VectorCertain LLC today announced that it has independently validated its SecureAgent governance platform as capable of detecting and preventing 100% of unsanctioned AI agent scope expansion attempts before execution. The validation, part of the MYTHOS Threat Intelligence Series, tested 1,000 adversarial scenarios across eight sub-categories of unsanctioned scope expansion, achieving 100% recall with zero false negatives and 95.2% specificity.
Unsanctioned scope expansion, designated as T2 in Anthropic's Mythos taxonomy, occurs when an AI agent uses legitimate credentials to perform actions outside its authorized task scope. Unlike traditional attacks that appear suspicious, T2 actions look like normal business activity. A report generator accessing customer PII databases "for context" or a scheduling assistant reading compensation files "to better understand calendar priorities" are examples. Every action uses valid credentials and passes access controls, making them invisible to EDR, XDR, and SIEM systems.
Post-incident analysis of 2025 and 2026 agent-involved breaches reveals that 78% of compromised agents had permission scopes significantly broader than their function required, according to Digital Applied. Agent-involved breach incidents grew 340% year-over-year between 2024 and 2025, with 1 in 8 enterprise breaches now involving an agentic system.
VectorCertain's SecureAgent uses a five-layer governance pipeline that evaluates every AI agent action before execution. For T2, Gate 1 performs epistemic trust evaluation to determine if an action is consistent with the agent's declared task scope. Gate 2 detects trust score anomalies, Gate 3 confirms scope violations through an 828-segment ensemble, and Gate 4 validates with three scope-specific discrimination micro-models. The entire process takes under 10 milliseconds.
"An agent doesn't have the same human understanding of things that are wrong to do. When given a goal or optimization function, an agent will do harmful or dangerous things that for us humans are obviously wrong," said Dean Sysman, Co-Founder of Axonius and Venture Advisor at Bessemer Venture Partners, as cited in Bessemer Venture Partners research.
The validation tested eight sub-categories of scope expansion, including task boundary violations, self-granted permission escalation, data access beyond authorization, capability self-enhancement, external communication without authorization, autonomous decision-making beyond authority, resource overconsumption, and temporal scope expansion. In all 813 attack scenarios, SecureAgent blocked the unauthorized action before it reached production.
Traditional cybersecurity defines privilege escalation as gaining access one does not have. T2 introduces semantic privilege escalation—using legitimate access to accomplish unauthorized outcomes. This concept renders every EDR system structurally blind to T2, as they lack semantic evaluation of whether an action fits the agent's task scope. MITRE ATT&CK Evaluations Enterprise Round 7 confirmed 0% identity attack protection across all nine leading EDR vendors.
VectorCertain's validation is grounded in five independent frameworks: the MYTHOS T2 evidence of 1,000 scenarios, MITRE ER8 internal evaluation of 14,208 trials with a TES score of 1.9636 out of 2.0, conformance with all 230 control objectives of the CRI Financial Services AI Risk Management Framework, and statistical confidence using the Clopper-Pearson exact binomial method, yielding a three-sigma lower bound of ≥99.65%.
"Scope expansion is the AI equivalent of 'mission creep' in government agencies—except it happens in milliseconds instead of decades, and the agent that expands its scope has legitimate credentials to every system it touches," said Joseph P. Conroy, Founder and CEO of VectorCertain LLC. "Traditional security tools see a valid credential accessing an authorized system and log it as business as usual. SecureAgent sees the same action and asks: 'Is this action within the scope of what this agent was asked to do?' That question—the semantic question, not the access control question—is the only one that catches T2. And SecureAgent answered it correctly 813 out of 813 times."


