
Artificial intelligence is undermining one of the central ways that security researchers keep the internet and our technology safe.
Last week, <a href="https://www.independent.co.uk/topic/google” rel=”nofollow noopener” target=”_blank”>Google announced that it would temporarily close one of its key security programs because artificial intelligence makes it no longer sustainable to run.
The company said that it was freezing one of its “Vulnerability Rewards Programs”, which focuses on finding critical flaws in its openovide an incentive for hackers to tell companies about issues with their software, so that they can be fixed before hackers use them
They represent an important way to ensure that cyber security researchers are rewarded for their work, and to ensure that they encouraged to use any bugs they find to help fix security problems rather than launch their own attacks. Most major tech companies run such bug bounty programs of their own, in recognition of their importance in protecting their software and platforms.
But Google said that it would temporarily freeze one of them because AI was making it easy to submit reports. “This pause is due to a significant rise in automated submissions, the vast majority of which are not valid,” it wrote in a post on X.
The news comes amid increasing concern about the ways that artificial intelligence could critically undermine online security. Much of that concern has pointed to the way that powerful new models make it easy to find vulnerabilities in software that can then be exploited by hackers – but the Google announcement shows that the growth of AI could have other damaging effects, too.
Google is not the only company to have paused its bug bounty program because the influx of low-effort, often inaccurate reports meant that engineers were too overwhelmed to find and fix actual problems. Earlier this year Linux founder Linus Torvalds said that “the continued flood of AI reports” had made its security work “almost unmanageable”, and last month Intel appeared to close down a similar program that paid up to $100,000 for bugs – though it did not specifically name AI as the cause.