AI is finding your vulnerabilities. It's also become one. Get ahead of both.
Tell us where your gaps are and we'll connect you with a vetted partner — or start with the free readiness assessment. Vulnerabilities.ai™ is the independent hub tracking AI-discovered vulnerabilities, the eight categories of risk in the AI you've deployed, and the BOD 26-04, FedRAMP, and EU AI Act deadlines already in force.
The full map of AI-era vulnerability risk.
CISA BOD 26-04 replaced CVSS-based patching with a four-variable risk model and 72-hour critical timelines. FedRAMP made aligned rules mandatory by December 7, 2026 — with certification revocation after March 7, 2027. Our compliance hubs give agencies and cloud providers the practitioner-grade guidance the directives themselves don't.
The vulnerabilities found through Project Glasswing are moving through coordinated disclosure now — unevenly, and slower than the headline numbers suggest. They'll surface as CVEs and emergency patches in software you run — and no one is tracking them for the general market. We are. Ledger connects frontier-AI findings to the remediation obligations they trigger.
78% of enterprise security leaders now hold a dedicated "security for AI" budget, yet 91% rate their AI security maturity as early-stage (Felicis, spring 2026). Eight AI-specific asset classes — from agent identities to training data to the AI-generated code already in your repos — mapped to the problems CISOs actually name.
Discovery is industrialized. Remediation is the bottleneck. Access is gated.
In April 2026, Anthropic's Claude Mythos Preview demonstrated that frontier AI can autonomously discover zero-day vulnerabilities — including a 27-year-old flaw in OpenBSD's TCP stack — for less than the cost of a nice dinner. Within weeks, Project Glasswing partners had surfaced tens of thousands of candidate findings — though the verified, published disclosure count has settled at a fraction of that, a gap Ledger tracks in detail. Anthropic itself now says the bottleneck in cybersecurity is no longer finding vulnerabilities, but verifying, disclosing, and patching them.
The industry's response arrived first as gated coalitions, and is now starting to widen. Project Glasswing began with roughly 200 vetted organizations; Mythos-class capability is now also reaching Enterprise customers through Claude Security and an expanding Cyber Verification Program. CrowdStrike's Project QuiltWorks started as an enterprise-only, Falcon-platform offering and extended to SMBs in August through seven channel partners. Coverage is genuinely growing — but it's still growing toward the organizations best positioned to notice and act on it first.
Everyone else — the mid-market, the FedRAMP ISV ecosystem, agencies under BOD 26-04 deadlines, the companies whose software is being scanned whether they know it or not — needs an independent place to understand what's coming, what's required, and who can actually help. That's what this site is.
Where does your AI security posture actually stand?
Our free self-assessment takes five minutes and maps your organization against the frameworks that matter: NIST AI RMF, MITRE ATLAS, BOD 26-04's four-variable model, and the agent-governance controls CISOs cite as their biggest gap. You get a scored readiness report with specific gaps identified — no sales call required to see your results.
Two domains. A 0–100 score. Your top three gaps, mapped to the solutions that close them.
Take the Assessment — Free →The compliance clock, at a glance.
BOD 26-04 · all agencies must have risk-tiered remediation policies in place.
All FedRAMP-certified cloud service offerings must comply.
Corrective action plans must be active before this date — not submitted on it.
Annex III standalone systems, as deferred by the Digital Omnibus.
Who's finding vulnerabilities with AI — and whether they're keeping their word.
Five programs — Project Glasswing, Project QuiltWorks, Daybreak, Gold Eagle, and the open-source coordination efforts around them — are scanning the world's software with frontier models. Ledger profiles each one, tracks the disclosures we've verified, and follows the open questions: whether Glasswing's disclosure ledger is keeping pace with its own deadlines, and whether faster discovery is actually closing the remediation gap.
Get matched with a vetted partner.
A short qualification form — your biggest current gap, what would actually be useful, and how you're covered today. We'll connect you with a vetted partner. Takes under a minute.
Get Matched with a Partner →We're building the independent readiness benchmark for BOD 26-04 and AI-era vulnerability response. Share the free assessment with your customers and prospects — a newsletter link, a LinkedIn post, a slide in a QBR. In return: early access to aggregate benchmark data, acknowledgment as a founding distribution partner in the report's methodology section, and first position in your marketplace category. Commission terms unchanged.
Apply as a Founding Partner →Independent by design.
We don't sell scanners, platforms, or remediation services. We track the landscape, maintain intelligence built on public authoritative sources, and curate the solution ecosystem — including the organizations still waiting on access as these coalitions slowly widen. Basic marketplace listings are free because the full landscape should be visible, not just the vendors with the largest budgets.
About Vulnerabilities.ai™ →