Artificial intelligence was supposed to make security research faster. Security researchers can now use AI to inspect large codebases, identify suspicious patterns and generate vulnerability reports much more quickly than before. But Google has now encountered the other side of that equation: too many reports, too little useful signal. Google temporarily paused new product-vulnerability submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) from October 1, 2026, after a significant rise in automated submissions, with the company saying that the vast majority were not valid. Google plans to reassess the programme and provide an update in the first quarter of 2027. 

What Happened to Google's Bug Bounty?

Google's OSS VRP rewards security researchers for finding vulnerabilities in Google-maintained open-source projects, including projects such as Go, Angular and Fuchsia, along with selected dependencies and repository configurations. The programme has been part of Google's broader vulnerability-reward ecosystem since 2022. The recent change does not mean Google has abandoned open-source security research. Instead, only the new product-vulnerability reporting path has been paused, while supply-chain vulnerabilities and existing reports remain covered under the current rules and researchers can use other applicable programmes such as the Patch Rewards Program. 

That distinction is important because the situation can easily be misunderstood. Google has not shut down its entire open-source security programme; it has paused one category of new submissions while it reassesses how the programme should handle the changing volume and quality of AI-assisted security reports.

Why AI Became a Problem for Bug Bounties

The underlying issue is simple: AI dramatically reduces the cost of producing a security report. A human researcher may spend hours understanding source code, validating an attack path and preparing a detailed vulnerability report. An automated tool or AI-assisted workflow can inspect the same repository and generate large numbers of candidate findings in a fraction of that time. The problem appears when the speed of discovery becomes greater than the ability to verify whether those findings are actually meaningful. 

Google had already acknowledged this change earlier in 2026. In updates to its Android and Chrome vulnerability programmes, the company said AI had made it much easier to produce lengthy vulnerability write-ups, leading programmes to place greater emphasis on concrete evidence, reproduction steps and high-impact findings instead of simply accepting detailed-looking reports. AI-generated does not automatically mean incorrect, but a rapidly growing number of low-value reports can still place significant pressure on security teams that must manually determine whether each finding is real, exploitable and important.

The Bigger Problem Is the Triage Queue

Finding a potential vulnerability is only the beginning of the process. Security teams still need to reproduce the issue, establish whether it can actually be exploited, understand its potential impact and decide whether a fix is necessary. When large numbers of duplicates, false positives or theoretical issues enter the system at once, they consume the same expert attention needed to investigate legitimate vulnerabilities.

HackerOne reported that vulnerability-report volume across its platform had increased by more than 100% after the arrival of more advanced AI tools. Its research found a mixture of genuinely useful AI-assisted findings as well as duplicates and reports that could not be verified. HackerOne has responded by expanding automated triage and routing while still requiring researchers to remain responsible for the quality of their submissions. The broader lesson is that human validation may increasingly become the scarce resource in cybersecurity rather than vulnerability discovery itself. 

AI Is Still Making Security Researchers More Powerful

It would be wrong to conclude that AI is bad for vulnerability research. Google itself says AI and automation are accelerating vulnerability discovery while helping security teams understand root causes, recommend fixes and identify variants of known bugs. Its security teams use systems including Big Sleep, CodeMender and OSS-Fuzz alongside human researchers and security engineers.

Microsoft is seeing a similar transformation. Its 2026 bounty review reported more than $20 million awarded to 562 security researchers, alongside increased submission volume and growing use of AI in security research. Microsoft continues to require reports to demonstrate reproducible and meaningful security impact. The direction of the industry is therefore not really “humans versus AI.” It is becoming AI-assisted discovery followed by stronger human verification. 

What Changes for Security Researchers?

For researchers, Google's decision is a warning about how AI should be used in bug hunting. A workflow based on scanning everything, generating hundreds of reports and submitting them all may produce a large quantity of output, but it does not necessarily produce valuable security research. A stronger approach is to use AI to discover potential weaknesses, manually validate them, reproduce the issue, prove the security impact and then submit a concise report. 

Google's current OSS rules emphasise high-quality reports containing reproducible proof, affected versions, impact and attack scenarios. That makes one skill especially important for students and new bug hunters: understanding the difference between a code smell and a real security vulnerability. A suspicious function is not automatically exploitable, and a theoretical attack is not necessarily a practical one. AI can help researchers determine where to look, but the researcher still has to prove what actually happens. 

The Industry Is Already Changing Its Rules

Google is not the only organisation responding to the changing economics of security research. HackerOne has introduced stronger mechanisms for handling AI-driven report volume, including automated routing, deduplication and quality controls. Its research highlights a more complicated future in which AI can simultaneously create valuable vulnerability discoveries and overwhelming amounts of low-quality output. 

Microsoft's bounty guidelines make a similar point. Automated scanning tools are common, but reports generated by scanners still require additional analysis demonstrating exploitability before they can qualify for rewards. A broader standard is therefore emerging across the industry: AI can help find a potential bug, but evidence still has to prove that the bug is real and matters. 

What This Means for Students Learning Cybersecurity

For students entering cybersecurity, this shift can actually be an advantage. Running an automated scanner is becoming less distinctive because AI can increasingly perform large-scale scanning automatically. The more valuable skill is understanding why a finding matters, how it can be reproduced and what an attacker could realistically achieve. 

Students learning bug bounty hunting should therefore spend serious time understanding HTTP, authentication, APIs, operating systems, networking, source-code analysis and vulnerability exploitation alongside AI-powered security tools. The strongest future security researcher may not be the person who produces the largest number of reports. It may be the person who can use AI to explore thousands of possibilities and then identify the one finding that genuinely matters. 

Knowledge Corner: What Is Security Triage?

Security triage is the process of reviewing vulnerability reports, reproducing the claimed issue, assessing its severity and deciding what action should follow. It is a critical part of every bug-bounty programme because a reported vulnerability still needs expert validation before it can be treated as a genuine security problem. 

This is why low-quality AI-generated reports can become an operational problem even when they are harmless. Every report still requires someone to determine whether it is valid, duplicated, exploitable or relevant, which means an increase in automated submissions can increase workload even when the number of real vulnerabilities does not increase at the same rate.

The Real Lesson: More Automation Does Not Automatically Mean Better Security

Google's decision illustrates an unusual side effect of AI adoption. Technology designed to improve security can create a new operational problem when vulnerability discovery becomes faster than vulnerability verification. The solution is not to stop using AI for cybersecurity. Instead, security workflows need to be redesigned around evidence, reproducibility and prioritisation, allowing AI to expand what researchers can investigate while humans remain responsible for deciding whether a vulnerability actually exists and how serious it is. 

Google's pause is therefore less a rejection of AI-powered security research and more a signal that the old bug-bounty model may not scale unchanged into the AI era. The next generation of vulnerability-reward programmes may increasingly be built around a simple principle: fewer reports, stronger evidence and much smarter triage.