The takeaway
Automated AI findings still need human verification before they reach a shared queue. Google's pause shows how much triage cost unvalidated agent output adds, and it thins out the paid disclosure channel for open-source security.
Why it matters for builders
Teams running AI agents that scan code or file security reports should add a human verification gate: unvalidated agent output is a triage cost shifted onto someone else. Google's pause also removes a paid disclosure channel for open-source vulnerabilities, so maintainers of projects you depend on are now less resourced to hear about real flaws.
Google Pauses Open-Source Bug Bounty Over AI Slop Flood
Google has stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP), the bug bounty that pays researchers for finding flaws in the company's public code, including projects like Go, Angular, and Protocol Buffers. The pause took effect October 1 and runs until at least a promised update in the first quarter of 2027.
The reason, in Google's own words, is a "significant rise in automated submissions, the vast majority of which are not valid."
What exactly changed
The OSS VRP rules page now states plainly: "As of October 1, 2026, we are no longer accepting product vulnerabilities submitted to the OSS VRP." Reports filed before that date are unaffected. Supply-chain reports, which require demonstrating a concrete path to tamper with source code or release artifacts, remain open. For some Google Cloud repositories, product bugs may still be routed through the separate Cloud VRP.
According to Tom's Hardware, Google engineers and open-source maintainers were overwhelmed by reports that were invalid or contained hallucinated findings. In many cases, triaging a single report cost more time than it was worth.

Why AI slop broke bug bounties
Bug bounties run on a simple trade: researchers spend expensive manual effort, and companies pay for the few findings that actually matter. Large language models collapsed the cost of producing a fluent, confident, plausible-looking report to almost zero. The result is a flood of submissions that sound serious but are wrong, and every one of them still needs a human to check.
Google is not the first to buckle. The curl project ended its bug bounty in January 2026 for the same reason. HackerOne stopped accepting new Internet Bug Bounty submissions in March. Intel recently froze a program that paid up to $100,000 per flaw, and Linux maintainers reported being swamped by bogus CVE filings.
Why it matters for builders
If your team runs AI agents that scan code, patch dependencies, or file security reports, this is a direct warning. Automated findings need a human verification gate before they leave your pipeline. Volume without validation is a liability that lands on someone else's desk, and the same pattern shows up anywhere agents generate work for humans to review, from support tickets to code review.
The second effect is smaller but real: open-source security disclosure just lost a paid channel. A genuine flaw in a project like Go now has fewer places to go, and unpaid reports to volunteer maintainers tend to sit longer. If you depend on open-source software, the pipeline that protects it is now thinner.
Sources: Google OSS VRP rules - TechCrunch - The Verge
The Automation Brief
Read 5 AI stories instead of 50.
The essential moves in AI agents, models, automation and infrastructure — filtered for builders and operators, with the part that actually matters.
No noise. Unsubscribe anytime.
Editorial notes
Stefan Trbojevic
n8n Lab Editorial
5 October 2026
5 October 2026
Sources
AI disclosure: AI assisted with research and drafting. Factual claims are reviewed by an editor.




