The directive obligates civilian federal agencies to fix, disable, or remove vulnerable software within three calendar days, depending on the severity of the threat. The compressed timeline is due in part to hackers’ use of artificial intelligence, according to the report.