AI Security2026-10-05
TechCrunch AI
Google Freezes Bug Bounty Over AI Submissions
Google has temporarily frozen its open source bug bounty program after a sharp increase in AI-generated submissions. The company said the flood of reports, many of them low quality or automatically produced, overwhelmed reviewers and made it harder to find genuine vulnerabilities. Bug bounty programs depend on trust and triage. Researchers submit findings, maintainers verify them, and rewards go to people who do real security work. When generative AI makes it cheap to produce plausible-looking reports at scale, that process can break down. Reviewers may spend hours chasing false positives while legitimate flaws sit in the queue. Google's decision illustrates a broader challenge for open source security. AI tools can help researchers find bugs faster, but they can also generate noise, duplicate findings, and speculative claims that lack evidence. For under-resourced open source projects, even a modest wave of automated reports can be exhausting. The freeze is temporary, but it raises difficult questions about how bug bounties should adapt. Programs may need stronger submission requirements, such as proof-of-concept code, reproducible steps, and clear impact statements. They may also use AI-assisted triage to filter low-effort reports, though that creates its own risks if automated filters miss real issues or unfairly reject valid work. There is also a question of responsibility. If AI is used in vulnerability research, who ensures the output is accurate and useful rather than merely voluminous? The incident does not mean AI has no place in security research. Used carefully, it can help spot patterns and accelerate analysis. But scale without verification can harm the very communities that maintain critical software. Google's pause is a warning that security workflows need to evolve alongside generative AI. The goal should be to preserve the value of bug bounties while reducing the burden of automated noise. Otherwise, more programs may conclude that the costs of open submissions outweigh the benefits.