# Google pauses open-source bug bounty program after AI spam

> Google stopped accepting product vulnerability reports in its open‑source reward program on Oct. 1 because of a flood of invalid AI‑generated submissions.

Oossa · 2026-10-03 · https://oossa.com/en/google-pauses-open-source-bug-bounty-program-after-ai-spam

Google announced on Oct. 1 that it is suspending product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP). The pause is temporary and will stay in place while the company deals with a surge of invalid reports that were generated by artificial‑intelligence tools. Google said participants can still submit bugs to other VRP programs and promised an update on the situation by the first quarter of 2027.

## What triggered the suspension?

The company noticed a large number of submissions that appeared to be automatically created by AI and did not contain valid security findings. These low‑quality reports clogged the review process and made it harder for engineers to focus on real bugs. To protect the program’s effectiveness, Google chose to halt new product submissions until it can redesign the intake workflow.

## The facts

- Google suspended product vulnerability submissions on Oct. 1, 2026.
- The suspension applies to the Open Source Software Vulnerability Reward Program (OSS VRP).
- Google asked reporters to use other VRP programs while the pause lasts.
- The company will provide an update by Q1 2027.

## Why it matters

For security researchers, the pause means they must submit open‑source bugs through other reward programs for now, which could slow down payouts for valid findings. For developers, the short‑term gap may reduce the number of quick fixes for open‑source components they rely on. Google has not said how long the suspension will last beyond the promised 2027 update.

## Sources & references

1. [Google freezes open-source bug bounty program amid flood of invalid AI slop submissions](https://www.tomshardware.com/tech-industry/artificial-intelligence/google-suspends-part-of-the-oss-vrp-bug-bounty-program-due-to-an-influx-of-invalid-ai-submissions-product-vulnerability-submissions-ended-october-1) – Tom's Hardware, 2026-10-03

Last updated: 2026-10-03
