Google has temporarily halted its bug bounty program aimed at discovering vulnerabilities in its open-source software, following a surge of false reports generated with the help of artificial intelligence. The influx of fabricated bug claims has overwhelmed the program’s human reviewers, making it difficult to identify legitimate security issues.

The program, designed to reward researchers who find genuine flaws in critical open-source projects supported by Google, encountered an unexpected challenge as AI tools began producing automated bug submissions at scale. This surge increased the volume of reports beyond manageable levels, prompting the suspension to preserve the effectiveness of the review process.

The open-source bug bounty initiative sought to improve the security of widely used projects by financially incentivizing detailed and verifiable vulnerability disclosures. However, as AI-driven methods generated numerous erroneous or non-existent bugs, the manual validation workload ballooned, threatening to overwhelm the team tasked with ensuring software integrity.

Researchers and developers involved in the program now face delays and uncertainty regarding reward eligibility as Google reassesses how to filter and authenticate incoming reports more effectively. The company is exploring solutions that might integrate more sophisticated automated triage while retaining human oversight for critical decisions.

As open-source software forms the backbone of much of the tech industry, ensuring its security remains a strategic priority. Google’s experience underscores the double-edged nature of AI in cybersecurity: while it can enhance detection capabilities, it also introduces new complexities requiring faster adaptation of validation frameworks to handle increasingly synthetic submissions.