what does low risk means?
It's like low cloud reputation. It won't be detected when scanning or RTP, but with download protection it will show it's a risky file and let you decide to allow or not.
And sad is that this kind of cloud feedback is also not new... It's like the standard EDR function that implemented a long time ago in Chinese version.
360 Endpoint Detection and Response working like this:
RTP/scanning found unknown file -> auto upload -> Analysis/Verdict in 5 min -> hips/scan component auto response/detect to new threat
In previous version, TS only upload unknown when manually scanning and need of your confirmation. The TS cloud is also set to be low sensitive in detection( for low FP).
I could see in the recent updates they gradually enhance this cloud feedback system and now it almost has the same cloud protection level as the Chinese version, but still, the framework of 360 cloud hips/proactive defense is old and cloud QVM detection is not integrated in hips.
I guess the reason for this late is due to false positive and privacy concern.