We're cutting through the BS at Black Hat. Come Meet Us!

Learn More

The coverage gap problem is worsened by AI

Kamden Schewitz

Product Marketing Manager, Axonius

The first post in this series looked at why asset inventories go out of date so quickly. A spreadsheet export is already wrong by the time you finish putting it together. A configuration database only knows about the assets that went through a proper change process. A security tool's own console only knows about the assets it was installed on. Each one gives you a piece of the picture, and none of them gives you the whole thing.

That post was about what you cannot see. This one is about what it costs you. When your systems disagree about what exists, some of your assets end up running without the security controls you assume are protecting them. That is the coverage gap problem.

The problem with the status quo

To be fair, plenty of coverage problems do get noticed. If an agent stops checking in, falls a few versions behind, or starts failing its health checks, your console will tell you. The machine is enrolled, so there is a record sitting there for the tool to flag. Most teams handle this well. The harder problem is the machine that never got enrolled in the first place.

This is the part no single tool can solve for you. As our research with the Ponemon Institute put it, asking an agent-based tool to verify its own coverage is inherently flawed, because an agent that was never installed cannot tell you it is absent. The same is true of everything else you own.

Your scanner can tell you about the things it scanned. Your cloud console can tell you about the accounts you connected to it. Ask any of them what they are not seeing and you will not get an answer, because that information sits outside what they were built to collect.

So the job ends up falling to a person. Someone pulls exports from four or five systems, lines them up in a spreadsheet, works out whether two similar-looking entries are actually the same machine, and eventually arrives at a coverage number. It takes days, it relies heavily on that person's judgment, and the answer describes your environment as it was on the day the exports were pulled.

Most of the security leaders we surveyed told us they could not confidently say which of their assets were missing required controls. Among those who could, most were still getting there through exactly this kind of manual review.

AI is making matters worse

The expansion of artificial intelligence is worsening the coverage gap across three distinct vectors. AI-driven development now enables infrastructure to be provisioned at unprecedented speeds, while simultaneously driving disclosure volumes to record highs and drastically reducing the window for attackers to weaponize newly discovered vulnerabilities.

Teams are building faster than provisioning can keep up with. Standing up a service used to involve a request, an approval, and a handoff, and that sequence was where enrollment happened. It was the moment an agent got installed and the machine entered the inventory. AI development tools have compressed that sequence to a prompt. Engineers stand up model endpoints, vector databases, and agent frameworks in an afternoon, and the automation itself now creates infrastructure: a workflow that provisions a key, queries a production database, and tears itself down before anyone reviews it. 

The fastest-growing part of the estate is the part most likely to be born outside the path that would have covered it.

Vulnerability volume is sky-high. Disclosure set a record in 2025 and has kept climbing through 2026, driven in part by AI-assisted research surfacing bugs faster than the ecosystem can process them. The enrichment layer gave way under the load. In April 2026, NIST moved the National Vulnerability Database to a prioritized model, enriching the vulnerabilities that meet defined criteria and leaving the rest unscheduled.

Programs built around waiting for a severity score are now waiting on a score that may never arrive.

Time to first exploit dropped fast. Mandiant's M-Trends 2026, built from a year of frontline investigations, estimates that the mean time to exploit has gone negative: attackers routinely weaponize vulnerabilities before the patch ships. 

Exploitation of internet-facing systems remained the most common way in for the sixth consecutive year.

These three trends compound in one place. Faster patch cycles, tighter SLAs, and sharper prioritization all operate on the queue. An asset that no tool knows about generates no finding, so it enters no queue and carries no deadline. The first trend keeps adding machines to that category while the other two shorten the time you have to find them.

The case for a single source of truth

If no individual tool can tell you what it is missing, then the answer has to come from something that can see all of them at once. That rules out anything sitting inside the stack next to your existing tools. It also rules out buying yet another inventory product, which would only turn up with blind spots of its own. What you need sits above everything else, treating each of your systems as an input.

It helps to think about how you would actually find a gap. A machine appears in your identity provider and in your cloud console, but never in your endpoint platform. That is a coverage gap, but none of those three systems contains that fact on its own. It only exists once you put all three side by side. Something has to be holding all of them together for the gap to be visible at all.

A layer like this depends on your existing tools rather than competing with them. Your scanner carries on scanning. Your CMDB carries on doing what it does for service management. The layer above collects what each of them reports, works out where they disagree, and produces one description of your environment that you can hold all of them up against.

For that description to be worth anything, it needs three things. It has to connect to every system that holds asset data, because anything you leave out becomes a new blind spot. It has to run continuously rather than once a month, because a monthly comparison only tells you about a time that has passed. And it has to keep track of metadata properly, so that one laptop known to six different tools under six different names is understood to be one laptop. Get that right and every team downstream is working from the same set of facts, and you can finally state what your coverage is and back it up.

Where Axonius fits

Screenshot_2026-08-03_at_11.06.16_AM.png

Axonius is built to be that layer. It connects to the systems you already own across security, identity, cloud, and infrastructure, takes what each one reports, and works through the conflicts to build a single model of your environment. Coverage comes out of that model rather than out of any one tool, which is how assets that have never appeared in a console become visible.

Those connections work in both directions. When a gap turns up, Axonius will kick off the workflow to deploy the missing agent, apply the policy that never took effect, and raise a ticket with the team that owns the machine, then check on the next sync that the fix actually held. Because that check keeps repeating, you also end up with something worth showing an auditor or a board: evidence of where your controls genuinely apply, instead of a number somebody assembled by hand the week before the meeting.

The real problem was never discovering assets. It was proving that every asset is covered by the controls your security program depends on. As environments become more dynamic and attackers move faster, that proof has to come from continuous verification rather than periodic audits. That's the role Axonius is built to play: connecting the evidence you already have, exposing the gaps no individual tool can see, and ensuring those gaps stay closed.

See how Axonius can help you close the coverage gap: Get a Demo

Categories

  • Artificial Intelligence Ai
  • Threats Vulnerabilities
Get Started

Get Started

See how to make asset intelligence actionable with a guided demo:

  • Stop chasing data — work from one asset model your entire team can trust.
  • See what's exposed before it's a problem — surface coverage gaps automatically.
  • Turn alert noise into action — cut thousands of alerts down, to the ones that matter.