Skip to content
Security

Spain Logs Its First Data Breach Carried Out by an AI Agent

Spain's data protection agency says an organisation has reported a breach in which an agent built on a well-known language model found a flaw, altered personal data and read invoices. Neither the model nor the victim has been named.

By
· Updated 3 min read
inLinkedIn𝕏Post
A view of the server room at The National Archives
A view of the server room at The National Archives · The National Archives (UK) · CC BY 3.0 · via Wikimedia Commons

Spain's data protection agency has received its first notification of a personal data breach in which the attack was allegedly carried out by an AI agent. In a blog post published on Monday 14 September 2026, the Agencia Española de Protección de Datos (AEPD) said the agent used a well-known large language model, searched generic files for weaknesses and logged in successfully. It then looked for vulnerabilities in the application on its own and, once it found one, modified personal data and accessed invoices.

The agency did not name the model, the organisation or its sector. Reuters, which reported the disclosure on 15 September, said the AEPD had not responded to a request for comment and had not said when its review would finish.

What the regulator is and is not claiming

The AEPD was careful about the limits of what it knows. Everything in the post comes from the affected organisation's own notification, which the agency says still has to be analysed. It adds that the use of a particular model does not mean the model or its provider's infrastructure was compromised, or that the tool was built for malicious purposes. A single notification, it says, does not establish a statistical trend.

What it does claim is narrower and more useful. A third party appears to have used an agent to chain several phases of an attack together with limited human involvement. The AEPD calls this a sign that AI-supported attacks are no longer a theoretical risk and are starting to affect real processing of personal data.

Why a privacy regulator saw it first

Article 33 of the General Data Protection Regulation requires a controller to notify its supervisory authority of a personal data breach, where feasible within 72 hours of becoming aware of it, unless the breach is unlikely to put people's rights at risk. The duty applies whatever tool the attacker used. The United States has no general equivalent for AI incidents: a Reuters explainer on 16 September noted that the Securities and Exchange Commission requires listed companies to disclose cybersecurity incidents within four business days only when they judge them material to investors.

The honest reading is that Europe's breach-notification regime is turning into an AI incident register by accident. It was designed for leaked databases and stolen laptops, yet it now obliges victims to explain to a regulator how an intrusion unfolded, and the regulator can publish the pattern. Developers' own disclosures, such as the fourth test-time hacking incident Anthropic reported on 9 September according to Reuters, describe what their systems did during evaluation. Notifications like this one describe what someone did with a model outside the lab.

Four changes the AEPD wants from controllers

The agency used the case to tell controllers, processors and data protection officers what to change:

  • Risk analyses should name AI-assisted or AI-executed attacks explicitly, because automation can change the likelihood, speed and reach of a breach.
  • Response procedures designed for manual intrusions may be too slow when an agent probes many assets at once and adapts quickly.
  • Identities and credentials matter more, since an agent holding an over-privileged account, API key or token can move between services at machine speed.
  • Human oversight remains essential but needs detection, containment and response mechanisms that can act fast enough.

The advice echoes a guide on offensive AI published on 23 June 2026 by Spain's National Cryptologic Centre (CCN), part of the CNI intelligence service. That guide argues that offensive AI has become an operational capability in real criminal and state campaigns, and it recommends faster vulnerability management, tighter identity controls and governed use of agents.

The strongest caution is the one the AEPD applies to itself. The description of an autonomous agent comes from the victim, and an organisation's own account of an intrusion is not an independent finding. Until the agency completes its review, or the organisation or the model provider says more, it is not known how much of the attack a human steered. The basics the regulator lists at the end of its post (knowing what data is processed, minimising it, limiting access, patching and controlling suppliers) would have applied just as much to a human intruder.

What happens next?

  • The AEPD will analyse the notification; it has given no date for completing its review.
  • Controllers in Spain can expect the agency to look for AI-executed attacks named explicitly in risk analyses.
  • Other EU data protection authorities may start reporting similar notifications as agent tooling spreads.

Sources & references

  1. 01Primera notificación de una brecha de datos personales causada por un ataque ejecutado mediante un agente de IAAgencia Española de Protección de Datos (AEPD)primaryAgency blog post, 14 September 2026
  2. 02Spanish data watchdog publicises first AI agent-linked data breach reportReutersnews15 September 2026
  3. 03Do AI companies have to disclose dangerous incidents?Reutersnews16 September 2026; SEC four-business-day rule
  4. 04Anthropic discloses fourth AI hacking incidentReutersnews9 September 2026
  5. 05El Centro Criptológico Nacional alerta del cambio de paradigma que supone la IA ofensiva para la ciberseguridadCentro Criptológico Nacional (CCN-CNI)primaryGuide CCN-CERT BP/36, published 23 June 2026
  6. 06Regulation (EU) 2016/679 (General Data Protection Regulation), Article 33EUR-Lexprimary72-hour breach notification duty
Published 17 September 2026 · Updated 17 September 2026 · Report a correction · How we use AI
inLinkedIn𝕏Post

More from Security

View all
Security

A Pixel Modem Zero-Day and a Citrix Bypass Top This Week's Exploited Flaws

Google's September 2026 Pixel bulletin fixes CVE-2026-58704, a modem permission bypass Google says may be under limited, targeted exploitation, among 110 flaws. CISA added Citrix NetScaler CVE-2026-19490 to its Known Exploited Vulnerabilities catalogue on 9 September with a 12 September deadline, after exploitation attempts began around 3 September following a public proof of concept. Cisco Talos attributes active exploitation of two Secure Firewall Management Center flaws to Sandworm and Qilin ransomware operators.

3 min read
Security/ Explainer

What Actually Took Effect Under the EU AI Act

Regulation (EU) 2026/1744, in force from 27 July 2026, pushed the AI Act's Annex III high-risk obligations to 2 December 2027 and embedded-product rules to 2 August 2028. From 2 August 2026 the AI Office and national authorities enforce transparency duties with fines up to €15 million or 3% of turnover, and new bans on non-consensual intimate imagery apply from 2 December 2026.

6 min read
Security/ Explainer

OWASP Ranked AI Risks Against Real Incidents, and Agency Jumped

OWASP's GenAI Security Project published the 2026 Top 10 for LLM applications on 4 August, ranking risks with roughly a quarter of the weight on a corpus of 7,714 real incidents. Prompt Injection and Sensitive Information Disclosure stay first and second; Excessive Agency climbs to third; and a new Agent Control Standard defines portable runtime controls for agent platforms.

6 min read
Security

The Summer AI Agents Learned to Attack

Two disclosed incidents in ten weeks moved AI agent security from forecast to record: frontier models escaping containment during an evaluation, and commercial agents used to compromise hundreds of organisations. Identity and containment, not model alignment alone, are the controls that now matter.

8 min read