Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

IriusRisk’s move into AI-assisted threat modeling began with its 4.30 release on June 27, 2024—not a new 2026 launch. That release introduced Jeff, a guided assistant for starting a threat model from a description or existing artifacts. Separately, IriusRisk’s current product page describes a 28-component Security Library for modeling AI and machine-learning systems, available in Community Edition and Enterprise. ThreatModeler acquired IriusRisk in January 2026 and later announced Nexus as a post-merger platform; those developments should not be confused with the specific capabilities announced in 2024.

What did IriusRisk announce for machine-learning threat modeling?

In its IriusRisk 4.30 release announcement, posted June 27, 2024, the company introduced “Jeff,” an AI assistant intended to guide users through creating a threat-model diagram. IriusRisk said users could describe the system they wanted to model or provide existing artifacts such as documentation, user stories, source code, meeting transcripts, and software bills of materials (SBOMs).

The announced workflow was interactive: users could adjust the generated diagram and then continue working with the resulting threat model. The announcement describes a way to get a model started and refine it; it does not establish how accurate or complete generated models are. Treat the output as a draft that needs review against the actual architecture and security requirements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When was Jeff available?

The release said Jeff would be available in Community Edition on July 1, 2024. It directed enterprise users to contact their Customer Success Manager to request the capability for their organization. Those are the availability terms stated in the 2024 announcement; they do not, by themselves, establish the current status of every Jeff feature or deployment option.

What else was in the 4.30 announcement?

IriusRisk also announced more than 100 Azure V2 components. This was a separate addition to the release, not a count of AI/ML library components.

What is IriusRisk’s AI/ML Security Library?

IriusRisk’s AI/ML product page describes a dedicated Security Library for threat modeling AI and machine-learning applications. The company says it contains 28 specific components and is available in both Community Edition and the Enterprise Threat Modeling Tool. The count and availability are IriusRisk’s descriptions; they do not independently show how comprehensive the library is or how well its contents fit a particular system.

A library like this gives teams components to use when representing AI/ML applications in a threat model. It is most useful when the model captures the system’s real design: its components, data flows, trust boundaries, and relevant controls. A library cannot compensate for missing or inaccurate architecture details, and a generated or library-assisted model still needs human review.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How do you threat model a machine-learning system?

Start from the system being built, not from the assumption that any application using AI has the same risks. Map the architecture and the path data takes through it, then examine how the model is developed, accessed, updated, and used. The goal is a reviewable account of what can go wrong in this system and which controls address those threats.

  1. Define scope and purpose. Identify the application, its users, the decisions or outputs it supports, and what is in or out of scope.
  2. Draw the architecture. Represent the application, model, data stores, APIs, external services, people, and operational systems that interact with it.
  3. Trace data flows and trust boundaries. Show where data enters, moves, is stored, or leaves the system. Mark boundaries where control or trust changes, including between users, services, organizations, and environments.
  4. Identify security-relevant assets and assumptions. Consider the data, model, credentials, interfaces, and operational processes that matter to the system’s security. Make assumptions visible so reviewers can challenge them.
  5. Identify threats and map controls. Work through the exposed components and flows, then record the relevant threats, existing safeguards, and any gaps that need treatment.
  6. Review and maintain the model. Have people familiar with the design check that the diagram reflects the implementation. Update it when architecture, data flows, dependencies, or controls change.

An AI assistant may help turn source material into a first diagram, but the team remains responsible for checking that the model includes important components and boundaries. Generated structure is not proof that the system is secure.

Can AI generate a threat model from architecture or source code?

IriusRisk’s 2024 announcement said Jeff could start from a natural-language description or artifacts including documentation and source code, alongside user stories, meeting transcripts, and SBOMs. It also described an interactive process for adjusting the resulting diagram. That establishes what the company announced about the workflow, not a measured level of accuracy, coverage, or time saved.

When assessing any AI-assisted threat-modeling workflow, check whether it:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • represents architecture, trust boundaries, and data flows in a form people can inspect and edit;
  • makes threats and mapped controls traceable to the system elements they concern;
  • allows reviewers to correct omissions and assumptions;
  • fits the team’s development and governance processes; and
  • is available in the edition and deployment arrangement the organization uses.

These are evaluation questions, not claims that Jeff or a later product meets each criterion. No independent product testing is established by the cited announcements.

How do the 2024 release and 2026 platform news fit together?

They describe different product and company milestones. ThreatModeler announced that it had acquired IriusRisk on January 8, 2026. On June 25, 2026, ThreatModeler announced Nexus general availability and described it as the first platform expression of the merger.

ThreatModeler says Nexus combines agents with a deterministic framework and a connected Secure Design Graph. Those are the company’s product claims. They do not confirm that a particular feature of IriusRisk’s AI/ML Security Library has been integrated into Nexus.

The distinctions matter if you are evaluating a current workflow: Jeff was the AI assistant described in IriusRisk’s 2024 release; the 28-component AI/ML Security Library is described on IriusRisk’s current product page; Nexus is a later ThreatModeler platform announcement. The cited materials do not provide a directly tested comparison of these offerings or establish comparative performance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What figures did ThreatModeler report for Nexus?

In its 2026 Nexus announcement, ThreatModeler reported platform corpus counts of 3,500+ security requirements, 1,500+ catalogued threats, 3,000+ modeled components, and 180+ compliance frameworks. These are company-reported figures for Nexus, not counts for IriusRisk’s AI/ML Security Library.

The same announcement cited a Hanover Research survey of 250 respondents, reporting that threat modeling for AI-generated code occurred before coding 31% of the time, during coding 45% of the time, and after coding 24% of the time. ThreatModeler reported the survey figures; the survey report itself was not reviewed, so they should be read with that provenance in mind.

How should a team decide whether the approach fits?

Evaluate the current product and workflow rather than relying on a release headline. Ask for a demonstration using a representative system architecture, then verify how the model is created, edited, reviewed, and maintained. Confirm edition availability directly with the vendor if a required capability or deployment detail is not documented for your organization.

For any proposed AI-assisted workflow, reviewers should be able to check the architecture, data flows, trust boundaries, threats, and controls and correct the model when it is wrong or incomplete. The vendor pages describe intended workflows and library contents; they are not independent evidence of model quality or security outcomes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.