Daily Hypernovelty Lead — Infrastructure — September 13, 2026

The Enrichment Started While the Questions Were Still Open

NIST will discuss an NVD agent-enrichment tool on September 17. The RFI still asks which of those tasks need a human reviewer.

A blank enrichment form and unused stamp sit on a records desk between two analog clocks, with stacked papers and an empty chair behind them.

The ingest clock can run in an hour. The enrichment questions are still open until October 13.

NIST has begun work on an AI agentic workflow to aid in the enrichment of vulnerability information provided by NVD, according to an Information Technology Laboratory event page last updated September 1, 2026, which sets a one-hour Zoom session for September 17 at 11:00 a.m. EDT to discuss the approach taken, the architecture of the solution, the issues discovered during implementation, and early results with the use of the tool at the NVD.[1] The page was created August 27. It does not publish those early results, and it does not give a date on which the workflow becomes the NVD of record.

That session is an ITL AI Program webinar titled The Development of an AI Agent Enrichment Workflow at the National Vulnerability Database.[1] Harold Booth and Derek Sappington are listed as technical contacts. Registration questions go to Liliana Rodriguez.[1] The same page still points commenters to the August 12 Request for Information, with comments due October 13, 2026, at 11:59 p.m. Eastern.[1][2]

That RFI is Federal Register document 2026-16371, published August 12 as 91 FR 52042, docket NIST-2026-0100.[2][3] The ACTION line is a notice and request for information. FederalRegister.gov is an unofficial XML copy, so anyone who needs legal notice should use the official edition on govinfo.[2][3] The notice describes the current split in the pipeline. NVD ingests Common Vulnerabilities and Exposures records within approximately an hour of publication using automated processes. NVD analysts then enrich those records with additional information and analysis such as severity scores and affected product versions.[2][3]

And question (1)(b) of that same notice asks which tasks are most appropriate for AI-enabled automation, which tasks should require human review, what information is needed for those reviews, and how reviews can be arranged to minimize time spent and avoid over-reliance on AI.[2][3] Those questions are still open. The webinar language about early results with the use of the tool at the NVD does not answer them, and the RFI is not a final architecture.

Meanwhile the August 12 NIST blog by Harold Booth and Jon Boyens names the tool as V-etalon.[4] "We have already begun work on a tool, called V-etalon, that leverages AI technologies to aid in enriching vulnerability information," they write.[4] They hope it will eventually provide a foundation for the evaluation of vulnerability information, and they say they will look for feedback and collaboration on GitHub once it is available, asking readers to stay tuned for an upcoming release and announcement.[4] That blog does not publish a repository, a field list, or an accuracy figure.

So the public record on September 13 is a pair of clocks that do not wait for each other. Analysts still sit in the RFI as the people who add severity and affected versions after the one-hour ingest. An agentic workflow is already being developed to aid that enrichment, and NIST will talk about implementation issues on September 17. Commenters still have until October 13 to say which of those tasks should require a human reviewer and what that reviewer would need to see. August coverage of the same RFI is in The Patch Queue Needs a Judge.[5] The named workflow and the September 17 discussion are the new public facts. They do not close question (1)(b).

This remains a webinar announcement plus an open comment request. It creates no duty to change a local triage rule, no completed evaluation of V-etalon, and no proof that a named CVE was enriched by the agent. This is orientation, not cybersecurity, legal, procurement, or investment advice.

Verification bottleneck

This scarce check is whether a named CVE's enrichment fields can be shown to have come from an analyst, from the agentic workflow, or from both, before anyone treats the September 17 session as a completed change to the NVD of record.

  • Discovery and CVE ingest can still move in about an hour. The webinar is about aiding the enrichment layer that currently follows that ingest.
  • NVD users, product owners, and later commenters would have to verify which fields the tool touched, who reviewed them, and whether the RFI's human-review question was answered in the architecture talk or only postponed.
  • Watch the September 17 session for a field list and a review step, the still-upcoming GitHub announcement for V-etalon, and whether October 13 comments address question (1)(b) against a tool that NIST has already begun.

Opportunities

So a one-record enrichment worksheet is where value may appear. For a single CVE it would record the identifier, the ingest time if known, which enrichment fields a team currently trusts (severity, affected versions, others), whether those fields are attributed to an analyst or left unlabeled, what a reviewer would need to see to accept an agent-aided value, and which RFI question (1)(b) that record actually answers. Patch decisions stay with the asset owner. Idea fodder only.

A lighter companion is a webinar capture card for September 17: architecture named, issues admitted, early-result claim, whether V-etalon is shown, and whether any human-review step is described.

Sources

[1] NIST, "ITL AI Webinar: The Development of an AI Agent Enrichment Workflow at the National Vulnerability Database," event page created August 27, 2026, updated September 1, 2026. https://www.nist.gov/news-events/events/2026/09/itl-ai-webinar-development-ai-agent-enrichment-workflow-national

[2] National Institute of Standards and Technology, "Request for Information (RFI) on Modernizing the National Vulnerability Database in the Age of Artificial Intelligence," 91 FR 52042, August 12, 2026, FR Doc. 2026-16371. https://www.federalregister.gov/documents/2026/08/12/2026-16371/request-for-information-rfi-on-modernizing-the-national-vulnerability-database-in-the-age-of

[3] Official PDF, 91 FR 52042. https://www.govinfo.gov/content/pkg/FR-2026-08-12/pdf/2026-16371.pdf

[4] Harold Booth and Jon Boyens, "Shaping the NVD for the Future: We Need Your Feedback on AI-Enabled Vulnerability Management," NIST Cybersecurity Insights, August 12, 2026. https://www.nist.gov/blogs/cybersecurity-insights/shaping-nvd-future-we-need-your-feedback-ai-enabled-vulnerability

[5] Jordan Finneseth, "The Patch Queue Needs a Judge," Hypernovelty Institute, August 13, 2026. https://hypernovelty.institute/articles/the-patch-queue-needs-a-judge/