Google has implemented new restrictions on its Open Source Software Vulnerability Reward Program, effectively barring AI-generated bug reports while simultaneously backing initiatives to enhance open-source security infrastructure through artificial intelligence.
The decision stems from mounting concerns within Google's OSS VRP team regarding the deteriorating quality of automated vulnerability submissions. A significant portion of these AI-generated reports contain fabricated exploit scenarios—commonly known as hallucinations—or flag issues with negligible security implications, creating substantial noise in the triage process.
"To ensure our triage teams can focus on the most critical threats, we will now require higher-quality proof (like OSS-Fuzz reproduction or a merged patch) for certain tiers to filter out low-quality reports and allow us to focus on real-world impact," Google wrote in a blog post.
This challenge extends beyond Google's ecosystem. The Linux Foundation faces similar pressures from the deluge of algorithmically generated vulnerability reports, prompting a collaborative funding initiative. Major AI stakeholders—Google, Anthropic, AWS, Microsoft, and OpenAI—have collectively committed $12.5 million to bolster open-source security capabilities and help maintainers manage the influx.
"Grant funding alone is not going to help solve the problem that AI tools are causing today on open-source security teams," said Greg Kroah-Hartman of the Linux kernel project in a blog post. "OpenSSF has the active resources needed to support numerous projects that will help these overworked maintainers with the triage and processing of the increased AI-generated security reports they are currently receiving."
The financial commitment will flow through the Alpha-Omega project and the Open Source Security Foundation (OSSF), with resources directed toward developing AI-powered tooling that assists maintainers in efficiently processing and validating the surge of automated submissions.
"We are excited to bring maintainer-centric AI security assistance to the hundreds of thousands of projects that power our world," said Alpha-Omega co-founder Michael Winser.
This article first appeared on InfoWorld.