Global Edition
Global Edition
UK Edition
EU Edition
US Edition

Understand the story, not the spin.

Markets

Spain reports first data breach by autonomous AI agent

Published 17 September 2026

Spain's data protection agency has reported the country's first personal data breach carried out by an autonomous AI agent, marking what officials describe as a shift from theoretical risk to real-world incident. The Agencia Española de Protección de Datos (AEPD) announced in a blog post on September 14 that it received a notification from an affected organization detailing the attack, which involved an AI agent using a known large language model (LLM) to chain together multiple stages of a cyber intrusion. According to the AEPD, the agent began by scanning publicly accessible files, which enabled it to successfully log into the target system. Once inside, it autonomously searched for vulnerabilities within the application. Upon finding a flaw, the agent modified personal data and accessed invoices. The agency emphasized that the attack does not imply the AI model or its provider's infrastructure was compromised, nor that the technology was designed for malicious use. AEPD head Francisco Pérez Bes stated that while a single notification does not establish a statistical trend, it constitutes a significant sign that AI-supported attacks have ceased to be a theoretical risk.

0:00 / 0:00