Spain's data protection authority, the AEPD, says it has received the first-ever report of a data breach caused by an AI agent built on a well-known language model. The authority made the case public in a blog post and sees it as a signal to act.
According to the report, the attacking AI agent first launched a search for vulnerabilities in generic files and successfully logged in. Once inside the system, it autonomously searched for further vulnerabilities. After finding some, it was able to modify personal data and access invoices. According to the AEPD, previously known similar cases involved AI agents that weren't publicly available.
Speed as the new quality
The authority stresses that the information available comes solely from the affected organization's own report, so the incident doesn't mean an AI provider itself was compromised. From a data protection standpoint, what matters is that a third party used an AI agent as a tool to successfully chain together the different stages of an attack. Such an agent can be given a goal, plan intermediate steps, use tools, execute code, query sources, interpret results, and autonomously adapt its approach based on what it finds. What's new here, above all, is the speed at which such an attack unfolds.
Three consequences for risk management
Francisco Pérez Bes, deputy head of the AEPD, outlines three consequences for organizations in the post. First, AI-assisted attacks now need to be explicitly included in risk analyses, since a general reference to malware, phishing, or unauthorized access is no longer enough, as automation can significantly change the probability, speed, and scale of an attack. Second, procedures designed to defend against manually executed attacks are likely to be too slow going forward, meaning IT security can no longer rely solely on manual intervention. Third, digital credentials and API keys are becoming more important, since anyone who obtains them can operate within a system at machine speed, making detection harder. The authority doesn't disclose which AI model was used in the attack or which organization was affected. Instead, it calls on data protection officers and those responsible for cybersecurity to prepare for this new threat landscape, while the basic principles remain the same: know your data processing, minimize data, restrict access, fix vulnerabilities, vet providers, and be ready to respond quickly.