‘This pause is due to a significant rise in automated submissions, the vast majority of which are not valid’: Google pauses open source bug bounty scheme over AI slop submissions

The Google open source scheme is the latest bug bounty to fall victim to AI-generated submissions

Google sign illuminated against a wall at night during the World Economic Forum (WEF) meeting in Davos, Switzerland.
(Image credit: Getty Images)

Google has revealed it will pause its open source bug bounty program, attributing the move to a “significant rise” in AI slop submissions.

In a statement on 1 October, posted both to X and the program brief, the tech giant revealed the pause will be enforced until at least the first quarter of 2027.

“As of October 1 2026, we are no longer accepting product vulnerabilities submitted to the OSS VRP,” the statement reads. “This pause is due to a significant rise in automated submissions, the vast majority of which are not valid.”

Google noted that it still might accept some reports covering product vulnerabilities through Cloud VRP. Similarly, the changes do not affect vulnerability reports submitted before 1 October.

Latest Videos FromIT Pro

“We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027. In the meantime, we encourage you to find impact across our other VRP programs and submit there instead, or pursue the Patch Rewards Program,” the company added.

AI slop submissions are a menace

The move by Google marks the latest in a series of efforts to clamp down on AI slop vulnerability reports in recent years. It’s an issue that has caused repeated issues across the open source community.

As ITPro reported in January this year, a bug bounty program run by Curl was shut down due to an onslaught of AI-generated contributions.

Daniel Stenberg, lead maintainer at the open source data transfer service, said teams were dealing with a torrent of submissions. Indeed, Curl recorded seven AI-generated contributions within just a sixteen hour period.

In an announcement at the time, Stenberg said this was placing a “high load” on security practitioners and the move aimed to “reduce the noise” created by AI-generated submissions.

The scale of AI slop reports across the open source community has reached such an extent that big tech companies have taken drastic action to tackle the issue.

In March, a consortium of companies pledged financial support for Alpha-Omega and the Open Source Security Foundation (OpenSSF), both of which are security initiatives within the Linux Foundation.

That consortium included several industry big-hitters such as Anthropic, Google, Microsoft, GitHub, OpenAI, and AWS. The $12.5 million funding package aims to develop sustainable security solutions and help eliminate slop reports.

At the time, AWS’ Mark Ryland said AI-generated reports were overwhelming open source maintainers and impacting broader security processes.

FOLLOW US ON SOCIAL MEDIA

Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.

You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.

Ross Kelly
News and Analysis Editor

Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.

He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.

For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.