GovKM
AI-Generated Evidence Saturation and Verification Capacity

Synthetic Evidence Can Disable a Knowledge Institution

Google’s pause on new OSS VRP product-vulnerability reports shows how large volumes of mostly invalid automated claims can exhaust expert verification capacity and disable an evidence intake channel without corrupting the underlying knowledge base.
Continuity process diagram representing large volumes of automated vulnerability reports overwhelming a human verification pipeline and reducing the institution’s ability to distinguish actionable evidence from invalid claims.
Expand image

A knowledge institution can fail even when none of its records have been corrupted.

Effective October 1, 2026, Google stopped accepting new product-vulnerability submissions through its Open Source Software Vulnerability Reward Program. Existing reports and supply-chain reports remain in scope. Google says the pause is temporary and that it intends to provide an update in the first quarter of 2027.

The immediate reason is verification capacity. Google said the program had experienced a significant rise in automated submissions and that the vast majority were not valid. This did not emerge overnight. In March 2026, Google had already revised OSS VRP requirements after what it described as a massive surge in AI-generated reports containing incorrect information, hallucinated exploitability, or technically real coding issues with negligible security impact.

The continuity failure

A vulnerability report is a claim, not yet authoritative evidence. The intake process must preserve a chain from Source / researcher or automation → Evidence / reproducible technical finding → Authority / expert validation → Decision / triage and remediation.

When generated submissions arrive faster than authoritative reviewers can validate them, the Source → Evidence boundary becomes saturated. The records may all be syntactically well formed. Some may even describe real code. But the institution cannot efficiently determine which claims are reproducible, reachable, material, novel, and worth scarce engineering attention.

The GovKM interpretation

This is an epistemic denial-of-service problem. Synthetic evidence does not have to poison the database to degrade the institution. It only has to consume enough verification capacity that authoritative review becomes the bottleneck.

Google’s March response raised the evidence threshold by requiring stronger proof for parts of the program. The October pause shows that evidence-quality rules alone were not enough to preserve the operating capacity of the intake channel under sustained automated volume.

The continuity lesson is that evidence systems must preserve not only provenance, but the cost and state of qualification. A submitted claim should carry reproducibility, supporting artifacts, duplicate status, model or automation disclosure where relevant, and the evidence needed to establish impact before it consumes high-cost expert authority.

Continuity path: Source / researcher or automated system → Evidence / vulnerability claim and proof → Authority / security triage → Context / project threat model and reachable code → Decision / accept, reject, or prioritize → Action / remediation → Record / validated case → Institutional Memory / vulnerability corpus → Future Reuse / defensive learning.

Why the pause matters

Google has not abandoned vulnerability disclosure. Supply-chain reports remain open, previous cases continue, and researchers are directed to other Google VRPs or the Patch Rewards Program where appropriate. The important institutional fact is narrower: one evidence channel became sufficiently costly to verify that Google temporarily stopped accepting a class of new claims.

That is a continuity failure at the boundary between evidence generation and authoritative attention.

Sources

Google Bug Hunters, Google Open Source Software Vulnerability Reward Program Rules, current October 5, 2026. https://bughunters.google.com/about/rules/open-source/google-open-source-software-vulnerability-reward-program-rules

Google Bug Hunters, Streamlining Google’s OSS VRP: Key Rule Updates, March 19, 2026. https://bughunters.google.com/blog/ossvrp-rule-updates-2026

TechCrunch, Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions, October 4, 2026. https://techcrunch.com/2026/10/04/google-froze-its-open-source-bug-bounty-program-due-to-a-significant-rise-in-ai-submissions/

RELATED KNOWLEDGE

Continue Exploring

Explore related research, framework domains, and continuity concepts.
CONTINUE WITH THE FRAMEWORK

Explore the continuity relationships that support trustworthy organizational intelligence.

Continue through the GovKM Framework to examine the doctrine, knowledge, and implementation guidance behind Organizational Continuity.