Google has officially paused its open-source bug bounty initiative after experiencing a massive surge in AI-generated vulnerability reports. The tech giant made the decision to temporarily freeze the program to evaluate its review workflow following a steep rise in low-quality submissions that threatened to overwhelm internal triage staff.
Crowdsourced security programs rely on independent security researchers to discover and responsibly disclose genuine software vulnerabilities in exchange for monetary rewards. However, the widespread availability of generative artificial intelligence tools has drastically altered this dynamic. Security review teams now face a flood of synthetic submissions, often characterized as AI slop, produced by individuals using automated systems to generate bulk reports without manual verification.
These automated submissions frequently suffer from severe accuracy and quality issues. AI-generated reports routinely present hallucinated security vulnerabilities, misinterpret normal software behaviors as critical defects, or present standard code structures as exploitable flaws. Despite the lack of substance in these synthetic submissions, security engineers are still obligated to spend time reviewing, cataloging, and officially closing each ticket to ensure authentic threats are not missed.
The massive increase in these low-effort submissions creates an unsustainable administrative bottleneck for platform maintainers and security auditors. By putting its open-source initiative on hold, Google is taking steps to alleviate reviewer fatigue and protect the efficiency of its security evaluation pipeline.
What it means
The suspension of Google's program highlights how artificial intelligence is disrupting established vulnerability disclosure frameworks. As automated tools make it trivial to produce high volumes of plausible yet inaccurate reports, bug bounty initiatives face severe operational friction. Organizations managing crowd-sourced security programs will likely need to implement stricter intake filters and verification controls to prevent synthetic noise from obscuring critical security vulnerabilities.




