‘This pause is due to a significant rise in automated submissions, the vast majority of which are not valid’: Google pauses open source bug bounty scheme over AI slop submissions
The Google open source scheme is the latest bug bounty to fall victim to AI-generated submissions
Google has revealed it will pause its open source bug bounty program, attributing the move to a “significant rise” in AI slop submissions.
In a statement on 1 October, posted both to X and the program brief, the tech giant revealed the pause will be enforced until at least the first quarter of 2027.
“As of October 1 2026, we are no longer accepting product vulnerabilities submitted to the OSS VRP,” the statement reads. “This pause is due to a significant rise in automated submissions, the vast majority of which are not valid.”
Google noted that it still might accept some reports covering product vulnerabilities through Cloud VRP. Similarly, the changes do not affect vulnerability reports submitted before 1 October.
“We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027. In the meantime, we encourage you to find impact across our other VRP programs and submit there instead, or pursue the Patch Rewards Program,” the company added.
AI slop submissions are a menace
The move by Google marks the latest in a series of efforts to clamp down on AI slop vulnerability reports in recent years. It’s an issue that has caused repeated issues across the open source community.
As ITPro reported in January this year, a bug bounty program run by Curl was shut down due to an onslaught of AI-generated contributions.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
Daniel Stenberg, lead maintainer at the open source data transfer service, said teams were dealing with a torrent of submissions. Indeed, Curl recorded seven AI-generated contributions within just a sixteen hour period.
In an announcement at the time, Stenberg said this was placing a “high load” on security practitioners and the move aimed to “reduce the noise” created by AI-generated submissions.
The scale of AI slop reports across the open source community has reached such an extent that big tech companies have taken drastic action to tackle the issue.
In March, a consortium of companies pledged financial support for Alpha-Omega and the Open Source Security Foundation (OpenSSF), both of which are security initiatives within the Linux Foundation.
That consortium included several industry big-hitters such as Anthropic, Google, Microsoft, GitHub, OpenAI, and AWS. The $12.5 million funding package aims to develop sustainable security solutions and help eliminate slop reports.
At the time, AWS’ Mark Ryland said AI-generated reports were overwhelming open source maintainers and impacting broader security processes.
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.
He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.
For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.
-
AWS CEO Matt Garman defends data center build-outs amid growing pushbackNews Garman claims that hostile nations are attempting to influence the narrative
-
Asus ProArt PA278QGV reviewReviews Color-accurate performance for creative desks without the high price – the Asus ProArt PA278QGV is an example of cost-cutting done right
-
Huawei reiterates its commitment to open source standards at Connect 2026News The Chinese IT giant is the latest to declare open source a key element of AI
-
Red Hat launches new open source project to drive AI governanceNews The asago open source project will allow enterprises to automate compliance processes and bolster security
-
Amazon targets agent safety gains with investment in team behind Lean programming languageNews The tech giant hopes support for the open source programming language could drive AI agent safety improvements
-
‘These Chinese models are excellent’: Nvidia CEO Jensen Huang hails powerful new Chinese AI models like Kimi K3 – and says don’t be put off by security ‘misconceptions’News As powerful new AI models like Kimi K3 hit the market, Huang says competition will be a positive for the global industry
-
Apple is speeding up software patching due to AI security concerns – here’s what you need to knowNews Apple is speeding up its software patching processes amid rising concerns that AI is helping hackers to spot and exploit flaws at a far quicker pace.
-
The UK is betting big on the power of open source AINews The government wants to encourage open source developers to help improve public services
-
‘Open source should rest on transparency, not deception’: Euro-Office ‘sovereignty’ claims questioned in scathing open letter by LibreOffice maintainersNews The developers behind LibreOffice have questioned Euro-Office’s sovereignty credentials and use of a Microsoft-based document format
-
AI is coming to Ubuntu: Canonical exec teases future AI features and agentic workflow capabilities for version 26.10 — but on a ‘strictly opt-in basis’News A range of new AI features are coming to Ubuntu over the next year, according to maintainers, but only providing they’re of “sufficient maturity and quality”.