Affiliate links on Android Authority may earn us a commission. Learn more.
Google praised AI for finding bugs. Now it has too many reports, not enough bugs
Oct 6, 2026 — 6:36 AM ET

- Google has stopped accepting product vulnerability reports through its OSS VRP after a sharp rise in automated submissions, many of which it says are invalid.
- The company had already warned in March about a massive surge in AI-generated reports, including hallucinated bugs and low-impact issues.
- The timing is hard to ignore: Google has spent much of 2026 praising AI for making bug hunting faster, easier, and far more productive.
Google has been doing a pretty good job of showing off what AI can do for software security. Its AI agents are finding bugs humans missed, uncovering vulnerabilities buried in code for years, and scanning enormous codebases faster than security teams ever could. Google executives have even called some of these tools a “game changer.” But a rather funny wrinkle has emerged in that success story: AI has apparently become so good at helping people find bugs that Google has had to close one of the doors through which those bugs were being reported.
The search giant has temporarily stopped accepting product vulnerability submissions through its Open Source Software Vulnerability Reward Program, or OSS VRP, after what it describes as a “significant rise in automated submissions.”
The change, first reported by TechRadar, took effect on October 1. Google says the “vast majority” of those automated submissions are not valid, and it will spend the next few months reworking this part of the program before providing another update in Q1 2027. Supply-chain reports remain open, while some Google Cloud-related issues may still qualify through the separate Cloud VRP.
However, this didn’t exactly come out of nowhere.
Back in March, Google said it had already seen a “massive surge in AI-generated reports” coming into the OSS VRP. Some contained hallucinated explanations of how vulnerabilities could be triggered. Others identified genuine coding mistakes, such as buffer overflows, but in unreachable code or places where the issue had little meaningful security impact. Google tightened its rules then, requiring stronger proof for some reports and dropping rewards for certain lower-tier vulnerabilities.
And that is where this becomes particularly amusing.
Google has spent much of 2026 celebrating its own AI security systems for doing exactly this kind of work, only with better guardrails. Its PageBreak agent, for example, has uncovered more than 500 cross-site scripting vulnerabilities across Google’s own web apps. Other internal AI agents scan hundreds of millions of lines of Google infrastructure code and reportedly prevent hundreds of vulnerabilities every month.
But GrapheneOS now warns that the pressure goes beyond bounty submissions. The project says Google has become “completely overwhelmed” by vulnerabilities being discovered by AI models both internally and externally, and that the volume is affecting how Android security fixes are handled and backported.
So Google clearly hasn’t fallen out of love with AI-powered bug hunting. It may simply be running into the other side of the breakthrough it has spent months celebrating: once machines make finding potential bugs dramatically easier, somebody still has to figure out which ones are actually worth fixing.
Thank you for being part of our community. Read our Comment Policy before posting.
