"The inadequacies of traditional vulnerability management approaches, which center on periodic scanning, static prioritization, and manual remediation, are increasingly apparent," the National Institute for Standards and Technology writes in a request for information the agency is set to publish Wednesday in the Federal Register.
NIST's RFI and the National Vulnerability Database
NIST has opened a formal request for information (RFI) aimed at overhauling its National Vulnerability Database (NVD). The agency describes the NVD as "one of the primary ways the federal government coordinates with security researchers to identify and fix software vulnerabilities." The RFI asks the public for input on how the database and its supporting processes should change to meet an "evolving cybersecurity landscape increasingly shaped by artificial intelligence and machine-consumable security data."
How NIST describes the AI-driven shift
NIST explicitly links the need for change to advances in large language models and other AI tools. The agency says those tools are "becoming more capable of finding and exploiting vulnerabilities at scale" and that AI hacking tools are contributing to recent trends in vulnerability reporting. As a result, NIST sees both a threat and an opportunity: threats in faster, higher-volume disclosure and exploitation; opportunities in rethinking how vulnerability information is produced and shared.

Your scanner finds 4,000 vulns. Which 12 matter?
Nubivance is a Rapid7 Registered Partner delivering vulnerability management as a service - scanning, risk-based prioritization, and remediation follow-through across IT and OT.
Fix the backlogTechnical shortcomings the RFI identifies
The RFI lists concrete problems the NVD faces today: increased volume and complexity of disclosed vulnerabilities; inconsistent data quality across reports; greater reliance on automation and machine-readable security data; and a growing "demand for near real-time vulnerability enrichment" by defenders confronting faster threats. Those gaps, NIST argues, mean the NVD’s current model — centered on periodic scans, static prioritization, and manual remediation — may not scale to the speed and automation of modern attack tools.
Public questions: automation, transparency and remediation
NIST frames its RFI around a set of practical questions intended to shape a larger modernization strategy. Many focus on automation, whether AI-driven or not: how defenders could better leverage automation in the vulnerability reporting process; which capabilities, products, and processes would help get information to stakeholders more quickly; how to build transparency and auditability into AI-driven decisionmaking; and what role AI should play in automated vulnerability remediation. NIST says it wants a "future-ready vulnerability management ecosystem that is continuous, contextual, and automated, while enabling cybersecurity practices to respond appropriately to real-world threats and business priorities."
Gold Eagle, VINCE, and the coordination question
The NIST effort follows other federal moves to address AI-related cyber threats. A month before the RFI, the Trump administration announced a new federal clearinghouse overseen by the Department of the Treasury called "Gold Eagle" for sharing AI threat information between government and the private sector. Separately, the White House partnered with Carnegie Mellon University’s Software Engineering Institute to create the Vulnerability Information and Coordination Environment (VINCE), a system intended to collect and distribute reports on AI-discovered vulnerabilities. The CyberScoop report notes it remains unclear how Treasury’s Gold Eagle clearinghouse will interact with NIST’s NVD or how VINCE and the NVD will coordinate.
What this means for defenders, the Department of the Treasury, and VINCE
- Defenders and security teams: NIST’s RFI signals an expectation that teams will increasingly rely on machine-readable feeds and near real-time enrichment, and that automated tooling — including AI — will need to be auditable and integrated into remediation workflows.
- The Department of the Treasury and Gold Eagle: Treasury’s new clearinghouse adds a second federal channel for AI-related threat sharing; NIST’s effort raises a coordination question about how that clearinghouse will connect to the NVD’s data and processes.
- Carnegie Mellon SEI and VINCE: VINCE is positioned to collect and distribute AI-discovered vulnerability reports; its role alongside the NVD is explicit but the mechanics of interaction remain undefined in the materials NIST has published.
NIST’s RFI invites public input as a first step toward reshaping a decades-old federal coordination mechanism for a faster, more automated era of cyber risk. The agency frames the choice plainly: adapt the NVD to be continuous, contextual, and automated — or risk falling behind the tools that already speed both discovery and exploitation. How respondents and other federal programs such as Gold Eagle and VINCE will shape the final architecture remains the next open question.




