Google Pauses OSS VRP Due to AI-Generated Spam Reports

Google has officially announced the suspension of its Open Source Software Vulnerability Reward Program (OSS VRP) following a significant surge in low-quality reports generated by artificial intelligence tools. As of October 1, the tech giant confirmed that the program, which incentivizes security researchers to identify vulnerabilities in open-source projects, will be placed on hold indefinitely. The decision stems from an overwhelming volume of inaccurate submissions—often referred to as hallucinations—that have clogged the review pipeline and hindered the ability of security teams to address genuine threats. Google noted that the system has become unsustainable under the current influx of automated, non-authentic vulnerability disclosures.
- Google has suspended its OSS VRP program to address the high volume of AI-generated junk reports.
- Inaccurate submissions are currently preventing security experts from identifying and patching real vulnerabilities.
- The company has initiated a long-term restructuring process that is expected to last until 2027.
- Researchers remain encouraged to participate in Google’s other active Vulnerability Reward Programs.

The Integrity of the Program is Being Compromised
The primary motivation behind this drastic measure is the operational strain caused by AI-driven automation. While artificial intelligence can be a powerful tool for security analysis, its misuse has resulted in a flood of false-positive reports. These AI-generated submissions lack the technical precision required for legitimate vulnerability assessment, forcing Google’s review teams to waste valuable resources sifting through noise. By suspending the program, the company aims to protect the integrity of its security research ecosystem and ensure that human expertise is focused on actual security risks rather than managing automated spam.
A Comprehensive Restructuring is Being Planned
Looking ahead, Google has committed to a multi-year effort to overhaul its reporting mechanisms. The company intends to integrate more robust validation processes that can effectively distinguish between human-verified security research and AI-generated noise. While the OSS VRP remains inactive, Google has advised researchers to divert their efforts toward other existing VRP programs that remain operational. The current timeline for this restructuring project extends into the first quarter of 2027, at which point the company expects to unveil a more resilient and efficient framework for managing open-source security submissions.
The Future of Bug Bounties is Being Debated
The decision by Google highlights a growing concern within the global cybersecurity community regarding the impact of generative AI on professional reward programs. As automation becomes more accessible, the barrier to entry for submitting reports has lowered, leading to unintended consequences for platforms that rely on high-quality input. Industry experts are now closely watching how major corporations adapt their defense mechanisms to maintain the viability of bug bounty programs. This pause is widely viewed as a necessary step to safeguard the long-term health of collaborative security efforts across the software industry. By addressing these systemic weaknesses now, Google hopes to create a more sustainable environment where genuine discoveries are rewarded appropriately and efficiently.
Given the rapid rise of AI in automated reporting, we are curious about your perspective on this shift. Do you believe that other major technology companies will soon follow Google’s lead by suspending their own bounty programs, or can these platforms successfully implement AI-resistant filters? Share your thoughts in the comments section below.
Your comment has been submitted,
it will be published after approval.