Google pauses part of bug bounty program amid flood of AI-generated reports
Google has temporarily stopped accepting certain bug bounty submissions after a surge of largely invalid AI-generated reports. The company had already tightened evidence requirements and cut rewards for low-tier findings, but the validation bottleneck now affects security teams industry-wide.
- Google paused some bug bounty submissions after a spike in AI-generated reports
- In March it tightened rules for its open-source vulnerability program
- Vercel received 1,285 vulnerability reports in a two-week challenge, dozens validated
- CISOs should judge AI security tools by validated findings, not raw volume
Read next
Security