Cybersecurity & Privacy

Google Pauses Open-Source Bug Reports Amid AI Slop Concerns

Google has paused new OSS product-vulnerability reports after a surge in invalid automated submissions. Supply-chain reports remain open, with an update due in Q1 2027.

By Daniel Mercer Edited by Maria Konash Published: Updated:
Google Pauses Open-Source Bug Reports Amid AI Slop Concerns
Google has paused new OSS product-vulnerability reports after a surge in invalid automated submissions, with an update promised for Q1 2027. Photo: Anthony Quintano / Wikimedia Commons

Key Notes

  • Google paused new OSS product-vulnerability reports on October 1 after a surge in invalid automated submissions.
  • Supply-chain reports, pending submissions and other eligible Google reward routes remain available.
  • Google plans a Q1 2027 update, but has not confirmed when product submissions will reopen.

Google has paused new product-vulnerability reports through its Open Source Software Vulnerability Reward Program after a surge in automated submissions that it says are overwhelmingly invalid. The change took effect on October 1, leaving the company to redesign how this part of its open-source bug bounty operates.

The decision highlights a growing problem for software maintainers: a system that can generate a convincing security report in seconds can also leave a human engineer spending much longer checking whether the alleged flaw exists. Google’s announcement identifies automation as the cause, without quantifying how many submissions came from generative AI. 

What Google Has Actually Paused

The updated program rules close intake for new OSS product-vulnerability submissions. Reports submitted before October 1 are unaffected, and the program still accepts eligible supply-chain findings. Certain flaws in Google Cloud repositories may also qualify through the separate Cloud VRP.

That scope matters. Google has not closed every vulnerability reward program or stopped rewarding every kind of open-source security research. The remaining supply-chain route concerns issues affecting the integrity of source code or the build process, rather than the suspended product-vulnerability category.

Google is directing researchers toward its other applicable reward programs and Patch Rewards. It has promised an update in the first quarter of 2027 while it reworks the affected part of OSS VRP. That is a commitment to share changes, rather than a confirmed date for reopening submissions.

Cheap Reports Can Create Expensive Work

In its October 1 announcement, Google said the pause followed “a significant rise in automated submissions, the vast majority of which are not valid.” It did not publish a submission count, rejection rate or estimate of the engineering time consumed.

The cost imbalance is easy to understand. Generating a suspected bug report is only the first step. Someone must reproduce the behavior, check the affected version, establish a security impact and distinguish a real vulnerability from an incorrect assumption about how the code works.

AI can reduce the cost of that initial search while multiplying the number of claims awaiting review. A polished explanation does not remove the need for evidence. If plausible-looking reports arrive faster than maintainers can validate them, the resulting queue can divert attention from genuine defects and routine development.

Curl Shows Both Sides of the Problem

The curl project offers a useful comparison. Maintainer Daniel Stenberg announced in January that its bounty would end on January 31, citing AI-generated junk reports and the burden they placed on maintainers. The project continued accepting security disclosures, but removed financial rewards.

The experience then changed. In an April update, Stenberg said the junk-report problem had largely subsided and report quality had improved. He also described a different strain: a high volume of useful findings still required people to investigate and fix them.

That distinction is central to the wider debate. Automated research can produce valuable discoveries, while submission systems can still struggle with volume. Our coverage of a reported Coldcard audit examined the same gap between a low model-running cost and the human work needed to validate a security finding.

What to Watch in the Redesign

Google has not yet detailed the replacement process. The practical question is how a revised program will separate credible evidence from speculative output before reports consume significant maintainer time. Clear scope, reproducible findings and demonstrable impact are the ingredients that make a report actionable, regardless of which tools helped produce it.

The Q1 2027 update should clarify how Google intends to balance those demands. For now, the pause shows that making vulnerability discovery cheaper does not automatically make vulnerability handling cheaper. The success of AI-assisted security research ultimately depends on getting verified findings into a process that has the capacity to fix them.

Disclaimer: AIstify is an independent media brand owned and operated by NuvexMedia LLC, publishing news, research, and insights on artificial intelligence, emerging technologies, automation, and related industries. NuvexMedia LLC invests in and collaborates with companies across the AI, technology, software, and digital innovation sectors. These relationships do not influence AIstify’s editorial coverage, and the publication maintains full editorial independence to provide accurate, timely, and objective information. © 2026 NuvexMedia LLC. All rights reserved. This content is for informational purposes only and should not be considered legal, tax, investment, financial, or other professional advice.

AI & Machine Learning, Cybersecurity & Privacy, News