The AI Slop Loop: Why Google's Bounty Freeze Signals a Broken Incentive Model

AI-generated image · Bay Street Wire
When automated hallucinations overwhelm human maintainers, the critical feedback loop between security researchers and silicon giants snaps.
As TechCrunch first reported, Google has paused its Open Source Software Vulnerability Rewards Program as of October 1. The company cited a "significant rise" in automated submissions, noting that the vast majority of these reports are not valid. This is the real-world manifestation of "AI slop"—a wave of low-quality, automated reports that TechCrunch previously warned posed a risk to the viability of bug bounty programs.
***Opinion:*** *The problem isn't the AI, but the friction it creates. When the cost of submitting a report drops to near zero, the incentive shifts from finding genuine vulnerabilities to gambling on volume, weaponizing the bounty model against the engineers it is meant to assist.*
Reporting from Tom’s Hardware highlights the human cost: Google engineers and maintainers have been overwhelmed by reports that are either invalid or contain hallucinations. Google has promised an update in the first quarter of 2027, effectively freezing the reward pipeline until next year. If the industry cannot filter AI noise from genuine research, the collaborative relationship between silicon giants and white-hat researchers may permanently erode.

