Perspective

The coverage gap: why most enterprises inspect a fraction of their risk

The economics of inspecting everything, and why it has been impossible until now.

7 min read  ·  Security leadership

Ask a CISO how much of their organization's communications traffic is actually inspected, and most will give you an honest number: somewhere between five and thirty percent. The rest — the overwhelming majority of emails, messages, collaboration threads, and AI-agent actions — moves through the enterprise uninspected, a dark mass of activity that only surfaces when something has already gone wrong.

This is the coverage gap. It is not a new problem, but it has become a more dangerous one, because the volume of inspectable activity has grown far faster than the tools built to watch it.

Why the gap exists: a structural problem

Two generations of inspection tooling each solved part of the problem, and each introduced a constraint that made full coverage impossible in practice.

The first generation — rule-based and keyword-matching systems — is genuinely fast. A keyword filter can evaluate a message in microseconds and has no meaningful cost-per-message. The constraint is coverage of a different kind: it only catches what the rule anticipated. A rule written to detect a specific phrase will miss every semantically equivalent phrase that an employee — or an adversary — chooses instead. In practice, this means rule-based systems catch the obvious and miss the sophisticated, which is precisely backwards from where risk concentrates.

The second generation — AI and large-language-model-based inspection — addressed the semantic gap. These systems can recognize intent, context, and nuance that no keyword list would ever capture. But they introduced a cost-per-query structure that makes total coverage economically prohibitive. At enterprise scale, inspecting every message and every agent action with an LLM-based tool is not a budget question — it is an architectural impossibility at real-time latency and a prohibitive expense even batch-processed. Organizations using these tools therefore do what the economics demand: they sample.

“Organizations using AI inspection tools do what the economics demand: they sample. And in every sampled regime, risk hides in the uninspected majority.”

Sampling is not a failure of implementation. It is the rational response to a cost structure that does not fit total coverage. And in every sampled regime, risk hides in the uninspected majority — because bad actors know, explicitly or implicitly, where the gaps are. The coverage gap is not random. It is adversarially exploited.

The three dimensions of the gap

The coverage gap manifests across three dimensions that compound each other.

The first is channel coverage. Most inspection programs were built for email, because email was the dominant business communication medium when the programs were designed. The enterprise communication surface has since expanded to include messaging platforms, video meeting transcripts, collaboration workspaces, and now AI agent outputs — each of which may carry material risk and most of which fall outside the inspection perimeter. A broker who moves a conversation from their monitored email to an unmonitored messaging application has not evaded a sophisticated attacker. They have simply stepped outside a boundary that the inspection program made visible.

The second is depth of inspection. Even within monitored channels, most programs review a statistical sample rather than the full corpus. FINRA Rule 3110's “reasonable sample” standard was written against the capacity constraints of human reviewers. Those constraints no longer need to apply — but the sampling habit persists because the tools that might replace it have not made total coverage economically viable.

The third is temporal coverage. Batch-processed inspection introduces a lag between action and detection that can range from hours to days. In the context of an insider trading pattern or a rogue agent action, this is not a minor inconvenience. By the time the finding surfaces in a next-day report, the damage is complete. Real-time inspection — inline, before the action resolves — is the only architecture that allows intervention rather than retrospection.

100%
of traffic inspected by Compiled
0.995
detection accuracy on held-out test sets
Real-time
inline decisions before actions resolve

Why the agent era makes the gap existential

The coverage gap pre-dates autonomous AI agents, but the agent era transforms it from a risk-management problem into an operational one. A human employee who sends a non-compliant message produces a record that can eventually be reviewed, and a response — however delayed — can be formulated. An AI agent that takes a non-compliant action may not produce a human-readable record in any channel that the inspection program monitors, and the action may be irreversible by the time it surfaces.

Enterprise organizations are deploying agents into workflows that touch customer data, financial systems, and regulated communications. Most of these agents operate against no real-time control plane. The behavior of the agent is governed by its training and its prompt — not by an inline policy enforcement layer that can observe each action, evaluate it against the organization's policies, and allow or block it before execution.

This is not a hypothetical risk. OWASP's Top 10 for Agentic Applications, published in December 2025, identifies memory poisoning and goal hijacking as primary agentic threats whose named mitigation is a behavioral inspection layer sitting in the path of agent actions — what OWASP calls a Semantic Firewall. The industry has named the category. The question is whether organizations will build coverage before incidents accumulate.

What closing the gap requires

Total coverage demands an inspection architecture that decouples detection quality from per-query cost. The two have been coupled because the detection mechanisms that can recognize subtle, novel, and context-dependent risk have historically been expensive to run at query time. An architecture that breaks this coupling — that can evaluate every message and every agent action with semantic precision at a cost structure compatible with total coverage — changes the economics of the problem.

It also demands that the inspection happen in-tenant. The regulatory landscape for communications surveillance increasingly penalizes, or at minimum scrutinizes, any architecture in which regulated communications leave the firm's environment to be processed by a vendor. Data-residency and privacy teams at regulated organizations are being asked to approve surveillance tools whose architecture creates a new data-handling exposure. An in-tenant architecture — where the inspection logic runs inside the firm's own environment and no communication is transmitted externally — is not a nice-to-have; it is the prerequisite for approval in many regulated environments.

Finally, it requires inline rather than batch operation. Inspection that happens after the fact is retrospective reporting, not governance. A behavioral defense layer should be positioned to produce allow, flag, or block decisions in real time — before the message is delivered and before the agent action resolves.

The case for acting now

The coverage gap is a known condition, and regulators, auditors, and examiners are increasingly aware of it. FINRA examiners ask what percentage of communications a firm actually reviews. SEC examination priorities for 2026 include verification of AI-related claims in virtually all examinations — which implicitly includes claims about the scope of AI-agent supervision. Healthcare organizations face HIPAA risk-analysis obligations that now include the communication and agent surfaces clinical AI systems touch.

The organizations that close the coverage gap first will not only reduce their risk exposure. They will be positioned to demonstrate a supervisory program that regulators recognize as substantively adequate — rather than one that samples where regulators are now asking for coverage. In a regime where cooperation credit is the dominant enforcement lever, the firms with detection infrastructure are the ones who can earn it.

Talk to us

Compiled closes the coverage gap — total inspection, in real time, inside your environment.

Chat with usBook a 30-minute walkthrough