Artificial intelligence promises to accelerate the discovery of security flaws, but Google is now confronting the darker side of this evolution: the generation of convincing reports for non-existent problems. The company has announced a temporary suspension of part of its Open Source Software Vulnerability Reward Program (OSS VRP), citing a deluge of invalid, automated submissions.
The Suspension and Exceptions
As of October 1st, Google has stopped accepting new product vulnerability reports through the OSS VRP. This decision does not affect all of the company's reward programs. Pending reports and those concerning the software supply chain continue to be processed. Google plans to reshape the program and has committed to providing an update in the first quarter of 2027, though no specific resumption date has been set.
The Rise of 'AI Slop'
The core of the issue lies in low-quality reports generated by AI tools, often referred to as "AI slop." While AI can assist in organizing findings, Google emphasizes that the burden of verification remains with the researcher. A detailed description is not proof that a vulnerability exists or has a significant security impact.
"AI tool results need verification... even a real code error can have negligible security significance," the company had previously noted in rule updates.
Contrasting Industry Experiences
The challenge of AI-generated reports is not unique to Google, but its impact varies across bug bounty platforms:
- HackerOne: Reports an increase in "false positives" and treats submissions containing fabricated vulnerabilities or vague technical content as spam.
- Bugcrowd: While overall submission volume is up, founder Casey Ellis states that AI has not yet caused a significant spike in low-quality reports.
With rewards for valid findings ranging from $500 to over $30,000, the financial incentive remains high. However, Google makes it clear that AI-driven speed cannot substitute for technical accuracy and documented proof of real-world consequences.