Cookie Consent by Free Privacy Policy Generator

Google pauses open source bug bounty due to AI-generated submissions

Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP) due to a significant rise in invalid, AI-generated submissions, according to TechCrunch reporting on 4 October 2026. The company stated that the volume of low-quality reports, many of which appear to have been automatically generated using AI tools, has overwhelmed the programme's ability to process legitimate vulnerability disclosures. Google has narrowed the scope of the bug bounty to focus on a smaller set of critical open source projects while it works to address the influx of automated submissions. The pause reflects a broader challenge facing bug bounty programmes across the industry, as AI tools make it easier to generate large volumes of plausible-sounding but ultimately invalid security reports.

Why this matters for UK organisations

For UK organisations that operate their own bug bounty programmes, vulnerability disclosure processes or security research partnerships, this development highlights a practical operational risk: the increasing use of AI to generate security reports at scale can overwhelm triage processes, delay the handling of genuine vulnerabilities, and create noise that makes it harder to identify real issues. Many UK businesses in technology, finance and critical infrastructure sectors rely on external researchers to identify flaws in their products and services, and the quality of those submissions directly affects how quickly legitimate vulnerabilities can be validated and fixed. The Google incident suggests that organisations may need to adapt their intake processes, triage workflows and quality filters to manage AI-generated submissions without discouraging genuine research. This is also relevant for internal security teams that receive vulnerability reports from employees, customers or third parties, as the same challenge may emerge in those channels as AI tools become more widely used.

What to review

UK businesses running vulnerability disclosure or bug bounty programmes should review how submissions are triaged, validated and prioritised. Consider whether your organisation has the capacity to filter low-quality or automated reports effectively, and whether clear submission guidelines and quality expectations are communicated to researchers. This is also an opportunity to assess whether your security team has the tools and processes needed to distinguish genuine vulnerabilities from AI-generated noise, particularly as the volume of automated submissions is likely to increase across the industry. Organisations should also consider whether their vulnerability disclosure policy includes guidance on the use of automated tools, and whether they have a clear process for handling reports that appear to be generated without meaningful validation or testing. Where bug bounty programmes are managed by third-party platforms, ensure that those platforms have effective quality controls and triage support to manage the changing nature of submissions.

Source: TechCrunch

News and blog posts
Today's brief highlights the operational challenges organisations face when...
Unauthorised parties accessed names, addresses and personal identification...
Citrix has disclosed a third actively exploited zero-day vulnerability in its...
Google has temporarily stopped accepting product vulnerability reports through...