It is bypassing because you have fail-open (the default) set under Manage & Settings...Blades...Threat Prevention...Advanced Settings...General Settings...Fail Mode. This setting still controls the Inspections Settings protections too even though they are part of the Access Control policy now (but didn't used to be).
A situation occurred in which the inspection engine could not properly scan the traffic due to it being out of state, and the default behavior is to let it through. Be careful about setting fail-close here since any traffic that cannot be properly scanned will be denied. There are many, many situations that this can apply to that you may not be expecting, such as a password-protected zip file or a file larger than 150MB being encountered with certain types of inspection set. These will start getting denied if you change this setting.
This setting is covered in the new Check Point Threat Prevention Specialist 2-day course, which was released to ATCs worldwide last month. I recently ran this class for the first time and it got rave reviews for its detailed coverage of IPS (including Inspection Settings), AV, and ABOT.
Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com