Cloud vulnerability disclosure gaps threaten AI infrastructure security
Atlantic Council analysis finds cloud providers lack mandatory vulnerability disclosure, strain the public CVE system, and create systemic risks for AI workloads; urges policy reforms and international coordination.
This Atlantic Council policy brief examines structural weaknesses in vulnerability management for cloud infrastructure hosting AI systems. The public vulnerability ecosystem—anchored by the CVE/NVD system and CISA's Known Exploited Vulnerabilities catalog—faces severe strain from rising submission volumes, budget constraints, and workforce reductions. Cloud providers voluntarily disclose only a subset of vulnerabilities (typically critical flaws), withholding lower-severity issues from public tracking, and maintain siloed vulnerability reward programs with no cross-provider coordination mechanism. This opacity means researchers identifying a flaw in one provider's services have no systematic way to check whether the same pattern exists elsewhere. Simultaneously, AI is accelerating both offensive and defensive capability: researchers using AI agents have discovered dozens of zero-day patterns in open-source libraries underlying cloud services, while maintainers report overwhelming volumes of AI-generated bug reports of variable quality. The brief argues that foundational U.S. cybersecurity authorities—CISA, NIST, the Cyber Safety Review Board—face leadership vacuums and funding uncertainty, while European regulatory instruments (NIS2, Cyber Resilience Act) are only now taking effect. The author recommends Congress reauthorize lapsed information-sharing frameworks, establish an AI-specific ISAC, re-fund CISA and NIST, re-establish the Cyber Safety Review Board with subpoena power, and lead international coordination on vulnerability disclosure norms for cloud and AI infrastructure.
Source reporting: https://www.atlanticcouncil.org/in-depth-research-reports/issue-brief/securing-cloud-infrastructure-ai
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free