NIST is asking the public what should stop an AI-written security fix from being wrong
Question 4(c) is one sentence long. It asks what controls and safeguards are needed to prevent erroneous AI-generated remediations.
That question sits inside a request for information the National Institute of Standards and Technology filed on Tuesday, on modernising the National Vulnerability Database. Comments are open for 60 days after the notice appears in the Federal Register, electronically only. NIST states it will not accept them by post, fax or email.
What the database does now
The NVD is the United States government repository of standards-based vulnerability management data. It ingests Common Vulnerabilities and Exposures records within roughly an hour of publication, automatically. Human analysts then add the parts machines have not been able to supply on their own: severity scores, and which product versions are actually affected.
That second step is where the notice points. Among the trends NIST lists are the growing volume and complexity of disclosed vulnerabilities, a range in the quality of the data, demand for near real-time enrichment, and what the document calls resource constraints associated with scaling vulnerability analysis and enrichment activities.
The threat model is stated in one line
NIST writes that malicious actors may seek to use AI systems to discover and exploit vulnerabilities at scale, and to support activity after they are inside.
The document sets that against the same technology working for the defence, and does not resolve the tension. It says traditional approaches built on periodic scanning, static prioritisation and manual remediation are increasingly inadequate. It does not say what replaces them. That is what it is asking.
Seven groups of questions
The notice is organised into vulnerability management process, dissemination, risk assessment and prioritisation, remediation, data and standards, development processes, and a vision for the database over five years.
The sharpest ones cluster around automation and its limits. Group one asks which tasks are appropriate for AI-enabled automation and which should require human review, and then asks something more specific than it looks: how to arrange that review so that it neither wastes the reviewer's time nor collapses into over-reliance on the machine. Group three asks how transparency and auditability could be enhanced when prioritisation decisions are made by a model. Group four asks what role, if any, AI systems should have in automated remediation, and what organisations and open-source projects would need in place to manage fixes they did not write.
Group five asks whether the existing standards for vulnerability identifiers, product naming and severity scoring are sufficient at all.
What this is not
It is not a rule, a policy, a funding commitment or a plan. A request for information binds nobody and creates no obligation.
What it does is establish, in a citable federal document, that the agency running the country's vulnerability repository considers its current model insufficient for the volume it faces, and is asking industry for the architecture. Responses will inform strategic planning, technical architecture decisions, standards development and data governance, the notice says. The docket is NIST-2026-0100.