This is by design - for any permission criterion which regular users can reach by doing the right things (e.g. confirming email or gaining points), experts and other special users get the permission automatically. I think this makes sense because special users are assigned manually by the admin, so presumably they are at least as trustworthy as regular users who have done any particular thing. But perhaps this doesn't make sense in your case - it should not be difficult to fix with a plugin that overrides the qa_permit_error(...) function in Q2A 1.5.