golden eagle ai policy - an ai art by Vladimir Tsakanyan

The Vulnerability State: Who Controls the AI Infrastructure of Cybersecurity?

Washington is building an AI-powered system to identify, validate and prioritize software vulnerabilities. At the same moment, a critical vulnerability in an AI infrastructure framework has entered active exploitation. The emerging question is no longer simply how governments patch software — but who gets to decide which vulnerabilities become national-security priorities.

By Vladimir Tsakanyan, PhD | Director, Center for Cyber Diplomacy and International Security

The New Battle Is Over Information

For decades, cybersecurity policy has operated around a relatively simple sequence:

discover → disclose → patch.

A vulnerability is discovered. Researchers notify a vendor. The vendor develops a fix. Governments and companies distribute the warning. Administrators install the patch.

That model is beginning to break.

The volume of software vulnerabilities is expanding faster than organizations can analyze and remediate them. Artificial intelligence is accelerating both sides of the equation: AI can help defenders discover vulnerabilities, but it can also help attackers identify weaknesses and develop exploitation techniques at unprecedented speed.

Washington’s response is increasingly moving beyond traditional vulnerability databases.

The U.S. government has launched Gold Eagle, an AI-enhanced vulnerability clearinghouse intended to ingest, validate and deduplicate AI-generated vulnerability reports and coordinate remediation. The initiative was created under a June executive order and launched in July. CISA says the system is intended to reduce risk to essential software and critical infrastructure.

But on August 18, cybersecurity experts were already questioning whether the system can operate at the scale its proponents envision.

That skepticism may actually reveal something more important than the technical debate.

The United States is beginning to construct an information layer above the vulnerability ecosystem.

And whoever controls that layer gains a new form of cyber power.

From Vulnerability Database to Vulnerability Governance

The traditional vulnerability database is essentially an information service.

It tells the world that a vulnerability exists.

The emerging model is different.

An AI-enabled clearinghouse could potentially decide:

  • which vulnerability deserves immediate attention;
  • which vulnerabilities are duplicates;
  • which reports are credible;
  • which software products are affected;
  • which organizations are exposed;
  • which vulnerabilities pose systemic risk;
  • and which patches should receive priority.

That is no longer simply information management.

It is risk governance.

Gold Eagle is intended to coordinate vulnerability discovery, validation and remediation, while helping prioritize the most dangerous vulnerabilities.

The distinction matters.

A vulnerability database answers:

“What is vulnerable?”

A vulnerability-governance system increasingly attempts to answer:

“What should the state care about first?”

That is a fundamentally different political function.

The AI Problem Arrives at Exactly the Wrong Time

The urgency is illustrated by today’s news.

CISA has added CVE-2025-62593, a critical code-injection vulnerability affecting the open-source Ray framework, to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. Ray is used for distributed computing and AI/ML workloads. Federal civilian agencies have been given an August 20 remediation deadline.

The irony is difficult to miss.

The government is building AI systems to help manage the vulnerability crisis while the infrastructure used to build and operate AI itself is becoming part of that crisis.

This is not an isolated contradiction.

AI systems increasingly depend on enormous software supply chains:

models → frameworks → libraries → containers → APIs → cloud infrastructure → GPUs → orchestration systems → data pipelines

Every layer introduces dependencies.

Every dependency creates potential vulnerabilities.

And every vulnerability can propagate through the AI ecosystem.

The cybersecurity perimeter is therefore moving.

It is no longer sufficient to protect the organization that operates the AI system.

The infrastructure underneath the AI system must also be secure.

The End of the Patch Queue

There is another problem.

For years, organizations have treated vulnerability remediation as a queue.

Critical vulnerabilities go first.

Medium vulnerabilities go later.

Low-risk vulnerabilities wait.

But AI changes the economics of exploitation.

According to reporting published today, researchers have warned that attackers can use AI to develop exploits for newly discovered vulnerabilities extremely quickly, while patching continues to lag. Cybersecurity experts cited by Cybersecurity Dive argue that remediation must accelerate accordingly.

This creates a dangerous asymmetry.

Discovery is becoming machine-speed.

Exploitation is becoming machine-speed.

Remediation remains organizational-speed.

The result is a widening gap between the speed at which a vulnerability can become dangerous and the speed at which institutions can respond.

Gold Eagle is therefore attempting to solve a genuine problem.

But the mechanism raises another question:

Can a centralized government system move faster than a decentralized global software ecosystem?

The Limits of Centralization

The strongest criticism of Gold Eagle is not that the idea is unnecessary.

It is that the problem may be too distributed for a single clearinghouse to solve.

Cybersecurity researchers operate globally.

Software developers operate globally.

Open-source projects operate globally.

Companies scan their own infrastructure.

Governments scan their networks.

Security vendors operate their own vulnerability intelligence platforms.

And independent researchers continuously discover vulnerabilities outside any centralized coordination mechanism.

Experts quoted by Cybersecurity Dive noted that voluntary participation limits the clearinghouse’s ability to coordinate the entire ecosystem. Researchers outside the system will continue discovering and reporting vulnerabilities independently.

That produces a paradox.

The more successful Gold Eagle becomes, the more information it must process.

But the more information it must process, the more difficult centralized coordination becomes.

The system therefore risks becoming another layer in an already fragmented cybersecurity architecture.

The Real Question: Who Sets Priority?

There is, however, a deeper issue.

Suppose tomorrow an AI system identifies 100,000 vulnerabilities.

Which ten deserve immediate government attention?

The answer is not purely technical.

It depends on:

  • economic consequences;
  • military significance;
  • critical infrastructure exposure;
  • intelligence value;
  • exploitation probability;
  • geopolitical context;
  • concentration of affected systems;
  • availability of mitigations;
  • and potential cascading effects.

In other words, vulnerability prioritization contains political judgments.

A vulnerability affecting a widely deployed consumer application may affect millions of people.

A vulnerability affecting a small industrial-control system may affect far fewer users but threaten a power plant.

A vulnerability in a defense contractor’s software may have little public visibility but enormous strategic significance.

There is no universal mathematical formula for deciding which one matters most.

At some point, cybersecurity becomes national-security policy.

And that is where the Gold Eagle experiment becomes particularly interesting.

The Birth of a Vulnerability State

The modern state has historically exercised power through territory.

Then it began exercising power through information.

Now it is beginning to exercise power through information prioritization.

That is different.

The state does not need to own every vulnerability database.

It does not need to control every security researcher.

It only needs to become authoritative enough that its prioritization decisions influence everyone else.

If governments, technology companies, critical infrastructure operators and security vendors begin treating an AI-generated vulnerability priority list as authoritative, the system becomes more than a technical platform.

It becomes infrastructure.

And infrastructure creates power.

This is the potential emergence of what could be called the Vulnerability State:

a governance architecture in which governments use automated systems to determine which weaknesses in the digital environment deserve immediate collective attention.

The concept is still emerging.

But the policy direction is already visible.

The Geopolitical Dimension

The consequences extend beyond the United States.

Software is global.

A vulnerability discovered in an American-developed open-source framework can affect European hospitals, Asian manufacturers, African financial institutions and government systems across multiple continents.

Whoever controls the coordination mechanism therefore possesses influence beyond national borders.

This creates an international question:

Should vulnerability prioritization become a national function or an international one?

The existing cybersecurity system is already fragmented between national governments, private companies, international organizations, standards bodies and independent researchers.

AI could intensify that fragmentation.

The United States could develop Gold Eagle.

The European Union could build its own vulnerability-intelligence infrastructure.

China could develop a state-centered system.

Other governments could create regional mechanisms.

The world could eventually face not one vulnerability information architecture, but several competing ones.

And then the question becomes diplomatic.

Which vulnerability assessment should governments trust?

Whose AI determines risk?

Whose data is used?

Who gets early access?

Who receives warnings first?

Who decides whether a vulnerability should be disclosed publicly or temporarily withheld?

These are no longer purely cybersecurity questions.

They are questions of digital sovereignty.

The Disclosure Dilemma

There is an additional tension.

Cybersecurity depends upon disclosure.

But national security sometimes depends upon secrecy.

If an AI system identifies a vulnerability in software used by critical infrastructure, immediate public disclosure could help defenders.

It could also alert attackers.

If the vulnerability has intelligence value, governments may have incentives to keep it secret.

If private companies discover it first, they may have different incentives.

If researchers discover it independently, they may favor disclosure.

Gold Eagle therefore enters an already difficult three-way relationship:

security → transparency → national interest

AI does not eliminate that conflict.

It may make the conflict faster.

From CVE Numbers to Strategic Assets

For years, vulnerability identifiers appeared to be administrative artifacts.

A CVE number was simply a way of giving a weakness an identity.

That era is changing.

A vulnerability identifier can now become the starting point for:

  • threat intelligence;
  • exploit development;
  • patch prioritization;
  • regulatory action;
  • government directives;
  • procurement decisions;
  • insurance assessments;
  • national-security warnings.

The information surrounding a vulnerability is therefore becoming economically and strategically valuable.

The future cybersecurity competition may involve not only discovering vulnerabilities first, but understanding their systemic significance first.

That distinction is crucial.

Discovery creates knowledge.

Prioritization creates power.

The AI Paradox

The emerging AI security architecture contains a fundamental paradox.

AI is being deployed to solve the vulnerability problem.

But AI itself expands the vulnerability problem.

AI accelerates software development.

AI accelerates vulnerability discovery.

AI accelerates exploit development.

AI accelerates defensive analysis.

AI also expands the amount of software that organizations must secure.

The system therefore feeds itself.

More AI produces more software.

More software produces more attack surface.

More attack surface produces more vulnerabilities.

More vulnerabilities require more AI-assisted analysis.

The solution becomes part of the problem.

This is not necessarily a reason to slow AI adoption.

It is a reason to recognize that cybersecurity has become an AI infrastructure problem, not merely an AI application problem.

The Ray Warning

Today’s Ray vulnerability should therefore be read as more than another entry in CISA’s vulnerability catalog.

It is a signal about where the next generation of cyber risk is moving.

AI infrastructure is no longer an experimental layer sitting outside mainstream cybersecurity policy.

It is becoming part of the operational foundation of government, business, research and national security.

When an AI framework becomes actively exploitable, the question is no longer simply whether a developer should patch it.

The question is how deeply that framework has penetrated the infrastructure of the digital economy.

That is precisely the kind of systemic question that a vulnerability-governance architecture is supposed to answer.

The Coming Competition Over Cybersecurity Intelligence

Gold Eagle may succeed.

It may fail.

It may become another government platform with limited adoption.

Or it may evolve into something much more consequential.

But the direction is clear.

Governments increasingly want to move from receiving cybersecurity information to organizing cybersecurity information at machine scale.

That transition deserves attention.

Because the next generation of cyber power may not belong exclusively to whoever has the best offensive tools or the strongest defensive networks.

It may belong to whoever has the best understanding of where the digital system is weakest.

The decisive capability may become the ability to see the vulnerability landscape as a whole.

And then decide what matters.

A New Layer of Cyber Sovereignty

The Internet created an environment in which vulnerabilities are discovered everywhere, software is developed everywhere, and attacks can originate anywhere.

National governments are now attempting to build mechanisms capable of making that environment legible.

Gold Eagle is one early experiment.

The larger transformation is more important.

Cybersecurity is moving from protection of systems toward governance of systemic risk.

That means vulnerability information itself is becoming a strategic resource.

The central question of the next decade may therefore not be:

Who can hack the system?

It may be:

Who can see the system’s weaknesses first — and who has the authority to decide what happens next?

That is the emerging politics of vulnerability.

And it may become one of the defining dimensions of cyber sovereignty in the AI era.


Discover more from Center for Cyber Diplomacy and International Security

Subscribe to get the latest posts sent to your email.

Discover more from Center for Cyber Diplomacy and International Security

Subscribe now to keep reading and get access to the full archive.

Continue reading