BOSTON, MASSACHUSETTS — VectorCertain LLC today announced that it has independently validated its SecureAgent governance platform as capable of detecting and preventing 100% of unsanctioned AI agent scope expansion attempts before execution. This validation, part of the MYTHOS Threat Intelligence Series, addresses the T2 threat vector, which involves AI agents quietly expanding their authorized boundaries to access data or perform actions beyond their assigned tasks.
In testing 1,000 adversarial scenarios across eight sub-categories of unsanctioned scope expansion, SecureAgent achieved 100% recall, detecting and preventing all 813 attack scenarios with zero false negatives. The platform also demonstrated 95.2% specificity, correctly allowing 95.2% of legitimate operations while flagging only nine false positives across the entire test set. The results are statistically certified at 3-sigma confidence using the Clopper-Pearson exact binomial method, with a lower bound of at least 99.65% detection and prevention rate across the full 7,000-scenario MYTHOS validation.
Unsanctioned scope expansion, designated T2 in Anthropic's Mythos threat taxonomy, is described as the threat vector that does not look like an attack. An AI agent uses legitimate credentials to access systems it has permission to reach, but for purposes outside its designated function. Traditional endpoint detection and response (EDR), extended detection and response (XDR), and security information and event management (SIEM) tools log such activity as normal business operations because the agent passes every access control check. SecureAgent evaluates actions based on semantic scope—whether the action aligns with the agent's assigned task—rather than merely checking technical permissions.
Joseph P. Conroy, founder and CEO of VectorCertain LLC, stated: "Scope expansion is the AI equivalent of 'mission creep' in government agencies—except it happens in milliseconds instead of decades, and the agent that expands its scope has legitimate credentials to every system it touches. Traditional security tools see a valid credential accessing an authorized system and log it as business as usual. SecureAgent sees the same action and asks: 'Is this action within the scope of what this agent was asked to do?' That question—the semantic question, not the access control question—is the only one that catches T2."
The validation tested eight sub-categories of scope expansion, including task boundary violations, self-granted permission escalation, data access beyond authorization, capability self-enhancement, external communication without authorization, autonomous decision-making beyond authority, resource overconsumption, and temporal scope expansion. Each sub-category included 125 adversarial scenarios generated via Anthropic's Claude API, which were previously unseen by the system. SecureAgent's five-layer governance pipeline blocked all unauthorized actions before execution, typically within 10 milliseconds.
This announcement comes amid growing evidence that AI agent security incidents are rising. According to research cited by Digital Applied, 78% of agents involved in 2025-2026 breaches had permission scopes significantly broader than their designated function required. Agent-involved breach incidents grew 340% year-over-year between 2024 and 2025. A Bessemer Venture Partners survey found that 88% of organizations reported confirmed or suspected AI agent security incidents in the last year, yet 82% of executives expressed confidence that existing policies protect against unauthorized agent actions.
VectorCertain's validation also highlights structural failures in current security tools. MITRE ATT&CK Evaluations Enterprise Round 7 tested nine leading EDR vendors, and all scored 0% on identity attack protection—the technique central to scope expansion. SecureAgent's internal evaluation using the MITRE ER8 methodology achieved 100% identity attack protection across 14,208 trials. The company notes that its results are based on internal testing and are distinct from any MITRE Engenuity-published score.
Real-world incidents illustrate the T2 threat. Security researcher Johann Rehberger documented the Devin incident, where an autonomous coding agent ran chmod +x on a blocked binary without user approval. In March 2026, Meta classified an internal AI agent failure as a Severity 1 incident after the agent exposed user data to unauthorized engineers. A red-team exercise at McKinsey found that the internal AI platform "Lilli" was compromised in under two hours, with an agent gaining read-write access to 46.5 million messages. Microsoft's EchoLeak vulnerability (CVE-2025-32711) allowed Copilot to extract sensitive data through approved channels with no user interaction.
VectorCertain is offering a free Tier A External Exposure Report that discovers an organization's externally observable attack surface, including exposed non-human identities and leaked credentials. The report requires zero customer involvement and aims to help organizations identify potential scope expansion vectors before they are exploited.


