The Pulse
Spain Reports First AI-Agent Personal Data Breach
No quotation available: the AEPD blog entry was checked for an attributable verbatim statement, but it contains no quotation suitable for publication.

AI.info Team ·
One notification, four stages of an attack
Spain’s data protection authority has received its first notification of a personal data breach allegedly carried out by an artificial intelligence agent. The Spanish Data Protection Agency, known as the AEPD, says the agent used a well-known large language model to search for vulnerabilities, complete a valid login, inspect an application and then alter personal data while accessing invoices.
The agency published the account on September 14, 2026, in a blog post written by Francisco Pérez Bes, its appointed deputy. The AEPD has not identified the organization affected, the model involved or the number of people whose data may have been exposed.
The account describes an incident reported by the affected organization, not a final finding by the regulator. The AEPD says the information remains subject to analysis and that the first notification cannot establish a statistical trend.
The AEPD separates the agent from the model provider
The agency also cautions against reading the incident as evidence that the language model or its provider’s infrastructure was compromised. Use of a particular model does not mean that the model was designed for malicious activity, the AEPD says. A third party allegedly selected the target and used the agent as an instrument for carrying out several stages of the intrusion.
That distinction matters because the reported behavior concerns the way a person deployed the system, rather than an assertion that the underlying model independently chose a target. The agency’s description also does not identify whether the agent exploited a newly discovered software flaw, misused valid credentials or combined several weaknesses after entering the application.
Why autonomy changes the response clock
The AEPD’s concern centers on the agent’s ability to continue operating after the initial access. According to the agency, the system first searched generic files for vulnerabilities, obtained a successful login and then examined the application autonomously until it found another weakness that allowed it to modify personal information and consult invoices.
Generative AI has already been used to help draft phishing messages, translate fraudulent campaigns, analyze code and support vulnerability research. An agent adds a different operational capability: it can receive a goal, plan intermediate tasks, use tools, interpret results and adjust its next action without requiring a person to direct every step.
That automation can change the speed and reach of a breach. A process that once required a human attacker to move between systems may instead test multiple paths, inspect several assets and react to failed attempts in a continuous loop. The AEPD says organizations should not assume that controls designed around manually executed attacks will provide enough time for detection and containment.
Credentials become a direct privacy risk
Pérez Bes’s analysis places particular emphasis on accounts, API keys and access tokens. An agent that obtains credentials with broad permissions can move between services at machine speed, potentially reaching additional data before a security team recognizes the activity as abnormal.
The agency says organizations should expressly include attacks assisted or executed by AI in risk assessments for personal-data processing. Generic references to malware, phishing or unauthorized access may not describe the probability, speed or scope of an incident involving an agent that can adapt its behavior after entering a system.
Human oversight still has a role, but the AEPD says it cannot stand alone. Detection, containment and response systems must operate quickly enough to match an automated attacker, particularly where applications expose personal data through reusable credentials or connected tools.
What the notification does not establish
The filing does not show that AI agents are responsible for a broader wave of breaches in Spain. It does not name the affected organization, identify the model, quantify the data involved or state whether invoices were copied, altered or merely viewed. The AEPD has also not concluded that the model provider bears responsibility for the incident.
Its significance is narrower and more concrete: a Spanish organization has notified the regulator of a personal-data breach in which an AI agent allegedly chained reconnaissance, authentication, application testing and data access. The agency now has to determine what happened, what information was affected and whether the organization’s security and notification duties were met.
For companies using connected AI systems, the immediate question is whether an agent can reach more than the task for which it was configured. In the reported case, the path from a generic file search to modified personal data and accessed invoices is the sequence the AEPD will now examine.