Google

AI noise forces Google to pause bug bounty for open source

AI noise isn't just annoying, it's now costly enough that Google has paused bug bounties for open-source projects.

3 min readTechCrunch
AI noise forces Google to pause bug bounty for open source

Google's decision to pause bug bounty payouts for certain open-source vulnerabilities is a quiet admission that AI-generated noise has become an operational threat. The company is essentially saying that the volume of low-quality, automated submissions, what many now call AI slop, has overwhelmed the human reviewers who triage real security flaws. This is not a minor policy tweak; it is a signal that the incentives driving security research are breaking under the weight of their own automation.

For anyone who relies on open-source software, which is to say, everyone building modern applications, this matters immediately. Bug bounty programs have long been the frontline for catching vulnerabilities before attackers do. When those programs become clogged with junk reports generated by large language models, the signal-to-noise ratio collapses. Real bugs get buried, response times slow down, and the entire ecosystem becomes less secure. Google's move is pragmatic, but it also reveals a deeper problem: the tools we build to accelerate discovery can just as easily accelerate distraction. This is not unlike the challenge Google faces in other domains. Consider how Google's Gemini 4 Argon delivers a focused workhorse for coders and security teams, a model explicitly designed to cut through complexity for developers. The irony is that the same kind of AI capability, when pointed at bug bounty forms instead of codebases, produces the opposite effect.

The practical consequence for our readers is straightforward: do not assume that crowdsourced vulnerability discovery will remain as reliable as it was a year ago. If you are a security lead, you should be asking your vendors how they filter AI-generated submissions. If you are a researcher, you need to understand that submitting a report generated by an LLM without verification may now actively harm your credibility. Google's pause is a defensive measure, but it also points toward a necessary redesign of how these programs work. The old model assumed human effort was the scarce resource. Now the scarce resource is human attention, and AI can generate infinite demands on it. This is the same tension visible in Google's broader strategy shifts, as AI agents evolve, Google shifts focus from Gems to integrated skills, where the company is learning that raw capability without curation creates more noise than value.

The open question is whether the industry will respond by raising the barrier to entry for submissions, requiring proof of exploitation or manual verification before a report is even accepted. That would slow down the bounty pipeline but might restore its integrity. Or we may see a future where only vetted, human-authorized researchers can submit findings, effectively turning public programs back into private invite-only ones. Neither outcome is ideal, but the alternative, letting AI slop degrade the most effective vulnerability discovery system we have, is worse. Watch how Google handles the resume of this program. The specific criteria they set for acceptable submissions will become a template for every other major bounty operator.

From TechCrunch

AI slop seems to be overwhelming bug bounty programs.

Read the original at TechCrunch