Google is adding a new dimension to software security with its latest move in AI. The company announced CodeMender, an AI tool that can automatically detect and fix security vulnerabilities in code. The system, which aims to help developers respond to faulty code more quickly, was developed based on Google’s experience from the BigSleep and OSS-Fuzz projects.
Up to $20,000 in Rewards
According to Google, CodeMender thoroughly examines the vulnerabilities it detects using its Gemini-based analysis system and identifies the source of the problem. It then creates an appropriate fix. This patch is first reviewed by review agents and then submitted to human developers for approval. This process involves a multi-layered verification process for security and correctness.
With the launch of CodeMender, Google also announced a special “Vulnerability Bounty Program” for AI-based projects. Under this program, rewards of up to $20,000 will be offered for discovered critical vulnerabilities. The company aims to encourage developers to participate more actively in security research.
Google has also updated its Secure AI Framework (SAIF) platform to version 2.0. The new version comes with three key innovations: a threat mapping tool, enhanced security updates, and the ability to share risk data with the Coalition for Secure AI Risk Map community.
A Big Goal with CodeMender
Google defines the primary goal of its new initiatives as making the digital ecosystem more secure. According to the company, AI will not only accelerate software development processes but also provide a strong line of defense against malicious cyberattacks.
At the heart of this vision, CodeMender aims to reshape the future of cybersecurity. The system not only addresses existing vulnerabilities but also updates itself against new types of threats thanks to its continuous learning capability. Google emphasizes that this technology has ushered in a new era in which AI assumes a “defensive” role.
The company also plans to integrate CodeMender into both open source communities and enterprise developers in the long term, making it the standard for automated security management. Thus, Google aims to create a new paradigm in AI-powered security solutions on a global scale.

