulnerabilities. Intel also paused its own bounty program, which paid up to $100,000 per flaw, citing similar concerns about submission quality. The pattern points to a structural challenge: AI tools have made it trivial to generate bug reports, but verification still depends on skilled human reviewers.
Security teams across IT and development face a growing tension. Automation reduces manual effort on the reporting side, yet it has flooded triage pipelines with noise. Every hallucinated report still demands a judgment call from an engineer who could otherwise be fixing actual vulnerabilities. The delays cascade-critical fixes sit in queues while teams sift through machine-generated claims.
What the suspension means for open-source security
The OSS VRP pause removes a formal incentive structure that rewarded researchers for finding genuine flaws. While Google plans to redesign the program, the gap leaves open-source maintainers with fewer external signals about vulnerabilities in their codebases. For organizations that rely on these projects-government systems, healthcare platforms, and enterprise IT stacks-the downstream risk increases when upstream security feedback loops break.
Professionals working with open-source dependencies should expect longer windows between vulnerability discovery and public disclosure during the suspension. Internal security reviews and dependency monitoring become more critical as external bounty programs recalibrate. For teams building on open-source foundations, this shifts more verification burden in-house.
Why this matters for IT and development teams
If your organization runs open-source software in production, the bounty program suspension means you lose a safety net that caught vulnerabilities before they reached your stack. Development and security leads should review their dependency monitoring processes now. Manual code audits and AI Security Analytics Courses can help teams build the skills to identify genuine threats without relying solely on external bug reports. The core lesson is clear: AI can generate leads, but it cannot replace the judgment needed to separate real risk from noise.