Google froze its open-source bug bounty program due to a flood of AI-generated slop. Is the future of tech automated security?
Google hit the brakes on its Open Source Software Vulnerability Rewards Program, and AI spam is to blame.
Script kiddies and hopeful bounty hunters leverage LLMs to churn out automated vulnerability reports. But these bots throw nonsense at human maintainers instead of finding real security flaws. Hallucinated code, bogus exploits, and endless noise completely overwhelm Google’s engineering teams. And manually triaging thousands of junk filings drains time that engineers should spend fixing code. Consequently, Google slammed the brakes on October 1, promising an update in early 2027.
This freeze exposes a major flaw in current AI tools. Generative AI excels at pattern matching, but completely fails at actual reasoning. Security research requires deep context and real validation- things a prompt cannot replicate. When novice hackers treat AI as a free money printer, tech companies pay the price in lost engineering hours.
Google’s decision sets a vital precedent.
Tech platforms cannot allow automated slop to destroy crucial crowdsourced security. The only solution? Bug bounty platforms must build strict AI filters or impose penalties for garbage submissions. Or the alternate scenario? Genuine security researchers will keep losing space to automated noise.
AI can generate code instantly, but humans still need to clean up the mess.


