{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/ncsc-ten-questions-ai-vulnerability-discovery-2026/",
 "asOf": "2026-09-26",
 "id": "ncsc-ten-questions-ai-vulnerability-discovery-2026",
 "date": "2026-05-11",
 "datePrecision": "day",
 "title": "UK NCSC issues ten questions for organizations using AI models to find vulnerabilities",
 "lane": "policy",
 "kind": "guidance",
 "summary": "The head of the NCSC's Vulnerability Management Group published ten questions for organizations considering AI-driven vulnerability discovery. The questions stress having a process to triage and fix findings, prioritizing exploitable issues, weighing data, permission, legal and jurisdiction risks of the chosen model, starting with the external attack surface, and planning for future models.",
 "whyItMatters": "It is government guidance on the operational side effects of defensive AI vulnerability discovery, such as unmanageable finding volume.",
 "actors": [
  "ncsc-uk"
 ],
 "topics": [
  "vulnerability-discovery",
  "standards-and-guidance"
 ],
 "atlas": [
  "credentials"
 ],
 "artifacts": [],
 "sources": [
  {
   "url": "https://www.ncsc.gov.uk/blogs/10-questions-ask-using-ai-models-find-vulnerabilities",
   "publisher": "UK National Cyber Security Centre",
   "title": "10 questions to ask when using AI models to find vulnerabilities",
   "date": "2026-05-11",
   "type": "primary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "Question 3 asks whether a process exists to manage vulnerabilities that AI finds; question 7 recommends starting with the external attack surface and combining AI with human review.",
   "locator": "Questions 3 and 7"
  }
 ],
 "significance": 2,
 "fideQuestions": [],
 "methods": [
  "ai-vulnerability-discovery"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}