{"slug": "nist-asks-industry-what-to-do-about-ai-and-vulnerabilities", "title": "NIST asks industry what to do about AI and vulnerabilities", "summary": "The US National Institute of Standards and Technology (NIST) is asking industry for input on how to handle the growth and complexity of vulnerabilities, driven by AI, as it prepares further changes to its vulnerability database. The request for information (RFI) notes that traditional vulnerability management approaches are inadequate and that AI presents an opportunity to transform the ecosystem. This follows NIST's announcement that it will stop enriching all CVEs submitted to the National Vulnerability Database (NVD) in April 2026, after seeing a 264% increase in submissions between 2020 and 2025.", "body_md": "[NIST](/tag/nist/)\n\nThe US National Institute of Standards and Technology (NIST) is prepping further changes to its vulnerability database in response to the AI-powered increase in vulnerabilities.\n\nThe government-backed organisation is taking the issue to the private sector, publishing a request for information on how it should tackle the growth and complexity of vulnerabilities and demand for “near real-time” enrichment.\n\nThe RFI said: “The inadequacies of traditional vulnerability management approaches, which center on periodic scanning, static prioritization, and manual remediation, are increasingly apparent… The advancement of AI presents an opportunity to transform the vulnerability management ecosystem.”\n\nIt comes a few months after NIST said it would no longer enrich all CVEs submitted to the NVD in April 2026, after seeing [ a 264% increase](https://www.thestack.technology/overstretched-nist-to-limit-cve-enrichments/) in submissions between 2020 and 2025.\n\nIts enrichment process involves adding reference tags, a common weakness enumeration identifier (CWE), and flagging software that is particularly vulnerable to the vulnerability.\n\n**A backlog**\n\n## Get the full story: Subscribe for free\n\nJoin peers managing over $100 billion in annual IT spend and subscribe to unlock full access to The Stack’s analysis and events.\n\n[Subscribe now](https://www.thestack.technology/membership/)\n\nAlready a member? [Sign in](https://www.thestack.technology/signin/)", "url": "https://wpnews.pro/news/nist-asks-industry-what-to-do-about-ai-and-vulnerabilities", "canonical_source": "https://www.thestack.technology/nist-asks-industry-what-to-do-about-ai-and-vulnerabilities/", "published_at": "2026-08-13 14:12:38+00:00", "updated_at": "2026-08-13 14:36:32.712311+00:00", "lang": "en", "topics": ["ai-policy", "ai-infrastructure"], "entities": ["National Institute of Standards and Technology", "NIST", "National Vulnerability Database"], "alternates": {"html": "https://wpnews.pro/news/nist-asks-industry-what-to-do-about-ai-and-vulnerabilities", "markdown": "https://wpnews.pro/news/nist-asks-industry-what-to-do-about-ai-and-vulnerabilities.md", "text": "https://wpnews.pro/news/nist-asks-industry-what-to-do-about-ai-and-vulnerabilities.txt", "jsonld": "https://wpnews.pro/news/nist-asks-industry-what-to-do-about-ai-and-vulnerabilities.jsonld"}}