Google Pauses Bug Bounties as AI Slop Floods Security

AI was supposed to help security researchers find more vulnerabilities. Google just paused part of a bug bounty program because AI was helping people report too many vulnerabilities that were not real.
Google has temporarily stopped accepting product-vulnerability submissions through its Open Source Software Vulnerability Rewards Program, citing what it called a significant rise in automated submissions.
The company said the vast majority of those reports were invalid.
The pause took effect October 1, with Google planning to provide another update in the first quarter of 2027.
It is an unusually concrete example of a problem appearing across knowledge work:
AI makes producing an answer cheaper.
It does not automatically make verifying that answer cheaper.
Bug bounty programs depend on signal
A bug bounty is a marketplace for security information.
A researcher discovers a vulnerability.
They document it.
The company verifies the problem.
If the finding is legitimate and important enough, the researcher gets paid.
That system only works when companies can efficiently separate real vulnerabilities from noise.
AI disrupts that balance.
Someone can now ask a model to review code, generate a vulnerability hypothesis and automatically create a convincing-looking report.
Producing the report takes minutes.
Validating it can still require an experienced security engineer.
Google had already warned about this
The company had been changing its rules before the latest pause.
In March, Google's bug-bounty team said it had seen a major surge in low-quality and invalid AI-generated submissions.
Some reports described vulnerabilities that could not actually be triggered.
Others identified coding mistakes that had little or no meaningful security impact.
Google responded by requiring stronger evidence for certain classes of reports, including reproducible results or actual merged security patches.
Apparently, that was not enough.
AI creates an asymmetry between generation and verification
This is the same economic problem affecting many AI-heavy workflows.
Generate 1,000 reports?
Easy.
Carefully verify 1,000 reports?
Expensive.
A model can produce text almost instantly.
An engineer may need to:
read the code,
reproduce the bug,
understand the security model,
test whether the affected path is reachable,
and determine whether exploitation is realistic.
That can take hours.
The attacker — or low-quality bug hunter — spends seconds.
The defender spends human time.
“AI slop” becomes a cybersecurity issue
The phrase “AI slop” is usually associated with low-quality social-media posts, fake news or automatically generated web pages.
Bug bounty programs show how the same phenomenon becomes operationally expensive.
A hallucinated vulnerability is not merely annoying.
It consumes scarce security-engineering capacity.
Enough fake reports can function almost like administrative denial of service.
Maintainers become overwhelmed.
Important legitimate disclosures risk being buried.
That creates a perverse outcome.
A tool designed to make security research easier can make vulnerability coordination less effective.
AI security research still has enormous value
None of this means AI is bad at cybersecurity.
Google explicitly acknowledged earlier this year that AI can be useful for discovering potential vulnerabilities.
The problem is validation.
A researcher who uses AI to find a vulnerability and then carefully reproduces the issue can provide real value.
A researcher who forwards the model's first answer without checking it creates work for everyone else.
That difference may shape the next generation of bug bounty rules.
Proof may matter more than prose
Traditional vulnerability reports contain detailed written explanations.
AI can now generate impressive explanations cheaply.
That means security programs increasingly need evidence that is harder to fake.
A working exploit.
A reproducible test case.
A fuzzing result.
A merged patch.
Clear proof of real-world impact.
Google's updated rules had already moved in this direction before the temporary pause.
The future bug bounty may reward demonstration more than description.
Security platforms will probably need AI to filter AI
There is an obvious next step.
If attackers and researchers can generate thousands of AI-assisted reports, companies will need automated systems to triage them.
One model submits the vulnerability.
Another model checks whether the report is internally consistent.
A sandbox attempts reproduction.
A separate agent measures exploitability.
Only the strongest findings reach human reviewers.
That is a familiar pattern in AI.
Automation on one side creates demand for automation on the other.
The incentive system may also change
Bug bounty programs were built when finding vulnerabilities required substantial expertise and effort.
AI reduces some of that effort.
Programs may therefore adjust how rewards are calculated.
More money for:
validated high-impact exploits,
high-quality patches,
or genuinely novel research.
Less reward for weak theoretical findings.
Google's separate Patch Rewards program already emphasizes concrete security improvements and can offer substantial rewards for high-impact fixes.
That approach may become more common.
What happens next?
Google's other vulnerability-reward programs remain available, and the pause applies specifically to the affected open-source product-vulnerability channel rather than representing the end of bug bounties at Google.
But the incident is an important warning for the entire cybersecurity industry.
AI can lower the cost of finding real flaws.
It also lowers the cost of producing extremely convincing nonsense.
Security programs therefore need to evolve from asking:
Does this report look technically sophisticated?
to:
Can this vulnerability actually be proven?
The AI era may produce more security researchers than ever.
The hard part will be figuring out which discoveries are real.
