Search Beyond News…

Google halts open-source bug bounty program as AI-generated submissions overwhelm the system

Executive summary: Google froze its open-source bug bounty program because of a significant increase in AI-submitted reports. This highlights the growing problem of AI-generated content overwhelming security review processes, potentially slowing down vulnerability discovery and patching in open-source projects.

Who is involved: Google and the open-source security community that depends on its bug bounty program.

Likely next: Google will likely introduce new submission filters or guidelines to handle AI-generated reports before resuming the program.

Google has frozen its open-source bug bounty program due to a 'significant rise' in AI submissions. The move indicates that AI-generated reports are flooding the program, likely making it difficult to triage legitimate vulnerabilities. This reflects a broader challenge for security teams as AI tools enable mass generation of low-quality or irrelevant submissions. The freeze is likely temporary, with Google expected to implement new filtering mechanisms before reopening the program.

What's next — scenarios

Base: Google reopens with AI filters (60%)

Google resumes the bug bounty program with automated screening to reject AI-generated submissions, restoring trust and efficiency.

Upside: Improved program quality (25%)

The freeze leads to a more robust program with better detection of genuine vulnerabilities, increasing payout efficiency.

Downside: Permanent reduction (15%)

Google keeps the program frozen indefinitely or significantly downgrades it, weakening open-source security incentives.

What to watch

Timeline

Analysis — what this means

Likely next events

Sectors affected

Key entities

Sources

Related cases

Browse the full archive →