Google has temporarily paused its Open Source Software Vulnerability Rewards Program after reporting a substantial increase in automated submissions, most of which did not meet validation standards.
The initiative rewards independent researchers who identify security issues in Google's open-source software. However, the growing volume of AI-generated reports has created an additional review burden for Google engineers and open-source maintainers.
Focus on high-quality security research
According to Google, many recent submissions contained inaccurate findings or AI-generated technical claims that could not be verified. The pause, effective from October 1, is designed to help the company reassess how the program can continue supporting meaningful vulnerability research efficiently.
Google expects to share an update during the first quarter of 2027. In the meantime, security researchers can still participate in the company's other bug bounty initiatives.
The decision highlights a growing challenge for the technology sector: as generative AI accelerates the creation of technical content, verification systems must evolve to protect the value of expert human research. Future security programs may increasingly combine automated screening with stronger quality controls.