Google suspends bug bounty program due to influx of AI reports - Sarmad

Google announced the temporary suspension of one of its flagship bug bounty programs, after the growing volume of reports generated by artificial intelligence became unsustainable to manage.
The suspended program focused on identifying critical vulnerabilities in open-source software.
Known as “bug bounty programs,” these initiatives reward security researchers with financial incentives for reporting vulnerabilities they discover, enabling fixes to be deployed before malicious actors can exploit them. Major technology companies rely on such programs to strengthen the security of their products and services, while also providing researchers with a financial incentive to report vulnerabilities rather than exploit them to launch attacks.
However, artificial intelligence is beginning to alter this dynamic. It has become easier to use AI to generate large volumes of security reports in a short period, though a significant proportion of these reports are not based on genuine issues. In a post on the X platform, Google stated that the decision to suspend the program resulted from a “sharp increase in the number of automated submissions,” noting that the vast majority of them “lack a valid basis.”
The problem extends beyond the sheer volume of reports; it also involves the time and effort required by engineers to review them. When a security team receives thousands of inaccurate reports, it becomes difficult to identify the real vulnerabilities that need to be fixed.
These developments raise broader concerns about the impact of AI on internet security. Previous warnings have focused on the ability of advanced AI models to assist hackers in discovering vulnerabilities that can be exploited to carry out attacks. Google’s experience, however, demonstrates that AI can create a different kind of problem: overwhelming security teams with automated reports that are difficult to verify.
Google does not appear to be the only company facing this issue. The influx of reports that lack sufficient effort and are often inaccurate has increased the burden on engineers and complicated their ability to identify genuine security problems. Earlier this year, Linus Torvalds, the creator of the Linux operating system, stated that the “continuous flow of AI-generated reports” had made security work “nearly impossible to manage.” Meanwhile, Intel appeared to shut down a similar bug bounty program last month, which had offered rewards of up to $100,000, without explicitly stating that AI was the reason for the program’s closure.