{"slug": "nist-wants-to-overhaul-its-vulnerability-database-for-the-ai-age", "title": "NIST wants to overhaul its vulnerability database for the AI age", "summary": "The National Institute of Standards and Technology (NIST) is seeking public input on overhauling its National Vulnerability Database (NVD) to address challenges posed by artificial intelligence and machine-consumable security data. In a request for information set to publish Wednesday in the Federal Register, NIST cites increased volume and complexity of disclosed vulnerabilities, inconsistent data quality, and demand for near real-time vulnerability enrichment as trends driven by AI hacking tools. NIST asks for insight on integrating automation, improving dissemination, and building transparency into AI-driven decisionmaking.", "body_md": "# NIST wants to overhaul its vulnerability database for the AI age\n\nThe National Institute for Standards and Technology is looking for input on how to overhaul its vulnerability reporting process to better meet the challenges of an “evolving cybersecurity landscape increasingly shaped by artificial intelligence and machine-consumable security data.”\n\nIn a [request for information](https://public-inspection.federalregister.gov/2026-16371.pdf?utm_campaign=pi+subscription+mailing+list&utm_medium=email&utm_source=federalregister.gov) set to publish Wednesday in the Federal Register, NIST said its [National Vulnerability Database](https://nvd.nist.gov/), one of the primary ways the federal government coordinates with security researchers to identify and fix software vulnerabilities, must be updated for the AI age.\n\nNIST is concerned that as large language models become more capable of finding and exploiting vulnerabilities at scale, the NVD’s process must be updated.\n\n“The inadequacies of traditional vulnerability management approaches, which center on periodic scanning, static prioritization, and manual remediation, are increasingly apparent,” the RFI states.\n\nNIST believes AI hacking tools are contributing to recent trends in vulnerability reporting. The NVD has seen increased volume and complexity of disclosed vulnerabilities, inconsistent data quality, increased reliance on automation and machine-readable security data, and “demand for near real-time vulnerability enrichment” from defenders facing faster threats.But NIST believes these challenges also present an “opportunity to transform the vulnerability management ecosystem” through proactive reforms and NVD innovation.\n\nThat’s where the public comes in. NIST is posing a series of questions that must be answered before a larger strategy can be developed. Many of their questions focus on better integrating automation – AI or otherwise – into the process.\n\nThe agency asked for insight on how defenders could better leverage automation in the vulnerability reporting process; which capabilities, products and processes would help more quickly disseminate information to stakeholders, how to build transparency and auditability into AI-driven decisionmaking, and what role AI should play in automated vulnerability remediation.\n\n“NIST intends to support a future-ready vulnerability management ecosystem that is continuous, contextual, and automated, while enabling cybersecurity practices to respond appropriately to real-world threats and business priorities,” the RFI states.\n\nThe NIST effort to revamp its vulnerability database comes a month after the Trump administration rolled out[ a new federal clearinghouse](https://cyberscoop.com/trump-gold-eagle-ai-cyber-clearinghouse/), overseen by the Department of Treasury, for sharing AI threat information between government and the private sector called “Gold Eagle.”\n\nIt’s not clear how Treasury’s process will interact with NIST’s database. The White House also partnered with Carnegie Mellon’s Software Engineering Institute to create the [Vulnerability Information and Coordination Environment](https://kb.cert.org/vince/), (VINCE) which will collect and distribute reports on AI-discovered vulnerabilities.", "url": "https://wpnews.pro/news/nist-wants-to-overhaul-its-vulnerability-database-for-the-ai-age", "canonical_source": "https://cyberscoop.com/nist-national-vulnerability-database-ai-overhaul/", "published_at": "2026-08-11 15:36:02+00:00", "updated_at": "2026-08-11 15:46:17.267103+00:00", "lang": "en", "topics": ["ai-policy", "ai-safety", "artificial-intelligence"], "entities": ["National Institute of Standards and Technology", "National Vulnerability Database", "Federal Register", "Department of Treasury", "Carnegie Mellon's Software Engineering Institute", "Vulnerability Information and Coordination Environment"], "alternates": {"html": "https://wpnews.pro/news/nist-wants-to-overhaul-its-vulnerability-database-for-the-ai-age", "markdown": "https://wpnews.pro/news/nist-wants-to-overhaul-its-vulnerability-database-for-the-ai-age.md", "text": "https://wpnews.pro/news/nist-wants-to-overhaul-its-vulnerability-database-for-the-ai-age.txt", "jsonld": "https://wpnews.pro/news/nist-wants-to-overhaul-its-vulnerability-database-for-the-ai-age.jsonld"}}