AI is “flooding” human review work—and this time, Google’s open-source security program has been overwhelmed. Starting October 1, Google has suspended itsOpen Source Software Vulnerability Reward Program(OSS-VRP), citing a “significant increase in automated submissions, the vast majority of which are invalid.” In other words: AI-generated junk vulnerability reports have overwhelmed human reviewers.
what happened?
Google’s OSS-VRP is a security initiative for open-source software—security researchers earn rewards for discovering genuine vulnerabilities in open-source projects maintained by Google. But Google announced on X and the program’s official website that:the program will be suspended starting October 1, with the earliest possible “update” not expected until Q1 2027.
The official wording is restrained: “This suspension is due to a significant increase in automated submissions, most of which are not valid vulnerabilities.” According to Tom’s Hardware, the reality behind the scenes is—Google engineers and open-source maintainers have been inundated with massive volumes of invalid reports—even those containing “hallucinations”.
The “AI Garbage Report” Problem Is Backfiring on the Security Ecosystem
This issue was actually forewarned. Last year, TechCrunch reported that cybersecurity experts had long been sounding the alarm:AI-generated “content garbage” (AI slop) is posing a serious threat to bug bounty programs.Now this prediction has materialized at Google.
The core problem lies in the fact that large language models can now churn out text that superficially resembles legitimate vulnerability reports—but these reports often collapse under scrutiny: either the reported vulnerability does not exist, or it is entirelyhallucinatedby the model. Reviewers are forced to spend enormous time individually debunking each report, while genuinely valuable vulnerability submissions get buried under noise.
This is analogous to the earlierAI hallucination that nearly triggered a U.S. military interception incident—both are different facets of the same underlying issue: when AI outputs are treated as trustworthy information and fed directly into decision-making pipelines, the cost can be extremely high.
Using AI to find vulnerabilities is, in itself, sound technology
To be clear, leveraging AI for vulnerability discovery is not inherently flawed—in fact, it’s an inevitable trend. Google itself has long relied on automated fuzzing tools like OSS-Fuzz to uncover vulnerabilities in open-source software, and various large models have proven effective in helping security researchers locate real defects more efficiently.
The problem arises at the “submission” stage. When bug bounty programs intersect with AI, they foster aarbitrage mindset: scanning at scale with models, generating reports en masse, and submitting them in bulk—betting that at least one will hit the mark. The result? Genuine and fabricated vulnerability reports become indistinguishable, and review costs balloon uncontrollably.
This resembles content farms infiltrating search engines—AI dramatically boosts “output volume,” but the “signal” does not increase; only the noise grows.
What does it mean for developers?
For domestic developers, this is a warning sign worth heeding. An increasing number of developers are using AI programming assistants to automatically detect bugs and draft reports—but if未经人工核实的 AI outputs are submitted directly to vulnerability platforms or open-source projects,the entire collaborative ecosystem ultimately suffers—maintainers drown in noise and may resort to shutting down, as Google has done.
AI programming tools themselves are not at fault; the flaw lies in “blindly forwarding AI output.” For example, Claude Code’s Projects The real value of such multi-agent collaboration tools lies in enabling AI to do the work while preserving human judgment and review. A simple recommendation is:Always verify any conclusion generated by AI yourself before sending it to others.
A more widespread dilemma
This Google case is, at its core, an increasingly common problem in the AI era:The cost of generating content approaches zero, while the cost of human review does not decrease.When anyone can use AI to mass-produce “plausible-looking” submissions, all human-dependent review channels—bug bounty programs, open-source PRs, content moderation, and even job applications—risk being overwhelmed.
This also explains whyNVIDIA is building a dedicated platform for controlling uncontrolled agentsand whyDeepSeek is open-sourcing sandbox training infrastructure—as AI participates in more and more production steps, “trustworthy verification” becomes increasingly valuable. In the future, whoever can efficiently “verify the authenticity” of AI-generated outputs will hold a new moat.
Frequently Asked Questions (FAQ)
Is Google permanently shutting down this bug bounty program?
No—it is pausing, not permanently closing. Google states the pause begins on October 1, 2026, and commits to providing further updates in Q1 2027.
Why would anyone submit vulnerability reports using AI?
Because bug bounties offer monetary rewards, and large models make “batch-generating reports” nearly costless. Some people use AI to automatically scan and automatically write vulnerability reports, hoping to hit a real vulnerability and claim the reward—resulting in a flood of invalid or hallucinated reports.
Does this concern ordinary developers?
Yes. If you maintain an open-source project, you may receive an increasing number of AI-generated issues or PRs of uneven quality. We recommend retaining a human review step for AI-assisted code and reports—do not accept them outright.
Does Google have other bug bounty programs?
Yes. Google recommends participants consider its other bug bounty programs (e.g., those targeting Google’s proprietary products) during the pause—only the “open-source software” track is temporarily suspended.
Want to learn how AI is transforming development and security practices? Browse AI Model Library or Tool Comparison Engineor continue reading:From “Voice Assistant” to “Voice Agent”: An Upgrade · Meta open-sources Muse hardware code · Gemini 4 Argon released.
