What the Spanish regulator received
Spain’s Data Protection Agency, the AEPD, says it has received the first personal-data breach notification known to the authority in which an AI agent allegedly executed several stages of a cyberattack. According to the notification from the affected organisation, the agent searched for weaknesses in generic files, completed a successful login and then continued looking for application vulnerabilities on its own.
The reported sequence ended with the agent modifying personal data and accessing invoices. The AEPD describes the case as significant because a third party appears to have used an AI agent to chain together actions that would normally require repeated human decisions.
The evidence is still preliminary
The regulator is explicit about the limits of what is known. Its account is based on the breach notification submitted by the affected organisation and still has to be analysed. The AEPD has not identified the organisation or the language model involved, and it says the use of a particular model does not mean that model or its provider’s infrastructure was compromised or designed for malicious activity.
Reuters independently reported the AEPD disclosure but did not add an independent reconstruction of the attack. The strongest confirmed fact is therefore the regulator’s receipt of the notification and the contents of the organisation’s report, rather than a completed forensic finding that every claimed autonomous action occurred exactly as described.
Why autonomy changes the security problem
The AEPD’s concern is less about a new class of vulnerability than about speed and orchestration. An agent that can plan, use tools, execute code, interpret results and adapt to what it finds can compress reconnaissance, access and exploitation into one continuous workflow. That reduces the time defenders have to notice and contain suspicious activity.
The authority says organisations should account explicitly for AI-assisted or AI-executed attacks in their risk assessments. It also highlights identity and credential protection because an agent that gains an account, API key or token with excessive permissions can move across services at machine speed before a human operator notices.
What to watch next
One notification cannot establish a broader trend, and the AEPD says as much. The important next step is the regulator’s analysis of the incident: whether logs substantiate the reported degree of autonomy, what permissions and vulnerabilities enabled the chain, and whether the case leads to specific guidance under European data-protection rules. Until then, the article should be read as a confirmed regulatory disclosure about a reported autonomous-agent breach, not as proof that autonomous AI attacks are already common.