Artificial intelligence seems to be starting to create a new problem in the cybersecurity space, this time not because it finds more vulnerabilities, but because it produces a huge volume of reports that offer no real value . Google has decided to temporarily suspend the submission of certain reports to its Open Source Software Vulnerability Reward Program (OSS VRP) .

The decision comes after a sharp increase in automated reports generated with the help of AI, with the company pointing out that the vast majority of them are not proven valid.
What is Google's OSS VRP?
The program was created in August 2022 with the aim of encouraging security researchers to responsibly identify and disclose vulnerabilities in important open source projects maintained by Google.
The program includes projects such as Golang, Angular, Bazel, Protocol Buffers, and Fuchsia, as well as critical third-party dependencies and potential vulnerabilities in repository settings. These include, among others, GitHub Actions configurations, application settings, and access control rules.
See also: GitHub reduces Public Bug Bounty rewards and moves the biggest rewards to a private program
Fees start at $100 and can go up to $31,337, depending on the severity and potential impact of a vulnerability. Particular emphasis is placed on issues that could impact the broader software supply chain.
AI filled the program with invalid reports
Google clarified that the temporary change concerns reports of product vulnerabilities in the OSS VRP and reports supply chain-related, nor those that have already been submitted and are under review.
The main reason is the massive increase in automated submissions. Artificial intelligence tools can now quickly analyze code, look for potential patterns associated with vulnerabilities, and generate reports with minimal human intervention.
The problem arises when speed of production exceeds accuracy. A report that simply indicates that there “maybe” a security vulnerability does not have the same value as a documented finding that can be replicated and proven to have real impact.
For security engineers, this translates into more time evaluating false positives and less time dealing with real threats.

Alternatives for researchers
Google isn't closing the door on security researchers. Researchers can continue to submit patches through Google Patch Rewards, which offers rewards of up to $15,000 for significant fixes to open-source software.
At the same time, the Cloud VRP remains available , through which vulnerabilities in Google Cloud open-source repositories that affect Cloud products can be reported.
The company is expected to review the operation of the OSS VRP and present more information in the first quarter of 2027.The change does not apply to product vulnerability reports submitted before October 1, 2026.
See also: Apple Bug Bounty: Maximum reward $2 million, $35 million to date
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Google has already invested millions in security research
The development is particularly significant considering the scale of Google's investment in its bug bounty programs. Since the launch of the first VRP in 2010, the company has paid out more than $81.6 million to thousands of researchers.
In 2025 alone, rewards reached a record high, with $17.1 million distributed to more than 700 researchers. The amount was up about 40% from the $12 million in 2024.
It's not just Google's problem
Google's case is part of a broader trend. In January, the curl ended its bug bounty on HackerOneafter receiving a large number of low-quality reports that were generated with the help of AI.
Intel followed suit , which in September eliminated monetary rewards for reporting vulnerabilities in software, firmware, hardware and services through its Integrity program , without publicly explaining the reasons for the decision.
Microsoft ofvulnerability detection, while creating greater operational demands on security teams.

The new AI paradox in cybersecurity
The development highlights an interesting paradox: the same technology that can help researchers identify real problems faster can simultaneously flood bug bounty programs with poorly vetted reports.
See also: Google: AI bug bounty program pays up to $30,000
The challenge now is not just the quantity of findings, but their quality. For companies, the challenge will be to design mechanisms that can quickly distinguish substantiated reports from AI-generated false positives, without discouraging researchers from responsibly using AI as a tool.
And as AI models become increasingly adept at analyzing code, this issue likely won't be limited to Google. Instead, it could become one of the biggest challenges bug bounty programs will face in the years to come.
source: www.bleepingcomputer.com
