Traditional coordinated vulnerability disclosure assumes systems can be patched. Here is why that breaks down for AI, and how MLCommons is building a new standard.