Google has paused its Open Source Software Vulnerability Rewards Program as of October 1, 2026, citing a significant rise in automated submissions generated by artificial intelligence. The tech giant announced that the vast majority of these AI-generated submissions were invalid or contained hallucinations, leading to an overwhelming workload for both Google engineers and open source maintainers who review the reports.
The suspension affects a program that previously rewarded security researchers for identifying vulnerabilities in Google’s open source software. In announcing the pause through posts on social media and the program’s website, Google stated that the decision was necessary due to the flood of automated submissions that lacked validity. The company promised to provide an update on the program’s status in the first quarter of 2027.
This development follows warnings from cybersecurity experts that TechCrunch reported on in 2025, when professionals in the field raised concerns about AI-generated content posing serious risks to bug bounty programs. Those early warnings appear to have materialized into the exact problem now confronting Google’s program, as the company struggles to manage the volume of low-quality, AI-generated vulnerability reports.
The issue of AI-generated submissions has created a significant burden for those responsible for reviewing and validating reported security vulnerabilities. When reports contain hallucinations or invalid information, reviewers must spend time investigating and dismissing these false leads rather than focusing on legitimate security concerns that could pose real threats to software systems.
During the pause, Google is encouraging participants who previously contributed to the Open Source Software Vulnerability Rewards Program to consider participating in the company’s other bug bounty programs. This suggestion indicates that while the open source program faces challenges with AI-generated submissions, Google’s other security research initiatives remain operational and continue to accept vulnerability reports from the security research community.