cd /news/ai-safety/ai-slop-submissions-force-google-to-… · home › topics › ai-safety › article
[ARTICLE · art-145250] src=helpnetsecurity.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

AI slop submissions force Google to freeze its open-source bug bounty

Google stopped accepting new product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP) as of October 1, 2026, citing a significant rise in automated submissions that were largely invalid and AI-generated. The company's OSS VRP rules page states the pause follows the flood of automated reports that burdened the engineers and open source maintainers reviewing them.

by read1 min views2 publishedOct 5, 2026

Google has stopped accepting new product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP), after a wave of invalid, AI-generated submissions swamped the engineers and open source maintainers who review them. The rules page for Google’s OSS VRP states that “as of October 1, 2026, we are no longer accepting product vulnerabilities submitted to the OSS VRP.” “This is due to a significant rise in automated submissions, the vast majority … More

The post AI slop submissions force Google to freeze its open-source bug bounty appeared first on Help Net Security.

── more in #ai-safety 4 stories · sorted by recency
── more on @google 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/ai-slop-submissions-…] indexed:0 read:1min 2026-10-05 · —