Security teams threat model systems—but rarely the people who write them. What if many AppSec issues aren’t technical flaws but predictable human behavior? This talk will use behavioral economics to explain why developers copy insecure code, skip tests, ignore warnings, or trust AI too much. Will break down the psychology behind insecure decisions, from present to automation bias, then fix them.