Companies like Google and Microsoft are find much bigger numbers of vulnerabilities in their own products as a result of AI. But the same technology is leading to public reporting programs becoming overwhelmed by the mass submission of speculative, duplicated, or hallucinated findings.
Now, Google’s announced it has temporarily stopped accepting submissions to its open source bug bounty program, OSS VRP.
“Why is this happening? This pause is due to a significant rise in automated submissions, the vast majority of which are not valid.”
We’ve seen this happen before. In early 2026, curl ended its HackerOne bounty program after low-quality, often AI-generated submissions overwhelmed its small security team.
Intel also launched a new bug bounty program on Intigriti but there are no longer bounties available, reportedly in order to stop a flood of AI generated reports.
Pros and cons
Bounties can be an incentive for mass-submitting behavior when generative AI lowers the cost of producing polished-looking submissions. So, it’s understandable that companies want to limit the number of incoming reports.
If most automated submissions are invalid, a temporary pause prevents Google engineers and open-source maintainers from spending disproportionate time disproving reports rather than fixing real issues.
A pause gives Google the time and chance to introduce better controls, such as mandatory proof-of-concept requirements, evidence thresholds, and rate limits without letting the current queue keep growing.
On the other hand, it may discourage legitimate researchers and make it harder for them to submit actual issues they’ve found.
It is hard to draw a line of what you will accept, because an AI-assisted report can be valid, just like a low-quality report is not necessarily AI-generated.
And as companies like Google and Microsoft have proven, AI assisted vulnerability discovery can also support real vulnerability discovery if it is coupled with validation, deduplication, and proof.
What about the future?
If we have learned anything it is that AI is not “breaking” vulnerability disclosure. It is exposing an older weakness in disclosure economics: the cost of filing a plausible report has fallen sharply, while the cost of proving or disproving it remains human-intensive.
The solution seems obvious. Let AI handle the submissions and only hand over those it can validate to the engineering teams. This will definitely frustrate some bug bounty hunters, because it will be like convincing a chatbot that you have a valid point and want to “talk to a human,” but hopefully it will bring down the number of less serious bug bounty hunters and create more room for those who know what they are doing.
Google has only promised an update in Q1 2027, so any redesign details would be speculative, but we do hope they find a way for responsible bug hunters to submit their findings.
From reporting threats to removing them.
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.




