
Artificial intelligence is increasingly being used to automate legitimate tasks, but Spain’s data protection regulator says it has now received a report of an incident in which an AI agent was allegedly used to carry out a personal data breach.
The Spanish Data Protection Agency, or AEPD, said it received the first notification of a personal data breach in which an AI agent was reportedly involved in executing the attack. The agency published details of the case on September 14, describing it as an important development in the growing use of autonomous AI systems.
According to the information submitted by the affected organisation, the agent used a widely known large language model to identify weaknesses, gain access to a system and then move through an application. It allegedly modified personal data and accessed invoices.
The AEPD stressed that the case remains under review, so the account should not be treated as a final determination of what happened or who was responsible.
How the AI agent allegedly carried out the attack
The incident is notable because the AI agent was reportedly involved across multiple stages of the attack rather than being used simply as a tool for generating code or advice.
Based on the affected organisation’s notification, the agent searched for vulnerabilities, successfully accessed the target system and continued looking for weaknesses after gaining entry.
It then allegedly altered personal information and accessed invoice records.
The AEPD said the incident involved limited human intervention in the execution of those stages. The disclosure does not establish, however, that the AI independently chose the victim or originated the overall objective. A third party was reportedly using the agent as part of the attack.
That distinction is important. An AI agent can autonomously decide how to break a broader task into steps and use available tools, but it still operates within objectives, permissions and infrastructure established by humans.
The AI model itself was not hacked
The AEPD also sought to separate the reported misuse of the technology from the security of the underlying AI model.
Using a particular large language model in an attack does not mean that the model itself was compromised, the agency said. Nor does it mean that the model provider’s infrastructure was breached or that the technology was designed for malicious purposes.
This is a crucial distinction as AI agents become more common.
Traditional generative AI systems primarily produce information in response to prompts. Agentic AI systems can go further by planning tasks, making decisions, accessing external resources and executing actions with varying degrees of autonomy. The AEPD has separately published guidance warning that this autonomy creates additional privacy and data-protection risks.
Why AI agents could change cyberattacks
The AEPD’s warning is less about AI creating an entirely new category of cyber threat and more about what happens when existing attack techniques can be automated.
An AI agent can potentially search systems, adapt its approach, process information and perform multiple actions at machine speed. That could shorten the time defenders have to detect unusual activity and intervene.
The Spanish regulator said AI can accelerate, scale and make existing malicious techniques more flexible, increasing the pressure on organisations responsible for protecting personal information.
That concern is particularly relevant under Europe’s General Data Protection Regulation, or GDPR, where organisations must assess personal data breaches and notify the competent supervisory authority when a breach is likely to create a risk to people’s rights and freedoms.
Why this case matters for companies
For businesses, the incident highlights a difficult security problem: traditional safeguards may have been designed primarily around human users, while AI agents can operate differently.
An agent with access to software tools, credentials, databases or external services may be capable of moving through several systems without requiring a person to approve every individual action.
The AEPD’s own guidance on agentic AI recommends considering the level of autonomy granted to an agent and the ways it can access, update, combine or transfer data. Its framework ranges from systems in which humans perform the actions proposed by an agent to systems in which the agent operates while a human merely observes.
That means organisations may need to think about AI agents not simply as software assistants, but as actors capable of interacting directly with sensitive digital environments.
Is this proof that AI is becoming an independent hacker?
Not exactly.
The Spanish case is significant because an AI agent was allegedly used to execute a substantial part of a real cyberattack. But the regulator has not said that the machine independently decided to attack the organisation or developed its own malicious intent.
The incident was reported by the affected organisation and remains under examination by the AEPD. Details such as the identity of the organisation, the specific AI model involved, the timing of the attack and the full extent of the accessed data have not been publicly disclosed.
That makes the case an early warning signal rather than evidence of a broad new wave of autonomous AI attacks.
The bigger shift toward agentic AI
The timing is notable because regulators are increasingly focusing on AI systems that can act rather than merely generate content.
The AEPD published dedicated guidance on agentic artificial intelligence earlier this year, examining privacy, data access, accountability and security issues created by systems capable of taking actions autonomously.
The newly disclosed breach puts those theoretical concerns into a real-world regulatory context.
For cybersecurity teams, the challenge is therefore evolving. Protecting systems may no longer mean simply blocking malicious software or suspicious human logins. It may also require monitoring what autonomous software agents are permitted to access, what actions they can take and how quickly they can move when something goes wrong.