Google has paused its Open Source Software Vulnerability Rewards Program after a flood of automated vulnerability reports, most of them invalid. The pause took effect on October 1, with the company promising an update in the first quarter of 2027. The move matters because it shows how AI-generated reporting can clog a security process faster than teams can review it.
Why Google halted open source payouts
Google disclosed the decision in posts on X and on the program website, linking the pause directly to volume and quality of incoming reports. The company described a significant rise in automated submissions, adding that the vast majority were not valid. The program had paid researchers for finding vulnerabilities in Google open source software, so the freeze stops new rewards in that channel for more than a year. Participants were directed to Google other bug bounty programs in the meantime.
The failure mode described is not a shortage of reports but a shortage of usable ones. According to Tom's Hardware, Google engineers and open source maintainers were overwhelmed by reports that were invalid or contained hallucinations. That pattern means triage time is spent disproving findings rather than fixing code. For a program built around researcher rewards, the cost shifts from payouts for real bugs to labor spent filtering noise.
The warning preceded the decision by about a year. Last year TechCrunch reported that cybersecurity experts cautioned that AI slop posed a serious risk to bug bounty programs. The concern was that low-cost generation would let submitters mass-produce plausible-looking reports without verification. Google experience now provides a concrete case: an open source program with public scope and clear reward rules became an easy target for automation at scale.
What the pause means for security operations
For companies that run their own intake of external findings, the lesson is about review capacity and acceptance criteria. A small business that receives a handful of reports can still check each one manually, while a large organization with popular open source projects faces hundreds of similar-looking submissions. The practical response is stricter report templates, reproduction requirements, and proof-of-concept thresholds before a report reaches engineers. Without those filters, maintainers become full-time reviewers of machine output.
The limits of this case also need careful reading. Google did not say that AI cannot find real vulnerabilities, only that automated submissions to this program were largely invalid. The pause applies to open source software rewards, not to Google other bug bounty programs, which remain open. Buyers and security managers should therefore ask vendors how they separate automated bulk reports from validated findings, what evidence is required, and how hallucinated details are detected during triage.
Whether the model returns will be visible in the first quarter of 2027, when Google promised an update on the program. A relaunch with new submission rules, validation tooling, or changed reward terms would signal that filtering has caught up with generation. If the date passes without changes, other open source programs are likely to keep tightening their own intake first.
