On October 1, Google paused its Open Source Software Vulnerability Reward Program (OSS VRP) due to a large increase in automated bug reports generated by AI, according to medianama.com. The company will continue processing reports submitted before October 1 and will still accept supply-chain related reports. Google plans to provide an update on the program in the first quarter of 2027.
The pause follows a similar adjustment in March 2026 when Google tightened rules to combat a rise in AI-generated submissions that contained hallucinated vulnerabilities or bugs with minimal security impact. These changes included stricter evidence requirements, such as reproductions through OSS-fuzz or merged patches. In April, Google also revised its Chrome and Android bug bounty programs and removed bonuses introduced in 2025 to manage the volume of automated reports.
The influx of AI-generated bug reports has increased the verification workload for Google’s engineers, challenging the traditional model of rewarding external researchers for uncovering overlooked security flaws. This trend has affected other projects as well; for example, the curl project ended its bug bounty program in January 2026 due to similar issues caused by automated submissions. The rise of AI tools has thus disrupted the bug bounty landscape across multiple open-source initiatives.
Google’s decision to pause the OSS VRP reflects the broader challenge of balancing AI-generated vulnerability reports with effective security verification. The company’s next update on the program is scheduled for the first quarter of 2027, when it may outline new strategies to handle AI-driven submissions.