Spanish data watchdog publicises first AI agent-linked data breach report
A demonstrator holds a sign calling for regulation of artificial intelligence during a protest outside the G20 Innovation Ministerial summit, in Chapel Hill, North Carolina, U.S., September 2, 2026. REUTERS/Jonathan Drake/
Read a summary of this article on FAST.
Get bite-sized news via a new
cards interface. Give it a try.
Click here to return to FAST
Tap here to return to FAST
FAST
MADRID, Sept 15 : Spain’s data protection watchdog said it has received the first reported notification of a personal data breach allegedly carried out by an artificial intelligence agent, a case that suggests autonomous systems are beginning to play a direct role in cyberattacks.
The Spanish Data Protection Agency (AEPD) said on Monday in a blog on its website that the incident involved an AI agent using a widely known large language model to identify vulnerabilities, gain access to a system and subsequently modify personal data and access invoices.
The agency said that the alleged breach was reported to it by the affected organization and the information remains under review, adding the use of a particular AI model did not mean either the model itself or its provider’s infrastructure was compromised, nor that the technology was developed for malicious purposes.
AEPD did not immediately respond to a Reuters request for comment, nor identify the large language model or the organization targeted by the breach.
![]()
Guess Word
Crack the word, one row at a time
![]()
Buzzword
Create words using the given letters
![]()
Mini Sudoku
Tiny puzzle, mighty brain teaser
![]()
Mini Crossword
Small grid, big challenge
![]()
Word Search
Spot as many words as you can
The agency said the case was relevant because a third party allegedly used an AI agent to carry out multiple stages of an attack with limited human intervention, highlighting the growing role of autonomous systems in cybersecurity incidents.
The incident comes as regulators and cybersecurity authorities across the United States and Europe increase scrutiny of the risks posed by increasingly capable AI systems, even as businesses adopt the technology at a rapid pace.
PRIORITISING PUBLIC SAFETY
Spain has positioned itself as one of Europe’s most vocal advocates of a “trustworthy AI” model that protects privacy, democracy, minors and public safety rather than prioritising speed or profit for the tech industry.
While a single case is insufficient to establish a broader trend, the notification suggests that AI-assisted attacks are moving beyond the theoretical stage and are beginning to affect real-world processing of personal data, AEPD added.
According to the notification submitted by the affected organisation, the agent successfully logged into the system before autonomously searching for application weaknesses. After identifying a vulnerability, it was able to alter personal information and view billing records.
The Spanish watchdog did not say when it would finish reviewing the reported breach.
The agency said AI does not create new threats. However, it increases the speed, scale and adaptability of existing malicious techniques, reducing the time available to detect and contain them.
Controllers, processors and data protection officers must prepare for a scenario in which the speed of attacks will continue to increase, the agency added.
Source: Reuters
Sign up for our newsletters

Get the CNA app
Stay updated with notifications for breaking news and our best stories
Get WhatsApp alerts
Join our channel for the top reads for the day on your preferred chat app

Get bite-sized news via a new
cards interface. Give it a try.
Click here to return to FAST
Tap here to return to FAST
FAST














