The National Institute of Standards and Technology is asking cybersecurity practitioners how artificial intelligence could help modernize the National Vulnerability Database without sacrificing human review, auditability or trust.

The request for information is on public inspection for Aug. 12 publication and a 60-day response window. It is a question-gathering exercise, not a decision to let an AI system classify or remediate vulnerabilities.

Graphic lists seven areas in NIST's NVD modernization inquiry.
NIST asks about seven areas spanning vulnerability management, dissemination, prioritization, remediation, data, development and the NVD's long-term vision.Boho News graphic from cited primary dataView source

The NVD automatically ingests Common Vulnerabilities and Exposures records in about an hour, according to NIST. Analysts then enrich records with severity scores, affected product versions and other context used by security tools.

NIST organized its questions around seven areas: vulnerability-management processes, information dissemination, prioritization, remediation, data and standards, software-development practices, and a five-year vision for the NVD.

The agency specifically asks which steps are suitable for automation, where human review must remain, and how AI-assisted decisions could be audited and explained.

It also seeks safeguards against incorrect remediation advice. That concern matters because a plausible but wrong recommendation can disrupt a system or leave a real flaw unresolved.

Graphic shows automated CVE intake followed by analyst enrichment and published data.
NVD automation can ingest a CVE record in about one hour before analysts add severity and product-version context.Boho News graphic from cited primary dataView source

NIST says CVE volume rose 263% from 2020 through 2025. Nearly 42,000 records were enriched in 2025, 45% more than the prior year, while submissions in the first quarter of 2026 were nearly one-third higher than a year earlier.

Those growth figures explain the scaling problem but do not prove that any particular AI architecture will solve it. NIST has not selected a model, vendor or automated remediation design, and later action will depend on the evidence it receives.