Driven by AI-augmented research and scanning, vulnerability volumes continue to surge, driving the National Institute of Standards and Technology to ask whether AI could be the answer.
August 14, 2026
The National Institute of Standards and Technology is seeking guidance on the future of the National Vulnerability Database (NVD) and to what degree AI should be integrated into its management of the service and the enrichment of data on software flaws.
On August 12, the US agency posted a request for public comment on six areas of the NVD's operations — including the vulnerability management process and risk prioritization — as well as the overall vision for the repository of vulnerability data. The "Request for Information (RFI) on Modernizing the National Vulnerability Database in the Age of Artificial Intelligence" comes as the agency is dealing with a massive influx of vulnerabilities, partly caused by AI enabling researchers to investigate and discover flaws at a faster pace.
"Today's vulnerability management ecosystem is rapidly evolving and is characterized by AI-enabled cyber tools and accelerated technology delivery cycles," the agency stated in the RFI. "Malicious actors may seek to leverage AI systems to discover and exploit vulnerabilities at scale and to support post-exploitation activities. The inadequacies of traditional vulnerability management approaches, which center on periodic scanning, static prioritization, and manual remediation, are increasingly apparent."






