A recent House Permanent Select Committee on Intelligence roundtable on gray-zone threats in a contested U.S. homeland put language to a problem that counterintelligence practitioners have felt for years without always naming it. The committee’s homeland-CI discussion described a threat made of low-signal indicators — activity that never rises to the level of a single case file, and that slips through programs built to work discrete investigations one at a time.

That description deserves attention, because it identifies a structural blind spot rather than a gap in awareness or effort.

What Makes a Gray-Zone Campaign Different

A conventional counterintelligence case has a shape. There is an event, a subject, a set of indicators, and a file that holds them together. Gray-zone campaigns are engineered to avoid that shape. They operate below the threshold of any one case, source, or report, distributing their signature across many small interactions and across long stretches of time. Any single fragment looks like noise, a coincidence, or a low-priority lead that doesn’t justify sustained attention. The campaign exists only in the aggregate — in the relationship between fragments that were never filed together.

It isn’t that the indicators are hidden. It’s that they are distributed, and distribution defeats a system designed to work one case at a time.

Why Case-Centric Programs Miss the Pattern

Most CI programs are organized around the case file. Work is assigned by case, measured by case, and closed by case. That structure is good at what it was built for: driving a discrete investigation to resolution. But it leaves the connective tissue between cases unowned:

None of that belongs to any single case, so none of it gets worked. The result is a program that can be doing everything right at the case level and still miss the campaign entirely. The fragments were all collected. They were simply never connected.

Detection Is a Data Problem, Not a Diligence Problem

Because the threat lives in the aggregate, detecting it is a matter of seeing across the whole data surface — linking entities that recur across files, and recognizing patterns that span cases and time. That is fundamentally an entity-linking and pattern-recognition challenge, and it is not one that more analysts working more cases in isolation can solve. Adding staff to a case-centric model produces more well-worked cases and more disconnected files. It does not produce the cross-case picture the campaign hides in.

The programs that close this gap are the ones that treat their entire body of reporting as a single analytic surface, not a stack of separate folders.

Where AxIS Fits

This is the specific problem AxIS is built to address. Instead of confining analysis to one case at a time, AxIS applies AI-assisted analysis and entity linking across a program’s full data surface, surfacing the entity that recurs and the pattern that spans files. The mosaic assembles while the indicators are still low-signal — before the pattern becomes an indictment. That is the Clear-Box model in practice: a program that can see the state of its own mission across every case, rather than reconstructing the connections after the fact.

Gray-zone threats are designed so that no single alarm ever trips. The programs that catch them are the ones that stopped waiting for one to.

Test your defenses against the actors operating right now.

Engage Sphinx for a RECON assessment, RedShift emulation, or Helix managed defense.

Get Started