Spain's data regulator logs the first breach notification attributed to an autonomous AI agent
The AEPD says a third party used an agent powered by a known large language model to log in, hunt for application flaws, alter personal data and read invoices.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.
The Spanish Data Protection Agency (AEPD) has published details of what it describes as the first notification of a personal data breach carried out by design through an AI agent. According to the notifying organization, the agent, powered by a known large language model, began by searching for vulnerabilities in generic files and successfully logged in. Once inside, it autonomously probed the application for further flaws, then modified personal data and accessed invoices. 'What is relevant from a data protection perspective,' the AEPD wrote, 'is that a third party would have used an AI agent as an instrument to successfully chain together different phases of the attack.' The agency calls this a qualitative change, since an agent can take a goal, plan intermediate tasks, use tools, execute code, consult sources and adjust its actions on its own. The AEPD has not yet investigated or verified the report, and SecurityWeek notes the agency chooses its words carefully. Still, the agency says AI-related breaches are no longer theoretical. It argues AI does not create new threats but raises the speed, scale and adaptability of attacks while shrinking defenders' response margins, a shift Spain's National Cryptologic Center has also highlighted. SecurityWeek characterizes the case as the first known agentic attack outside of a rogue frontier-model agent. The AEPD says organizations' risk management should now explicitly account for AI-assisted and AI-driven attacks, since automation changes an incident's likelihood and speed.