Google freezes open source bug bounty programme following surge in AI-generated reports
Google is reported to have frozen one of its ‘bug bounty’ or vulnerability tracking programmes as a result of an explosion in bug bounty reports submitted by artificial intelligence (AI).
The suspension of the programme will remain in effect until next year and specifically impacts Google’s open-source bug bounty programme.
As reported by TechCrunch on Sunday (4/10) local time, cybersecurity experts warned last year that ‘AI slop’—carelessly developed AI—could become a serious issue for bug bounty programmes.
While researchers are typically rewarded for successfully identifying vulnerabilities in Google’s open-source software, it appears that, in this instance, such rewards cannot be processed.
In posts on X and the relevant programme website, Google stated that its open-source bug bounty programme has been temporarily halted starting from 1 October 2026.
According to another report from Tom’s Hardware, the decision was made because Google engineers and open-source maintainers are overwhelmed by the task of verifying invalid reports or those containing AI-generated hallucinations.
“This hiatus is caused by a significant increase in automated submissions, most of which are invalid,” Google stated.
Although Google’s open-source bug bounty programme is temporarily frozen, Google has requested that application developers consider other available bug bounty programmes offered by the company.