WorkThe story, in brief

Google pauses open source bug bounty scheme over AI slop submissions

Google's open source bug bounty is paused. The reason: AI slop. What happens when automation floods the channels meant to find real exploits?

Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
People, judgement and the changing nature of work.AI illustration by KeyNews
The KeyNews take

Why it matters

Google has paused its open source bug bounty program due to a surge in AI-generated submissions that are mostly invalid. This is a narrow operational story about a single vendor's program friction — not a systemic shift in how security work or autonomous systems operate — but it illustrates an emerging workplace friction: automated tools degrading human-facing processes.

The key facts

9 to know
  1. Google paused the open source bug bounty scheme

  2. Cause: significant rise in automated (AI-generated) submissions

  3. Vast majority of automated submissions are not valid

  4. This is the latest bug bounty program affected by AI submissions

  5. Date: October 2026

  6. Google paused open source bug bounty scheme due to surge in automated submissions

  7. Vast majority of AI-generated submissions reported as invalid

  8. Incident reflects broader trend of AI-generated spam in bug bounty and security communities

  9. Operational cost: engineering resources spent triaging invalid reports rather than addressing real vulnerabilities

The story so far

Earlier coverage of this storyline

  1. Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissionsTechCrunch AI
  2. This story

Go to the source

ITProitpro.com

Publisher excerpt: The Google open source scheme is the latest bug bounty to fall victim to AI-generated submissions
Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work