Google pauses open source bug bounty scheme over AI slop submissions
Google's open source bug bounty is paused. The reason: AI slop. What happens when automation floods the channels meant to find real exploits?

Why it matters
Google has paused its open source bug bounty program due to a surge in AI-generated submissions that are mostly invalid. This is a narrow operational story about a single vendor's program friction — not a systemic shift in how security work or autonomous systems operate — but it illustrates an emerging workplace friction: automated tools degrading human-facing processes.
The key facts
9 to knowGoogle paused the open source bug bounty scheme
Cause: significant rise in automated (AI-generated) submissions
Vast majority of automated submissions are not valid
This is the latest bug bounty program affected by AI submissions
Date: October 2026
Google paused open source bug bounty scheme due to surge in automated submissions
Vast majority of AI-generated submissions reported as invalid
Incident reflects broader trend of AI-generated spam in bug bounty and security communities
Operational cost: engineering resources spent triaging invalid reports rather than addressing real vulnerabilities
The story so far
Earlier coverage of this storyline
Go to the source
ITProitpro.com
Publisher excerpt: The Google open source scheme is the latest bug bounty to fall victim to AI-generated submissions