NIST opens a request for information on modernizing the vulnerability database for AI

On August 12, 2026 the National Institute of Standards and Technology published a notice in the Federal Register titled “Request for Information (RFI) on Modernizing the National Vulnerability Database in the Age of Artificial Intelligence.” The status is worth stating plainly: this is a notice and request for information, not a proposed rule and not a standard. Nothing binds anyone. It is the stage at which an agency decides what a future framework should ask for, which is precisely when comments have leverage. Comments must be received on or before October 13, 2026 at 11:59 p.m. Eastern Time, submitted electronically through regulations.gov under docket number NIST-2026-0100, and all comments will be posted publicly without redaction.

The NVD is the US government’s repository of standards-based vulnerability management data, and NIST frames the modernization objectives as scalability, automation, interoperability, transparency, and utility. The RFI asks where AI-enabled automation belongs in the vulnerability management lifecycle, which tasks still warrant human oversight, and what governance is needed around AI-driven systems inside that pipeline. It also asks about integrating AI tooling earlier, into technology development processes, so that vulnerabilities are identified and remediated proactively rather than catalogued after the fact.

A second cluster of questions is about the data itself being machine-consumable. NIST asks whether existing vulnerability identifiers, product naming schemes, and severity scoring systems are sufficient to support actionable prioritization in an AI era, which puts the long-standing CVE and CPE conventions explicitly on the table. It also raises capacity: NVD analysts currently enrich CVE records within roughly one hour using automated processes, and the RFI asks what modernization would be needed to hold that under growing volume and near real-time expectations.

The reason this matters beyond the security team is the direction of pressure. AI systems are now both the consumer of this data, in the form of agents doing triage and remediation at machine speed, and a driver of the volume problem, as automated discovery raises the rate at which vulnerabilities are reported. An RFI asking whether the identifiers and scoring schemes themselves need to change is an early signal that the interfaces security tooling has depended on for two decades are open for revision. Vendors whose products consume NVD data have until October 13, 2026 to say what they need.