The CVE™ Program’s Frontier AI Researcher CVE Numbering Authorities (CNAs) Pilot, is an initial six-month effort with Anthropic and OpenAI that began on began on July 28, 2026. This is a closed pilot, with participation limited at this time to these two organizations.
The pilot is intended to help the CVE Program evaluate how the large-scale, AI-enabled vulnerability research capabilities of frontier AI labs can contribute to accurate, coordinated, actionable, and sustainable CVE Records. Under the pilot, Anthropic and OpenAI may assign CVE Identifiers (CVE IDs) for vulnerabilities they discover in widely adopted products and applications when those products are not already within another CNA’s scope.
This pilot supplements and does not replace, waive, or modify the CNA Operational Rules; participating organizations remain responsible for complying with all applicable CNA requirements. The effort is deliberately focused on products and applications that have achieved meaningful adoption, deployment, or ecosystem significance. The CVE Program is not accepting additional pilot participants at this time. At the end of the initial six-month period, the CVE Program will review the pilot’s outcomes, risks, operational burden, and value to CVE consumers before determining whether to continue, modify, expand, extend, or conclude the effort.
Additional information about the pilot’s purpose, scope, operating requirements, and evaluation approach is available in the Frontier AI Researcher CVE Numbering Authorities (CNAs) Pilot document: https://www.cve.org/Resources/Roles/Cnas/FrontierAiResearcherCNAsPilot.pdf.