Google has officially suspended its Open Source Software Vulnerability Rewards Program (OSS VRP), citing a massive, unsustainable surge in automated, low-quality submissions driven by artificial intelligence. The move, which took effect on October 1, marks a significant turning point in the industry-wide struggle to balance the benefits of crowdsourced security research against the modern reality of AI-assisted spam. The company, which has long been a proponent of open-source security through its collaborative bounty initiatives, has indicated that the program will remain offline until at least the first quarter of 2027, when it intends to provide an update on the initiative’s future.
The decision arrives as the latest chapter in a growing conflict between software maintainers and a new wave of automated reporting tools. For years, bug bounty programs have served as the backbone of modern cybersecurity, allowing tech giants like Google to leverage the collective expertise of thousands of independent researchers. By incentivizing the discovery and responsible disclosure of vulnerabilities, these programs have effectively patched millions of lines of code before malicious actors could exploit them. However, as generative AI tools have become more sophisticated and more accessible, the barriers to entry for participation in these programs have effectively collapsed, leading to a deluge of content that engineers are struggling to process.
In official communications posted both on the platform X and on the program’s dedicated website, Google attributed the indefinite pause to a “significant rise” in automated submissions. The company noted that the vast majority of these reports are not valid, placing an undue burden on the security teams and open-source maintainers responsible for vetting them. According to reports from industry outlets such as Tom’s Hardware, the situation had reached a breaking point, with Google’s internal teams becoming overwhelmed by a flood of reports that were either functionally invalid or contained complex, convincing hallucinations—a hallmark of generative AI models attempting to perform technical analysis without true contextual understanding.
This development is not entirely unexpected. Last year, cybersecurity experts began raising alarms that the rise of "AI slop"—a term used to describe the low-quality, automated, or hallucinated output generated by LLMs—posed a genuine existential threat to the integrity of established bug bounty ecosystems. Security researchers warned that if automated tools were used to generate thousands of "potential" vulnerabilities, it would create a signal-to-noise ratio problem so severe that it would drown out the high-quality, manual research provided by skilled human professionals.
The core issue lies in the nature of modern vulnerability research. Traditionally, finding a security flaw requires deep technical knowledge, a rigorous understanding of the codebase, and the ability to reproduce a potential exploit. Human researchers are adept at nuance, identifying patterns that automated scanners miss, and understanding the real-world impact of a vulnerability. In contrast, AI models—while excellent at processing large datasets—often lack the capacity to determine whether a "vulnerability" they have identified is actually exploitable in a production environment or if it is merely a theoretical issue that poses no risk. When these models are used to churn out reports at scale, they produce a massive volume of "false positives" that human maintainers must then manually investigate to confirm their lack of merit.
For Google’s OSS VRP, this process of manual verification has become a resource drain. Every submission, regardless of its quality, requires a human touch to ensure that genuine security threats are not ignored. When thousands of automated, hallucinated reports are funneled into the review pipeline, the time and effort required to filter them out can effectively paralyze the entire operation. By pausing the program, Google is effectively hitting a reset button to evaluate how it can better verify submissions and filter out the noise before re-engaging with the broader security community.
The pause specifically targets the open-source branch of Google’s rewards structure. It is important to note that this does not mean Google is abandoning its commitment to security or ending its relationship with the research community entirely. The company continues to encourage participants to explore its other active bug bounty programs. These alternatives often involve more specific, product-based vulnerability rewards where the scope is tightly defined, which may make them more resistant to the broad-brush automated scanning that has plagued the open-source program. However, the suspension of the OSS VRP serves as a stark reminder that the open-source ecosystem, which is inherently decentralized and relies heavily on community goodwill, may be uniquely vulnerable to these new automated threats.
The timeline for the return of the program—early 2027—suggests that Google recognizes this is not a problem that can be solved overnight. Addressing the flood of AI-generated noise likely requires more than just a temporary fix; it may involve fundamental changes to how the program handles submissions, such as implementing more stringent verification requirements, utilizing more advanced AI-filtering tools to combat AI-generated spam, or restructuring the reward tiers to prioritize proven expertise over raw submission volume.
For the cybersecurity community, the pause is a sobering reflection of the "arms race" that has emerged alongside the rise of artificial intelligence. While AI has the potential to help developers write more secure code, it has also lowered the barrier for those who wish to clutter security pipelines with junk data. Whether this is done by malicious actors seeking to disrupt operations or by well-meaning but ill-informed individuals relying too heavily on automated tools, the result is the same: a degradation of trust and efficiency in a system designed to protect the global digital infrastructure.
As the industry looks toward 2027, the success of Google’s rebooted program will likely depend on its ability to distinguish between legitimate, high-quality research and the growing tide of automated, hallucinated output. If Google can successfully implement a framework that restores the value of the human researcher, it may provide a blueprint for other companies facing similar pressures. If not, the industry may be forced to reckon with a future where the "bug bounty" model is fundamentally altered, perhaps moving toward more invite-only structures or requiring higher levels of verification before a submission is even considered.
For now, the security community must adjust to the temporary absence of one of the most prominent open-source rewards programs in the world. While the pause is a frustration for those who contribute meaningful research, it is an essential step for a company that must prioritize the integrity of its code and the sanity of its maintainers. As Google prepares for the next phase of its program, the focus will undoubtedly be on finding a sustainable balance between the speed of innovation and the necessity of rigorous, human-verified security. The era of unchecked, automated bug reporting is clearly coming to an end, and in its place, the industry is searching for a new model that respects the work of human experts while navigating the complexities of an AI-driven world. Until the OSS VRP returns, the security of the broader open-source ecosystem will depend on the vigilance of maintainers and the continued commitment of ethical researchers to produce high-quality, meaningful work that helps keep the software landscape secure.

