Downloaded file might be bypassed instead of being blocked by DLP
Both DLP blade and Threat Emulation blade are inspecting the downloaded file. Threat Emulation might fail to process the file (e.g., no entitlement or internal error), and goes into Fail-open mode.
Although the logged action of DLP blade would be "Prevent", the actual action would be "Detect". As a result, the file would be bypassed.