Google has announced that it is temporarily suspending a “Vulnerability Reward Program” aimed at detecting critical security flaws in open-source software due to problems caused by artificial intelligence. These systems, known as bug bounty programs, encourage researchers to report vulnerabilities rather than exploit them, and are run by most major tech companies.
In a statement on X, Google said the pause was caused by a significant surge in automated submissions, the vast majority of which were invalid. The news comes at a time of growing concern that powerful AI models are making it easier to find security vulnerabilities.
Google is not the only company experiencing similar problems. The rise in faulty reports generated with little effort is burdening engineers to the point where they cannot address real issues. Linus Torvalds, the founder of Linux, said that the unrelenting stream of AI reports has made security work “almost unmanageable.” Intel, meanwhile, last month shut down a similar program that offered rewards of up to $100 thousand for reports; however, it did not explicitly cite AI as the reason.
Why it matters
Bug bounty programs are one of the fundamental mechanisms in the open source world for ensuring that security vulnerabilities are closed before they fall into the hands of malicious actors. If these programs are rendered ineffective under the burden of AI-driven reports, it means that critical vulnerabilities could go unreported or that maintenance teams would be unable to filter out real threats. The Torvalds and Intel examples show that the problem is not confined to a single company but has turned into a blockage across the ecosystem. The pause narrows the legitimate reporting channel for independent researchers and brings back to the fore the risk of abuse that these systems were established to prevent. The real question facing developers, however, is whether these programs can be sustained without a method to filter the flood of automated reports.