AI Threat Detection Gaps
Detection Dashboard: All Green. Novel Technique Category: Not on the Dashboard. Attacker: Undetected.
6 min read · 7 July 2026 · AI governance
A technology services vendor's AI-powered threat detection platform displayed a coverage dashboard showing monitoring status across the vendor's technology environment , network, endpoint, cloud, application, and identity layers. Each coverage category showed green, indicating active monitoring and detection coverage. The dashboard had been configured by the vendor's security team at product deployment six months earlier, and the coverage indicators reflected the threat categories and technique types that had been included in the initial configuration. Three months into deployment, a threat actor group targeting technology services companies had begun using a novel lateral movement technique , abusing a specific cloud-native service's API for covert lateral movement in ways that did not match any of the pre-configured detection signatures or behavioural models in the AI product. The vendor's threat intelligence team had received an ISAC advisory about the technique four weeks after the threat actor group began using it. The advisory had been acknowledged. It had not prompted an update to the AI product's detection configuration. The dashboard continued to show green for all configured categories. The novel technique was not in any configured category. It did not appear on the dashboard at all. The all-green dashboard was not evidence that all techniques were being detected , it was evidence that all configured detection categories were producing results within expected parameters. The unconfigured categories, including the novel technique being actively exploited, were simply absent.
What are AI Threat Detection Gaps, Really?
AI threat detection gaps are the technique categories, attack patterns, and threat actor behaviours that an AI-powered security monitoring platform does not detect , either because detection coverage for those categories was never configured, because the AI's training data did not include representative examples of those techniques, or because the techniques are specifically designed to avoid the AI's detection logic. Threat detection gaps are systematically concealed by dashboard designs that display coverage status for configured categories only , creating the appearance of comprehensive coverage when in reality the dashboard is silent about techniques that are not configured.
The configuration completeness problem is the primary gap mechanism. AI threat detection platforms require configuration , detection rules, behavioural models, and monitoring coverage must be defined and activated for each technique category the platform is intended to monitor. Coverage dashboards display the status of configured categories. They do not display what is not configured. A dashboard that shows green across all displayed categories may simultaneously have no configuration for technique categories that are actively being exploited , those categories are not red or amber on the dashboard. They are simply absent.
The threat landscape evolution problem is the temporal dimension. Security monitoring configurations that are accurate at deployment become progressively less complete as the threat landscape evolves , new techniques emerge, existing techniques are modified to evade detection, and threat actor groups adapt to avoid the signatures and behavioural models that detection platforms have been trained on. A threat detection platform configured against the threat landscape of six months ago may have significant coverage gaps for the current threat landscape, and those gaps will not appear on the dashboard unless someone proactively adds monitoring configuration for the new technique categories.
The intelligence-to-configuration gap is the specific operational failure in the hook scenario. The vendor's threat intelligence team received an ISAC advisory about the novel lateral movement technique and acknowledged it. Acknowledging the advisory is not the same as updating the detection platform's configuration to monitor for the technique. The gap between receiving threat intelligence about a novel technique and implementing detection configuration for that technique is the window during which the technique can be used in the environment without generating alerts.
Why this matters
AI threat detection gaps matter for TPRM because all-green detection dashboards are frequently presented as evidence of comprehensive coverage , and accepted as such by TPRM teams reviewing vendor security posture. The dashboard confirms that configured detection is working. It does not confirm that the configuration is complete for the current threat landscape.
Where most teams get this wrong
The most consistent failure is accepting dashboard coverage status as evidence of detection completeness. Coverage status describes how configured monitoring is performing. Coverage completeness describes whether the configuration addresses the relevant threat landscape , a different and more important question.
- Dashboard coverage accepted as completeness evidence
- Configuration completeness not assessed against current threat landscape
- Intelligence-to-configuration gap not evaluated , how long to implement detection for new techniques
- Novel technique coverage not specifically assessed
- ISAC and threat intel integration into detection configuration not monitored
What good looks like
Mature AI threat detection programmes assess coverage completeness against the current threat landscape , specifically evaluating whether MITRE ATT&CK technique coverage is current, whether ISAC threat intelligence translates into detection configuration updates, and whether detection gap metrics are tracked alongside coverage performance metrics.
- ATT&CK coverage map updated quarterly against current threat landscape
- Intelligence-to-configuration SLA , how quickly new technique advisories become detection updates
- Detection gap tracking , techniques in ISAC advisories without corresponding detection
- Novel technique discovery process , how new attacker behaviours enter the detection inventory
- Configuration completeness assessment , independent of dashboard status
Tooling
ATT&CK Coverage , MITRE ATT&CK Navigator for detection coverage mapping
ATT&CK Navigator visualises detection coverage against the ATT&CK technique matrix , showing which techniques have detection coverage and which do not. Updating the ATT&CK Navigator map quarterly against current threat intelligence provides a completeness assessment that dashboard status does not. For TPRM practitioners, asking for the vendor's ATT&CK coverage map updated in the last quarter provides a specific coverage completeness question.
Governance challenges
The governance challenge with AI threat detection gaps is the dashboard illusion , the confidence that all-green status provides to security leadership and TPRM reviewers. The governance resolution is supplementing dashboard status with coverage completeness assessment , specifically asking how the dashboard's configured categories were selected and whether the selection is current against the threat landscape.
- Ask for ATT&CK coverage map updated in last quarter , not just dashboard status
- Ask about intelligence-to-configuration SLA , how quickly ISAC advisories become detection updates
- Ask whether the novel lateral movement technique in recent ISAC advisories has detection coverage
- Ask about detection gap tracking , how unconfigured technique gaps are identified and tracked
- Supplement dashboard review with configuration completeness assessment
If you are a small team
For any AI threat detection platform, ask the ISAC question: in the last six months, how many ISAC or threat intelligence advisories about novel techniques has your team received , and for each one, what is the timeline from advisory receipt to active detection configuration in your platform? That question reveals the intelligence-to-configuration gap , the window between knowing a technique is being used and having detection for it. An advisory received four weeks ago that has not yet become a detection configuration is a four-week detection gap for that technique.
- Ask for intelligence-to-configuration timeline for recent ISAC advisories
- Ask for ATT&CK coverage map updated in last quarter
- Ask whether specific novel techniques from recent advisories have detection coverage
- Ask how detection gap tracking works between advisories and configuration
What to require
Ask directly:
"For the ISAC advisories your team received in the last six months , what is the timeline from advisory receipt to active detection configuration in your platform, and can you confirm whether the novel cloud-native lateral movement technique in the most recent advisory has an active detection configuration?"
Expect as evidence
- Intelligence-to-configuration timeline for recent advisories
- ATT&CK coverage map updated in last quarter
- Active detection confirmation for specific ISAC-advised techniques
- Detection gap tracking process
A vendor who confirms all-green detection status should be asked for ATT&CK coverage completeness. Dashboard status confirms configured detection is working. Coverage map confirms whether the configuration is complete for the current threat landscape.
How to evidence it
- ATT&CK coverage map records
- Intelligence-to-configuration SLA documentation
- Detection gap tracking records
- ISAC advisory to detection configuration timeline
Key Takeaway
All-green dashboard. Novel technique in ISAC advisory four weeks ago. Advisory acknowledged. Detection configuration: not updated. Novel technique: undetected. The dashboard showed green because all configured categories were performing within parameters. The novel technique was not in any configured category. It was not red. It was absent. All-green dashboard status confirms configured detection is working. ATT&CK coverage completeness confirms whether the configuration addresses the current threat landscape. Intelligence-to-configuration gap reveals the window between knowing a technique exists and having detection for it. The dashboard is the performance metric. The coverage map is the completeness metric. Both are required. Neither substitutes for the other.
Speak to It™
The term you nodded along to, explained in ninety seconds, so you can speak to it professionally. It is how most readers find these articles.
Join the Association