Security · September 18, 2026

Also published in Português (Brasil)

Spanish Authority Reports Data Breach Potentially Executed by AI Agent

an aerial view of a large industrial building
Geoffrey Moffett / Unsplash

The Agencia Española de Protección de Datos received a notification regarding a personal data breach that was apparently carried out using an artificial intelligence agent based on a known language model.

According to the organization affected by the incident, the agent allegedly searched for vulnerabilities, gained system access, performed further checks, modified personal data, and accessed invoices. These details remain to be verified, as the information was provided in a notification and does not constitute a final reconstruction of the event. It is not yet known which specific vulnerability, credential, or configuration allowed the access, nor is it clear what instructions, tools, or permissions the agent possessed or the level of human intervention involved.

There has been no confirmed exfiltration of data. The use of a language model in this sequence does not indicate that the model itself or the infrastructure of its producer were compromised.

The incident highlights the technical concept of autonomy, where an agent can execute an operation, observe the result, and adapt the next step within its instructions. This ability to chain reconnaissance, credential use, privilege verification, and data access rapidly may reduce the time available for defenders to detect and contain an intrusion. This scenario suggests that defensive processes must adapt to offensive automation, as tasks previously performed by humans may now occur at machine speed.

From a regulatory perspective, the General Data Protection Regulation does not require a specific category for artificial intelligence attacks. Articles 24 and 32 already require controllers to implement technical and organizational measures appropriate to the risk, considering the state of the art. Article 32 specifically addresses the confidentiality, integrity, availability, and resilience of systems, as well as the regular verification of measure effectiveness. Articles 5, paragraph 2, and 25 further establish accountability and data protection by design and by default.

The regulation does not mandate a specific product or a universal time limit for blocking intrusions but requires an assessment based on concrete risks. If data can be reached or modified before an organization recognizes anomalous access, the actual defense timing becomes a factor in verifying adequacy. Additionally, Article 35, paragraph 11, provides for the review of a data protection impact assessment when necessary, particularly if the risk posed by processing operations changes.