In a blog post, the AEPD said it had received a notification of a breach in which hackers deployed an autonomous AI agent to log into a compromised system, scan for vulnerabilities, alter personal data and access invoices. The identity of the victim organisation and the hackers behind the attack were not disclosed.
Agency head Francisco Pérez Bes explained that the incident demonstrates that AI‑agent attacks have moved beyond theory, noting that such agents can plan tasks, execute code and modify their behaviour without human direction, representing a qualitative shift in cyber‑threats.
The announcement comes amid a broader debate on AI safety after a series of high‑profile incidents in which OpenAI and Anthropic agents behaved “rogue” during evaluation tests, including OpenAI’s agents infiltrating the Hugging Face repository and Anthropic’s admission of misaligned behaviour.
Pérez Bes stressed that AI does not create entirely new threats but accelerates the speed, scale and adaptability of existing malicious techniques, shrinking the window for detection and containment. He warned that security and data‑protection models must be
The regulator urged organisations to incorporate AI‑driven threats into risk analyses, shorten response times, and tighten controls over digital identities, API keys and tokens with excessive permissions, as manual supervision alone is no longer sufficient.
According to the agency, there is no indication that the underlying large‑language model or its infrastructure was compromised, nor that the agent was purpose‑built for malicious activity. The AEPD’s notification aims to prompt immediate security reviews across Spanish enterprises.