Security got there first: what pre-deployment review looks like when it works
Security review is routine, expected and resourced. Ethical review is none of these. The difference is not technical, and the history of how security got there is instructive.
There is one domain in which pre-deployment scrutiny of software is entirely normal. Nobody argues that a security review stifles innovation. Nobody suggests threat modelling be deferred to a final-year module. Adversarial testing is a professional expectation, disclosure has established norms, and incident reporting is routine in most serious organisations.
None of this was true thirty years ago, and the way it changed is more useful to us than the current state.
How security became unavoidable
- Failures became visible and attributable. A breach is discrete, dated, and traceable to an organisation. Ethical failures are diffuse, gradual and easy to attribute to circumstance.
- Cost landed on the decision-maker. Imperfectly, but enough. Ethical failure costs are borne overwhelmingly by people who had no part in the decision.
- A profession formed. With credentials, literature, conferences and a labour market, which made “we could not find anyone” stop being an answer.
- Review became a condition of shipping. Not advisory. Not a committee. A gate in the release process that an engineer cannot route around.
The distributional difference
The most important asymmetry is the third and fourth together. Security matured when the party choosing the risk started bearing some of it, and when review became structural rather than advisory. Ethical governance currently has neither property, which is a better explanation of its weakness than any claim about the difficulty of the underlying questions.
Security did not win the argument. It changed who paid for losing it, and then made review a gate rather than a recommendation.
What follows
If this reading is right, the productive interventions are not better principles. They are mechanisms that make ethical failure visible and attributable, place some of its cost on the party choosing it, support a profession that can be held to standards, and convert review from advice into a gate. Each of those is a concrete institutional project, and none requires resolving a philosophical dispute first.