The National Institute of Standards and Technology is asking cybersecurity practitioners how artificial intelligence could help modernize the National Vulnerability Database without sacrificing human review, auditability or trust.
The request for information is on public inspection for Aug. 12 publication and a 60-day response window. It is a question-gathering exercise, not a decision to let an AI system classify or remediate vulnerabilities.

The NVD automatically ingests Common Vulnerabilities and Exposures records in about an hour, according to NIST. Analysts then enrich records with severity scores, affected product versions and other context used by security tools.
NIST organized its questions around seven areas: vulnerability-management processes, information dissemination, prioritization, remediation, data and standards, software-development practices, and a five-year vision for the NVD.
The agency specifically asks which steps are suitable for automation, where human review must remain, and how AI-assisted decisions could be audited and explained.
It also seeks safeguards against incorrect remediation advice. That concern matters because a plausible but wrong recommendation can disrupt a system or leave a real flaw unresolved.

NIST says CVE volume rose 263% from 2020 through 2025. Nearly 42,000 records were enriched in 2025, 45% more than the prior year, while submissions in the first quarter of 2026 were nearly one-third higher than a year earlier.
Those growth figures explain the scaling problem but do not prove that any particular AI architecture will solve it. NIST has not selected a model, vendor or automated remediation design, and later action will depend on the evidence it receives.
