Executive Summary
AI has made threat modeling easy to start. It has not made it easy to trust. In seconds, a model can describe an architecture, list plausible threats, and draft documentation that once took days. That speed is real. On its own, it is also fragile.
Generative AI is probabilistic, not deterministic: the same question can return a different answer each time. That variability is fine for a first draft and unacceptable for a risk decision, where accountability, auditability, and confidence in the result are the whole point.
Threat modeling is not a content task. It is a governed, collaborative discipline that aligns architecture, development, and security around risk, and produces decisions a team can defend later. Done well, it gives those teams a shared language. Done as a stream of prompts, it collapses back into a checklist built on guesswork.
This paper looks at how to use AI for threat modeling without giving up the things enterprise security depends on, and at the platform pattern that holds both: ThreatModeler® Nexus™, agentic threat modeling grounded in a Secure Design Graph.
