US officials are weighing whether to shorten the deadlines federal agencies have to patch known software vulnerabilities, Reuters reported, citing people familiar with the discussions. The driver is the speed at which AI-assisted attackers are turning newly disclosed flaws into working exploits. The window between a vulnerability becoming public and being weaponized is collapsing, and the current federal timetable was written for a slower threat.
Federal civilian agencies today operate under remediation windows tied to the Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog. When a flaw is added, agencies get a fixed number of days to patch or mitigate it. Reuters' sources indicate officials are considering whether those windows are still defensible when attackers have generative AI helping them write exploit code.
Reuters did not report a specific new deadline, a target effective date, or which agency would issue the directive. The reporting frames the conversation as active rather than concluded. No public rulemaking or binding operational directive has been announced.
Key facts
- 01Reuters reports US officials are considering shorter federal deadlines to remediate known software vulnerabilities.
- 02The reassessment is being driven by concerns that AI-powered hacking is compressing the time attackers need to weaponize disclosed flaws.
- 03The current federal patching regime relies on the CISA Known Exploited Vulnerabilities catalog and fixed remediation windows.
- 04Reuters cited unnamed people familiar with the discussions; no final policy or timeline has been published.
The concern animating the review is concrete. Security researchers across the past year have documented attackers using large language models to triage vulnerability disclosures, draft proof-of-concept exploits, and adapt malware to specific targets. What used to take a skilled human days can, in some categories of bug, take a model and an operator hours.
That shift puts pressure on the defender side of the equation, where federal agencies are not known for speed. Patching a vulnerability across a sprawling government IT estate involves change windows, vendor coordination, and legacy systems that resist modern tooling. Cutting a 21-day window to something shorter sounds simple on paper and is operationally brutal in practice.
The policy question is whether the federal government should accept more operational disruption to close the exploitation gap, or hold the current deadlines and lean harder on detection and response. Reuters' sources suggest officials are leaning toward the former, on the view that AI-augmented adversaries have already changed the math.
There is also a market signal here. Defense contractors, endpoint security vendors, and the cloud hyperscalers have all spent the last 18 months pitching AI-driven vulnerability management as the answer to AI-driven offense. A tighter federal deadline would be a forcing function for that procurement, not a side effect of it.
The skeptical read is that shortening deadlines without funding the agencies to meet them produces paper compliance and missed targets, not better security. CISA has limited authority to compel remediation at agencies it does not run, and prior binding operational directives have seen uneven adherence. A faster clock against the same operational constraints risks being a reporting exercise.
It is also worth noting what is not in the Reuters story. There is no named official on the record, no draft directive text, no scoped list of which vulnerability classes would be subject to the tighter window, and no indication of whether private-sector critical-infrastructure operators would be pulled in. Until those details surface, the contour of the policy is a direction, not a rule.
The shift, if it happens, would be one of the first concrete federal cybersecurity policy moves explicitly justified by AI capability rather than by a specific breach. That is the part worth watching. For years the government has talked about AI as a future risk to defend against; tightening patch deadlines because language models are writing exploits today would mark the point at which AI-assisted offense became a binding constraint on how Washington writes its own security rules.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




