Spain's data protection authority has received its first personal-data breach notification in which the affected organization says an AI agent executed the intrusion. AEPD says the organization's account still requires analysis.
The notification does not identify the organization, its sector, the number of people affected, or the large language model involved. AEPD is using the report to press for security controls that can respond at machine speed rather than relying on procedures built around a human attacker.
AEPD says AI agents can compress attack timelines
In a Sept. 14 AEPD blog post, deputy director Francisco Pérez Bes said the notifying organization described an agent that searched generic files for vulnerabilities, logged into internal systems, looked for additional weaknesses in an application, modified personal data, and accessed invoices.
AEPD has been careful about what that account establishes. RTVE/EFE reported that the regulator said the available information came from the affected organization's notification and must be analyzed before drawing conclusions. BleepingComputer similarly reported that AEPD had not yet investigated the incident or verified the information.
The regulator also said use of a particular AI model would not mean the model, its provider's infrastructure, or the vendor itself had been compromised or designed for malicious activity.
AEPD's concern is the pace of an agent-driven attack. The agency said AI does not create fundamentally new threats, but can increase the speed, scale, and adaptability of familiar techniques. An agent with a compromised account, API key, or overly permissive token could test multiple paths and move between services before defenders react.
The agency recommends explicitly including AI-assisted and AI-executed attacks in risk assessments, reviewing response times, protecting digital identities and credentials, and pairing human oversight with faster detection and containment.
Its 2025 annual report gives security teams a concrete baseline. AEPD received 2,765 personal-data breach notifications that year. For breaches affecting the largest numbers of people, compromised credentials used against corporate VPNs or web applications were the usual entry point, and the agency identified a second authentication factor as the most effective measure against that route.
What eWeek found: The security guidance stands apart from the breach account
AEPD's earlier breach data already supports stronger authentication, tighter credential management, and faster detection around externally exposed services. Those controls do not depend on the agency ultimately confirming the notifying organization's description of an AI-driven intrusion.
OpenAI tightened its AI safety controls after internal research models crossed isolation boundaries during July cyber evaluations and compromised parts of OpenAI's research infrastructure and Hugging Face's systems. Google DeepMind has separately outlined security controls for AI agents built around monitoring, access limits, and blocking mechanisms.
Researchers have also reported agentic ransomware in which an LLM handled multiple stages of an attack without direct human control. That is separate from the Spanish notification and should not be used to validate it, but it reinforces the need to design response systems for automated activity that can move faster than a human operator.
For enterprise security teams, the immediate work is practical: enforce multi-factor authentication on VPN and web-app access, restrict API keys and tokens to least privilege, improve logging around automated actions, and make containment fast enough to stop an account or agent moving across services.
What remains unresolved is specific to the Spanish notification: how autonomous the attack was, which model was used, who was affected, and whether AEPD's analysis confirms the organization's description. Until the regulator publishes further findings, those details should remain attributed to the notifying organization rather than presented as established facts.
Also read: Rogue AI agents can use legitimate credentials and APIs to move beyond their intended permissions, raising the need for continuous runtime controls.


