{"version":1,"type":"story","url":"https://digestai.news/story/google-suspends-open-source-bug-bounty-over-ai-generated-submissions","json":"https://digestai.news/story/google-suspends-open-source-bug-bounty-over-ai-generated-submissions.json","markdown":"https://digestai.news/story/google-suspends-open-source-bug-bounty-over-ai-generated-submissions.md","slug":"google-suspends-open-source-bug-bounty-over-ai-generated-submissions","headline":"Google suspends open-source bug bounty over AI-generated submissions","summary":"Google paused its Open Source Software Vulnerability Reward Program (OSS VRP) on October 1 due to an overwhelming number of invalid AI-driven bug reports. The company cited thousands of low-effort, poorly written submissions—many hallucinated—that overwhelmed engineers and maintainers, diverting focus from real vulnerabilities. The suspension affects only product vulnerability reports, not supply chain submissions or Cloud VRP for Google Cloud repos, though the latter may still accept reports in some cases.\n\nThe issue reflects broader industry challenges: Linux maintainers reported being ‘completely overwhelmed’ by AI-generated CVEs, and Intel suspended its own bounty program (paying up to $100,000 per flaw) amid similar concerns. Google plans to reform the program and provide updates by Q1 2027. The move highlights how AI tools, while reducing manual effort, have flooded security programs with noise, forcing manual validation and delaying critical fixes.","keyPoints":["Google suspended OSS VRP on October 1 due to AI-generated, invalid bug reports overwhelming engineers","Thousands of low-effort submissions—many hallucinated—diverted focus from real vulnerabilities, per Google","Linux and Intel faced similar issues: Linux hit 2,000 vulnerabilities per release, Intel paused its bounty program"],"whyItMatters":"The suspension signals how AI-driven automation can flood security programs with noise, forcing teams to sift through false positives. It may prompt industry-wide reforms in bug bounty programs and highlight the need for better AI filtering in vulnerability reporting.","category":{"slug":"policy","name":"Policy & Regulation","url":"https://digestai.news/category/policy"},"entities":{"companies":["Google","Linux","Intel"],"models":[],"people":["Etiido Uko"]},"firstPublishedAt":"2026-10-03T12:00:00Z","updatedAt":"2026-10-03T12:00:00Z","sourceCount":1,"hasPrimarySource":false,"sources":[{"outlet":"Tom's Hardware","title":"Google freezes open-source bug bounty program amid flood of invalid AI slop submissions","url":"https://tomshardware.com/tech-industry/artificial-intelligence/google-suspends-part-of-the-oss-vrp-bug-bounty-program-due-to-an-influx-of-invalid-ai-submissions-product-vulnerability-submissions-ended-october-1","publishedAt":"2026-10-03T12:00:00Z","type":"press","primary":false,"lead":true}],"sourceNotes":null,"discussions":[],"thread":null,"cite":{"text":"Digest AI, \"Google suspends open-source bug bounty over AI-generated submissions\", 3 October 2026, https://digestai.news/story/google-suspends-open-source-bug-bounty-over-ai-generated-submissions","publisher":"Digest AI","title":"Google suspends open-source bug bounty over AI-generated submissions","datePublished":"2026-10-03T12:00:00Z","url":"https://digestai.news/story/google-suspends-open-source-bug-bounty-over-ai-generated-submissions"},"generatedBy":"Written by Digest AI's editorial model from the linked sources; the sources are the record.","license":"Headlines, digests and key points are written by Digest AI and may be quoted with a link to the story page. Linked articles belong to their publishers. Terms: https://digestai.news/terms#reuse"}