In brief: Since 1 October, Google has stopped accepting new product-vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP). The company cites a sharp rise in automated submissions, the vast majority of which it says are invalid. Supply-chain reports, existing cases and the separate Patch Rewards programme remain open.
What is actually paused
The intake freeze covers new product-flaw reports submitted to the OSS VRP. Reports filed before 1 October continue to be processed. Software-supply-chain reports are explicitly excluded, and some findings in open-source repositories that affect Google Cloud products may still qualify for the Cloud VRP.
Google also directs researchers to its other reward programmes and to Patch Rewards. That route evaluates implemented security improvements rather than new vulnerability reports. Google promises an update on the redesigned OSS VRP branch in the first quarter of 2027, but has not specified future filters or access requirements.
The warning arrived in spring
The pause is not a rejection of AI-assisted security research. Google tightened the OSS VRP rules in March and added an April update: AI can accelerate discovery, but its output must be validated during the research.
Google's new statement provides no absolute submission numbers, time series for the valid-report rate or data on triage effort. It supports the company's claim of overload, but does not establish the general quality of AI-discovered vulnerabilities or their actual success rate.
Pandorex Analysis
The scope matters. Golem's headline says Google is stopping the open-source bug-bounty programme, which is broader than the official measure; the article body describes the exceptions accurately. This is not a complete end to the OSS VRP.
The episode exposes a structural imbalance: automation lowers the cost of producing a plausible report, while validation and triage remain labour-intensive. Google's response shifts part of the incentive from reporting towards fixing. Its effect on signal quality cannot be judged before new rules and meaningful programme data appear.
