Google Pauses Open Source Bug Bounty Over Flood of AI-Generated Reports

Google has temporarily stopped its program that paid researchers for spotting security issues in open source code.
The pause started on October 1 and is set to last until at least early 2027.
AI Tools Flood Security Programs
Many reports now come from automated systems that produce invalid or made-up details.
This pattern follows earlier warnings that AI can generate low-quality security claims at scale.
Founders who rely on open source libraries may face slower vulnerability fixes in the short term.
Other Google bug bounty programs remain open for participants to use instead.
Long-Term Shifts for Developers and Companies
Over the next twelve months, similar programs could add AI filters to handle volume without full pauses.
Companies with strong internal security teams may gain an edge while public programs adjust.
Historical growth in bug bounties shows they adapt to new technologies like automation over time.
Startups building on open source should monitor multiple reward channels to stay protected.
Valid human researchers could see higher average payouts once invalid entries are reduced.









