Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions
Google's open-source bug bounty just hit pause. AI-generated submissions flooded the program, forcing a freeze.

Why it matters
AI-generated noise is degrading the signal in security disclosure workflows. This is a concrete operational friction point for security teams and bounty administrators — the volume and low quality of AI submissions is consuming triage resources faster than humans can filter them, forcing programs to shut down intake.
The key facts
10 to knowGoogle froze its open-source bug bounty program (date: October 4, 2026)
Reason cited: 'significant rise' in AI submissions
AI submissions characterized as 'slop' — low-quality, likely auto-generated reports
Impact: intake halted; administrators unable to triage at scale
Broader pattern: bug bounty programs overwhelmed by AI-generated noise
Google froze open-source bug bounty program intake
Reason: 'significant rise' in AI submissions
Problem: AI-generated low-quality or duplicate submissions overwhelming human review
Date: October 4, 2026
Broader pattern: AI tooling is automating submission/report generation faster than human teams can triage and validate
Go to the source
TechCrunch AItechcrunch.com
Publisher excerpt: AI slop seems to be overwhelming bug bounty programs.