The Office of Science and Technology Policy (OSTP) has circulated a request for information (RFI) on how best to develop policies that support the responsible development of AI while minimizing risk to rights, safety, and national security. For example, AI-based vulnerability scanners that use graph-based models have outperformed traditional vulnerability scanners in detecting certain types of vulnerabilities. Generative AI models, such as ChatGPT, are poorly suited for detecting novel or non-publicly available vulnerabilities, as they are tailored for natural (non-computer) languages and have been trained on articles that list vulnerabilities in source code.