I would say that "protecting users from applications" (or at least, external attackers) has been commonplace for maybe even two decades now, ever since major malware 'plagues' of the early 2000's (pre-SP2 Windows XP) like Blaster or Sasser.
That said, in that era it was often assumed (more so than now) that software the user installed himself is trusted.
We all seem to forget that computing has changed drastically in the last decade.