Google resumes its Open Source Software Vulnerability Rewards Program with updated rules filtering AI-generated reports.
Google paused its vulnerability bounty program on October 1 after an influx of low-quality automated AI bug reports.
Across 6 frontier models answering independently, the panel leans yes: the median is 82%.
They broadly agree, 10 points between Gemini at 88% and Claude at 78%.
Nothing is settled until 4 Apr 2027, when the outcome is checked against sources and every number above gets a permanent score.
What each one said
-
GeminiGoogle
Google relies heavily on community OSS security and will revamp screening criteria rather than permanently abandon the program.
- Google's security team typically takes three to six months to re-architect submission pipelines after major triage disruptions.
- Bounty programs paused due to LLM spam historically relaunch with KYC, fee barriers, or explicit automated report bans.
- A full 18-month window provides ample runway to deploy gating filters before the April 2027 resolution date.
88% -
DeepSeekDeepSeek
Whether Google can build an AI-report filter good enough to reopen a program it paused for exactly that reason.
- Google paused the OSS VRP on Oct 1, 2025, citing AI slop; the fix is a triage/filter layer, not a policy debate, so the blocker is engineering.
- Google already runs AI-assisted triage on its main VRP and has 18 months to ship; a filtered relaunch is the obvious institutional path.
- Precedent: Google's 2024 OSS VRP relaunch after a pause took months, not years; the main risk is a quiet permanent shutdown instead of a formal resume.
88% -
GPTOpenAI
Google has a strong incentive to reopen within six months, but the scope of AI-report filters is the key uncertainty.
- Google must publish revised program terms and restore submissions; that is operationally simpler than creating a new bounty program.
- Major bug bounties usually survive spam waves, and a six-month pause gives Google time to add triage gates and disclosure rules.
- I would lower this sharply if Google shifts OSS rewards to invitation-only testing or routes reports permanently through existing VRPs.
82% -
QwenAlibaba
Google has strong incentives to resume but will likely add AI-report filtering before reopening.
- Google paused on Oct 1, 2026 due to AI spam; they've historically resumed programs after process fixes within weeks to months.
- The OSS VRP is a low-cost, high-PR program Google uses for goodwill; abandoning it permanently would generate negative press.
- Filtering AI-generated reports is technically straightforward (rate limits, proof-of-concept requirements, manual triage gates) and Google has already signaled this…
82% -
GrokxAI
Google's VRP team must ship AI-report filters and reopen OSS-VRP inside six months.
- Security/VRP owners paused Oct 1 2026; they historically retune rules in weeks-to-months rather than years.
- Filters (rate limits, provenance, quality gates) are already discussed internally and match prior VRP policy updates.
- A longer freeze or merger into the main VRP without an explicit OSS restart would drop the odds; public GitHub/blog posts would raise them.
81% -
ClaudeAnthropic
Hinges on Google engineering effort to build AI-report filters and relaunch within an 18-month window.
- Google has strong incentive to resume OSS VRP since bounty programs are core to its security strategy and community goodwill.
- 18 months is ample time for Google to design triage/filtering rules for AI-generated reports, a problem many bounty programs now face.
- Main risk is indefinite deprioritization or replacement with a different program structure rather than a literal 'resume with updated rules' framing.
78%
6 of 6 models answered · 10 points between the highest and lowest. None was shown the market price.
Question sourced from a news sweep on 6 Oct 2026. Forecast by google/gemini-3.8-flash, anthropic/claude-sonnet-5, openai/gpt-5.6-terra, x-ai/grok-4.6, deepseek/deepseek-v4.1-flash, qwen/qwen3.8-max-0902 via OpenRouter.