Summary
- Google stopped accepting new OSS VRP product vulnerability reports from 1 October.
- The company says a significant rise in automated submissions has produced a large volume of invalid reports.
- Existing submissions and supply chain reports remain open while Google reworks the programme.
Google has stopped accepting new product vulnerability reports through its Open Source Software Vulnerability Reward Program after automated submissions created a volume of invalid reports that the company says has become unsustainable.
The change took effect on 1 October and applies specifically to product vulnerabilities submitted through the Google Bug Hunters OSS VRP. Existing submissions remain in scope, while supply chain reports continue to be accepted.
Google said the pause follows a significant rise in automated submissions, the vast majority of which are not valid. The company plans to rework this part of the programme rather than closing the wider open source bounty permanently.
The decision follows earlier changes made during 2026 after Google reported a large increase in submissions generated or heavily assisted by artificial intelligence. Many lacked demonstrable security impact, described unreachable conditions or presented plausible sounding findings that did not survive technical validation.
AI itself is not excluded from the research process. Google’s earlier rules instead increased the emphasis on evidence, requiring researchers to verify that a reported weakness is reachable and produces a meaningful security consequence before handing the work to maintainers.
Automated discovery creates a difficult imbalance because generating a possible vulnerability can be cheap while proving whether it is real remains expensive. A model can identify hundreds of suspicious code patterns quickly, but engineers may have to inspect each one individually to distinguish an exploitable flaw from an ordinary bug or false positive.
When submissions carry a financial reward, that imbalance also creates an incentive to send large numbers of low-confidence findings in the hope that a small fraction qualify. The verification cost then falls on the programme operator and the open source maintainers whose time is required to reproduce the report.
Open source projects can be particularly sensitive to that pressure because many depend on small teams or volunteer maintainers. A sustained stream of speculative security reports competes directly with fixing confirmed bugs, reviewing code and maintaining the software itself.
The problem is distinct from the increasingly capable use of AI in genuine vulnerability research. Advanced models can inspect source code, trace program behaviour and help experienced researchers develop proofs of concept, and vendors are themselves using AI to identify security flaws.
Quality therefore depends less on whether AI contributed to the work than on whether the researcher has validated the result. A reproducible vulnerability with demonstrated impact remains useful regardless of the tools used to find it, while a large volume of unverified output can reduce the effectiveness of the reporting system.
Google has left its supply chain category open during the pause, reflecting the different consequences of weaknesses that can affect source repositories, package distribution or build integrity across downstream users.
The company is also continuing to process product vulnerability reports submitted before the 1 October cutoff. That prevents researchers with existing cases from losing eligibility simply because the programme rules changed after their work was submitted.
Bug bounty programmes have traditionally used recognition and financial incentives to bring vulnerabilities to vendors privately before public disclosure. If automated reporting increases the operating cost faster than the volume of genuine findings, more programmes may respond with stronger evidence requirements or narrower submission scopes.
Google’s pause provides an early example of that adjustment. AI is increasing the rate at which candidate flaws can be generated, but triage systems and human review capacity do not scale automatically at the same speed.
The company has said it will continue restructuring this part of the OSS VRP and provide a further update in the first quarter of 2027. Until then, new product vulnerability submissions are closed while other parts of the programme remain active.





