Shostack + Friends Blog

 

Secure By Design roundup - Dec/Jan 2026

The normalization of deviance, exciting threat modeling news, and a question of do regulatory threats change ‘the threat model’ as much as GPS attacks? Not yet. a photograph of a robot, sitting in a library, working on a jigsaw puzzle. The robot holds up the jigsaw puzzle, and snow is falling inside the library

This month leads off with Wunderwuzzi’s excellent article The Normalization of Deviance in AI. The context, which closely relates to both Diane Vaughn’s “normalization of deviance” and Charles Perrow’s concept of “normal accidents” to contextualize how we’re becoming accepting of AI-related defenses that would be shocking in any other context. He says “we can observe the drift of normalization occurring in real-time.” It’s a great point.

Threat Modeling

Appsec

AI

Regulation

Shostack + Associates News

Image by midjourney: ”a photograph of a robot, sitting in a library, working on a jigsaw puzzle. The robot is spotlighted by light streaming in through a small window, through which you can it's snowing.” I appreciate how this one is holding up the jigsaw and it’s snowing inside, both demonstrating AI is bad at concepts.