Enterprise security teams operate inside a flood of CVEs, cloud findings, container findings, dependency alerts, identity exposure, configuration weaknesses and threat intelligence. GenAI can become the reasoning and orchestration layer above that telemetry, converting vulnerability data into a defensible remediation queue without pretending that an LLM is itself a vulnerability scanner.
The operating model
A mature AI-assisted program should combine CVSS + EPSS + CISA KEV + asset criticality + external exposure + exploit intelligence + compensating controls + mission consequence. The model then explains why a vulnerability matters, correlates duplicate findings, identifies affected business services, drafts remediation guidance and routes work to the correct owner.
GenAI should not replace vulnerability management. It should become the reasoning and orchestration layer above it.
Open-source security fabric
- OpenVAS / Greenbone for network and infrastructure vulnerability assessment.
- Trivy for containers, repositories, filesystems, Kubernetes and software supply-chain scanning.
- Grype for software and container vulnerability detection, enriched with EPSS and KEV context.
- OWASP Dependency-Track for SBOM-centric component risk and dependency intelligence.
- DefectDojo as an aggregation and workflow layer across heterogeneous security findings.
Commercial risk engines
- Tenable VPR
- Qualys TruRisk
- Rapid7 Active Risk
- Microsoft Defender exposure scoring
The architectural lesson is not to choose AI instead of these platforms. Preserve deterministic scanners and vendor risk engines as evidence producers. Put the AI layer above them where it can normalize language, correlate evidence and explain priority.
Why severity alone is obsolete
NIST reported in April 2026 that CVE submissions increased 263% between 2020 and 2025 and shifted NVD enrichment toward a risk-based model. Vulnerability management has become an attention-allocation problem as much as a scanning problem.
CVSS remains useful for technical severity, but severity is not probability. EPSS estimates exploitation probability over the next 30 days. CISA KEV supplies a different signal: evidence of exploitation in the wild. Neither should stand alone.
AI prioritization pipeline
- Discover: ingest scanner, SBOM, cloud, endpoint, identity and configuration findings.
- Normalize: map assets, CVEs, packages, owners and business services.
- Enrich: add CVSS, EPSS, KEV, exploit intelligence, reachability, exposure and asset criticality.
- Reason: summarize attack paths, explain priority and cluster findings sharing one remediation.
- Act: create tickets, propose patches or mitigations, assign owners and generate executive summaries.
- Verify: rescan, validate closure and retain evidence.
Bounded agency
The AI may recommend. The enterprise remains accountable. Autonomous patching, production configuration changes, vulnerability exceptions and formal risk acceptance should remain behind policy-controlled approval gates unless narrowly and deliberately authorized.
Every recommendation should expose its evidence: scanner source, CVE, affected asset, EPSS value and timestamp, KEV status, business owner, exposure state, compensating controls and rationale. If the AI cannot show its work, it should not determine the queue.
Executive dashboard
Track KEV exposure, exploitable critical paths, internet-facing risk, mean time to remediate by risk tier, aging of mission-critical findings, exception debt, recurrence after remediation and the percentage of high-priority findings with verified ownership.
Bottom line
The next-generation vulnerability program is a decision system. Scanners discover. Threat intelligence supplies context. Risk engines rank. GenAI connects the evidence, explains consequence and accelerates workflow. Humans govern consequential decisions.