NIST has opened a request for information on modernizing the National Vulnerability Database for a security ecosystem shaped by AI and machine-readable data

NIST RFI: Rebuilding the NVD for AI-Era Security. The Leveraged Years regulation briefing card.

A request for information imposes nothing. What makes this one worth reading is where NIST chose to put the questions: on human review, on AI-generated fixes, and on who is accountable when a machine decides what to patch first.

The short version

Bottom line: Non-binding. This is a Notice and Request for Information under 15 U.S.C. 272(b), (c) and 278g-3. It creates no obligation for any organization, and NIST says responses will inform future strategic planning, technical architecture decisions and standards development.

Who this affects: Chief information security officers and vulnerability management leads; security tool vendors and CVE Numbering Authorities; open source maintainers; compliance officers whose control frameworks cite NVD severity data.

Issue date: Published August 12, 2026 at 91 FR 52042, filed August 11, 2026. Comments must be received on or before October 13, 2026 at 11:59 p.m. Eastern Time.

What changed: Nothing operational. NIST has opened a formal consultation on how the NVD should be rebuilt, organized into seven question groups covering process, dissemination, prioritization, remediation, data standards, development processes and a five-year vision.

Analysis: The most consequential questions are the ones about restraint. NIST asks which tasks should require human review, how reviews can be arranged to avoid over-reliance on AI, and what controls prevent erroneous AI-generated remediations. Those framings tend to survive into the guidance that follows.

Primary sources: Federal Register notice, 91 FR 52042

Instrument (EN)
Request for Information (RFI) on Modernizing the National Vulnerability Database in the Age of Artificial Intelligence
Authority
Information Technology Laboratory, National Institute of Standards and Technology, U.S. Department of Commerce
Jurisdiction
United States
Status
Open consultation
Bindingness
Non-binding. A request for information creates no legal obligation
Issue date / next deadline
Published August 12, 2026. Comments due October 13, 2026, 11:59 p.m. Eastern Time
Docket
NIST-2026-0100 on regulations.gov; Docket Number 260805-0401
Citation
91 FR 52042, FR Doc. 2026-16371
Primary source
https://www.federalregister.gov/documents/2026/08/12/2026-16371/request-for-information-rfi-on-modernizing-the-national-vulnerability-database-in-the-age-of

What NIST says is wrong with the current model

The notice sets out the baseline first. The NVD ingests Common Vulnerabilities and Exposures records within roughly an hour of publication using automated processes, and analysts then enrich those records with severity scores, affected product versions and other analysis.

Then it names the strain. NIST writes that the inadequacies of traditional vulnerability management approaches, which center on periodic scanning, static prioritization and manual remediation, are increasingly apparent.

It lists the pressures behind that judgment: growth in the volume and complexity of disclosed vulnerabilities, variable data quality, greater reliance on machine-readable security data, AI-assisted discovery and triage, demand for near real-time enrichment, and resource constraints on scaling analysis.

The threat framing is explicit

NIST does not treat AI here as a neutral efficiency story. The notice states that malicious actors may seek to leverage AI systems to discover and exploit vulnerabilities at scale and to support post-exploitation activities.

That sits alongside the opportunity framing, where NIST says it intends to support a vulnerability management ecosystem that is continuous, contextual and automated while still letting security practice respond to real-world threats and business priorities.

Both framings appear in the same section, which is a fair signal of how the eventual guidance is likely to read.

The questions that matter most for governance

Question group one asks where the biggest bottlenecks sit, which tasks are appropriate for AI-enabled automation, which should require human review, and what information a reviewer needs so that reviews minimize time spent without producing over-reliance on AI. It also asks about novel governance and risk management considerations.

Group four is the sharpest for anyone running an engineering organization. It asks what role, if any, AI systems should have in automated vulnerability remediation, what organizational structures and policies are needed to manage AI-generated remediations, and what controls and safeguards prevent erroneous ones.

Group three asks how transparency and auditability in AI-driven prioritization decisions might be enhanced. If your risk committee has ever accepted a machine-ranked patch queue without asking how the ranking was produced, that question is aimed at you.

Data and standards get their own section

Group five asks whether existing standards for vulnerability data are sufficient for actionable prioritization in the AI era, naming vulnerability identifiers, product naming schemes and severity scoring systems specifically.

Product naming is the quiet one. Anyone who has tried to match a CVE to an installed package across a large estate knows that identifier quality, not severity scoring, is usually what breaks automation.

Group seven asks respondents to describe the value the NVD has actually delivered, what capabilities should be added over the next five years, and what metrics should track whether modernization worked.

How to respond

Comments go through the Federal e-Rulemaking Portal only. Search NIST-2026-0100 on regulations.gov, use the comment function, and include the document number and title in the subject field.

NIST states it will not accept comments by postal mail, fax or email, and asks that comments be submitted only once. Relevant comments received by the deadline will be posted publicly without change or redaction, so confidential business information should stay out.

Respondents are encouraged to address any or all of the questions. There is no requirement to answer all seven groups.

What we did not verify

Opened: the complete Federal Register text of FR Doc. 2026-16371 published August 12, 2026 at 91 FR 52042, including the summary, dates, addresses, supplementary information and all seven question groups, retrieved from the Government Publishing Office full text feed.

Not opened: the regulations.gov docket NIST-2026-0100 itself, any comments filed to date, and NIST's prior NVD program communications.

We do not claim NIST has decided to introduce AI into NVD enrichment, nor that any change to the NVD is scheduled. The notice asks questions and does not announce a program.

Key compliance takeaway

If your security program depends on NVD enrichment, this is the cheapest chance you will get to say what breaks in practice. The deadline is October 13, 2026 and the mechanism is a single portal submission. Note also that the questions NIST asks about human review and erroneous AI-generated fixes are the ones most likely to reappear as expectations in later guidance.

Source File

https://www.federalregister.gov/documents/2026/08/12/2026-16371/request-for-information-rfi-on-modernizing-the-national-vulnerability-database-in-the-age-of

Open the Federal Register notice at 91 FR 52042 and confirm the August 12, 2026 publication date, the October 13, 2026 comment deadline at 11:59 p.m. Eastern, and docket NIST-2026-0100.

Malicious actors may seek to leverage AI systems to discover and exploit vulnerabilities at scale and to support post-exploitation activities. * NIST, Request for Information on Modernizing the National Vulnerability Database in the Age of Artificial Intelligence, 91 FR 52042, August 12, 2026

FAQ

Does this RFI require anything of my organization?

No. It is a request for information issued under 15 U.S.C. 272(b), (c) and 278g-3. NIST says responses are intended to inform future planning, architecture decisions, standards development and data governance approaches.

When and how do comments have to be filed?

By October 13, 2026 at 11:59 p.m. Eastern Time, electronically through regulations.gov under docket NIST-2026-0100. NIST states it will not accept postal mail, fax or email submissions.

Will my comment be published?

Yes. NIST says all relevant comments received by the deadline will be posted at regulations.gov without change or redaction, so personal or confidential business information should be excluded.

Is NIST proposing to automate NVD analysis with AI?

The notice does not propose that. It asks which tasks are appropriate for AI-enabled automation, which should require human review, and what safeguards would prevent erroneous AI-generated remediations.

Sponsored Training

Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.

."}}]}