Executive Summary Recognizing the ability of Frontier AI models to discover and exploit vulnerabilities at unprecedented speed and scale, CISA’s Binding Operational Directive (BOD) 26-04 marks a significant shift in federal vulnerability management. Rather than prioritizing remediation based on patch availability, the directive requires agencies to focus on risk-informed, evidence-based decision-making, accounting for exploitability, exposure, and mission impact. This shift reflects a new