GOOGLE has paused submissions to its open source bug bounty programme, the OSS VRP, after a surge in AI-assisted and other automated reports that are largely invalid. The company says the pause is intended to curb the flood of speculative, duplicated, or hallucinated findings and to prevent engineers and open‑source maintainers from spending disproportionate time debunking reports rather than fixing real issues.
The move follows a similar pattern seen earlier in 2026, when curl ended its HackerOne bounty programme and Intel’s bug bounty programme reportedly halted further bounties to stop AI-generated submissions.
The article notes that while bounties can incentivise mass submissions in the AI era, a temporary pause enables better controls, such as mandatory proof-of-concept, evidence thresholds, and rate limiting, without letting the current queue swell further. However, there is a tension: legitimate researchers may be discouraged, and distinguishing valid AI-assisted reports from low‑quality ones remains challenging.
The piece suggests that AI could aid vulnerability discovery if paired with proper validation, deduplication, and reviewer processes. Google has said it will provide an update in Q1 2027, though details of any redesign are not yet known. The piece frames the situation as a reaction to evolving disclosure economics, where the cost to file a plausible report has dropped while proving or disproving it remains human-intensive.