A landmark study published this month by 38 researchers from Northeastern University, Harvard, MIT, Stanford, Carnegie Mellon, Hebrew University, and the University of British Columbia has delivered the most rigorous empirical validation to date of a principle VectorCertain LLC has been engineering into silicon and software for five years: AI agents cannot govern themselves, and no amount of model improvement will change that.
The study, titled "Agents of Chaos" (arXiv:2602.20021), led by Natalie Shapira and David Bau of Northeastern University's Baulab, deployed six autonomous AI agents with real tools, data, and access. Twenty AI researchers spent two weeks attempting to compromise them. The agents failed catastrophically: they disclosed Social Security numbers and bank account details, accepted spoofed identities, entered infinite loops, and even destroyed their own mail servers. The researchers concluded that "effective containment requires controls that operate independently of the model."
VectorCertain, founded by Joseph P. Conroy, had already built exactly that: a four-gate Hub-and-Spoke governance architecture that evaluates every agent action before execution. The architecture addresses the three structural deficiencies identified in the study: lack of a stakeholder model, lack of a self-model, and lack of audience awareness. VectorCertain's SecureAgent platform uses external gates to verify authorization, evaluate action scope and proportionality, classify output data, and ensure governance model independence.
The study's findings align with VectorCertain's approach. The researchers noted that vulnerabilities like prompt injection are not bugs but properties of how large language models process sequential input. In-model defenses can be overridden by sufficiently crafted input. VectorCertain's gates operate outside the agent's conversational context, making them immune to such manipulation.
VectorCertain's claims are independently validated. The company's SecureAgent platform satisfied all 230 control objectives of the U.S. Treasury's Financial Services AI Risk Management Framework and achieved a TES score of 1.9636 out of 2.0 (98.2%) in internal evaluation against MITRE ATT&CK methodology. The platform has a false positive rate of 1 in 160,000, 53,333 times lower than the EDR industry average.
The urgency of governance is underscored by market data: the AI agent market reached $7.6 billion in 2025 with 50% projected annual growth, and 160,000+ organizations already run autonomous agents. Yet Kiteworks' 2026 report found that 63% of organizations cannot enforce purpose limitations on AI agents and 60% cannot terminate a misbehaving agent.
VectorCertain holds 55+ provisional patents protecting its architecture. The company's founder, Joseph P. Conroy, authored "The AI Agent Crisis" (Amazon, September 2025), which documented the systemic failures the study has now confirmed.
For more information, visit www.vectorcertain.com.


