Policy
Google freezes open-source bug-bounty product reports after a flood of AI-generated submissions
Google stopped accepting product-vulnerability submissions to its Open Source Software Vulnerability Reward Program on October 1, citing thousands of invalid, AI-written reports describing unexploitable or hallucinated bugs that were burying maintainers. Supply-chain reports and some Cloud VRP repositories remain open, and Google says it will share an updated program by Q1 2027. Linux and Intel have taken similar steps. For anyone building AI security tooling, the lesson is that triage quality, not volume, is what program owners now reward.
Companies mentioned