Request for Information (RFI) on Modernizing the National Vulnerability Database in the Age of Artificial Intelligence (NIST — Notice)
United States · NIST 2026-16371
The National Institute of Standards and Technology (NIST) established and operates the National Vulnerability Database (NVD), which provides the U.S. government repository of standards-based vulnerability management data. NIST seeks stakeholder input on opportunities, challenges, and priorities for modernizing the NVD in an evolving cybersecurity landscape increasingly shaped by artificial intelligence (AI) and machine-consumable security data. NIST's goal is to improve the NVD's scalability, automation, interoperability, transparency, and utility.
Technical detail
The National Institute of Standards and Technology (NIST) established and operates the National Vulnerability Database (NVD), which provides the U.S. government repository of standards-based vulnerability management data. NIST seeks stakeholder input on opportunities, challenges, and priorities for modernizing the NVD in an evolving cybersecurity landscape increasingly shaped by artificial intelligence (AI) and machine-consumable security data. NIST's goal is to improve the NVD's scalability, automation, interoperability, transparency, and utility.
Who is protected: See Federal Register notice — auto-imported, specifics pending verification.
Who must comply: See Federal Register notice — auto-imported, specifics pending verification.
Key facts
| Jurisdiction | United States |
|---|---|
| Level | Federal |
| Status | Enacted (not yet in effect) |
| Protection strength | Limited protection |
| Enacted | 2026-08-12 |
| Citation | NIST 2026-16371 |
| Enforced by | NIST |
| Topics | government use of AI · AI disclosure and transparency |
| Last verified | 2026-08-13 |
| Official source | Federal Register — NIST — 2026-16371 ↗ |
More AI rules in United States
- Trump AI Innovation & Security EO (June 2026) · In effect
- FERC order directing PJM and other grid operators to reform · Enacted (not yet in effect)
- Chatrie v. United States (Fourth Amendment protection for lo · Blocked / in litigation
- Kids Internet and Digital Safety Act (KIDS Act) (H.R. 7757) · Proposed / pending
- NAIC AI Evaluation Tool Pilot (12 states, 2026) · Proposed / pending
- FTC Proposed Policy Statement — AI Accuracy (July 2026) · Proposed / pending
Related government use of AI rules elsewhere
- CA EO N-6-26 (AI Workforce) · In effect
- WA SB 5982 (Data Center / Clean Energy) · In effect
- Arkansas public entity AI/ADS policy mandate (Act 848, 2025) · In effect
- One-year moratorium on data center development (Inver Grove Heights MN) · In effect
- San Marcos citywide data center ban (Land Use Matrix amendme · In effect
- Washington County (MD) 12-month data center moratorium · Enacted (not yet in effect)
See something wrong or out of date? Submit a correction — every entry must carry a verifiable official source.