IndiaFocal.

India, in focus.

National

Spain logs first data breach tied to an AI agent, watchdog says

Spain's data protection agency says it has received its first breach notification involving an AI agent that autonomously attacked a system.

Spain's data protection authority has disclosed what it describes as the first breach notification it has received involving an artificial intelligence agent, a case that points to autonomous systems taking a direct part in cyberattacks.

The Spanish Data Protection Agency (AEPD) said in a blog post that the incident involved an AI agent that used a widely known large language model to probe for weaknesses, break into a system and then change personal data and reach invoices.

The affected organisation filed the notification, and the agency said the matter is still under review. It did not name the large language model involved or the organisation that was targeted, and it did not say when its examination would conclude.

According to the account submitted by the organisation, the agent logged into the system and then searched on its own for weaknesses in the application. Having found a vulnerability, it was able to alter personal information and view billing records.

The AEPD stressed that the use of a particular AI model did not mean the model itself or its provider's infrastructure had been compromised, nor that the technology had been built for malicious ends.

The agency said the case matters because a third party allegedly used an AI agent to carry out several stages of an attack with only limited human involvement, underscoring the expanding role of autonomous systems in cybersecurity incidents.

While a single case cannot establish a wider pattern, the notification indicates that AI-assisted attacks are moving past the theoretical stage and beginning to touch real-world processing of personal data, the agency added.

It also cautioned that AI does not create new threats by itself, but it sharpens the speed, scale and adaptability of existing malicious techniques, leaving less time to detect and contain them. Controllers, processors and data protection officers should prepare for attacks that keep getting faster, the agency said.

The disclosure comes as regulators and cybersecurity authorities in the United States and Europe step up scrutiny of the risks from increasingly capable AI systems, even as businesses adopt the technology quickly.

Spain has cast itself as one of Europe's loudest advocates of a "trustworthy AI" approach that safeguards privacy, democracy, minors and public safety rather than putting speed or industry profit first.