Spain's data protection agency receives its first breach notification for an attack run by an AI agent

On September 14, 2026, the Spanish Data Protection Agency (AEPD) published a blog post by its deputy Francisco Perez Bes reporting that it had received its first notification of a personal data breach caused by an attack executed through an AI agent. According to the notification, the attacker’s agent, built on a well-known language model that the agency does not name, began by searching generic files for weaknesses and then logged in successfully. Once inside, it searched the application for vulnerabilities on its own, which let it modify personal data and access invoices. The AEPD’s framing is that a third party used the agent as an instrument to chain the separate phases of the attack together.

The agency does not identify the affected organization, the number of people affected, or the model involved. Its post is mostly about what data controllers should take from the case: explicitly include AI-assisted attacks in risk assessments, review incident-response procedures because purely manual processes may be too slow, prioritize digital identity and credential management, add automated detection and containment alongside human oversight, and keep the fundamentals - know your processing, minimize data, limit access, fix vulnerabilities, control suppliers. It stresses that the GDPR’s 72-hour notification duty is unchanged by the use of AI, and that a single case is a relevant signal rather than a statistical trend.

Why it matters: most evidence of agent-driven intrusions so far has come from AI labs’ own threat reports or from security vendors. This is a regulator recording, through the ordinary legal breach-notification channel, that an agent-run attack reached real personal data at a real organization - the point at which the threat becomes a compliance fact rather than a forecast. What it does not show is the scale, sophistication or attribution of the attack, or whether the agent did anything a human attacker with a script could not; the AEPD gives almost no technical detail and says itself that one case is not a trend.