CISA Considers 72-Hour Remediation Deadline for Critical Vulnerabilities Amid AI Threat Acceleration
Reuters reported May 1, citing two unnamed sources, that CISA Acting Director Nick Andersen and National Cyber Director Sean Cairncross are discussing cutting the KEV remediation deadline from two to three weeks to 72 hours. The two sources cited AI tools, specifically Anthropic's Claude Mythos and OpenAI's GPT-5.4-Cyber, as the driver, telling Reuters these models can identify and exploit newly disclosed vulnerabilities within hours. CISA declined to comment on the reporting, and Reuters could not confirm whether a decision had been reached or a timeline set. Former CISA Deputy Director Nitin Natarajan told Reuters the tighter deadline made sense given how quickly AI-powered threats were evolving but warned that staff cuts and funding reductions had already diminished the agency's capacity.
AI-powered exploit acceleration provides a credible forcing function for compressing KEV remediation windows, but a mandatory 72-hour deadline is