SPAIN’S data protection watchdog has received what it says is the country’s first report of a personal data breach carried out by an artificial intelligence agent.
The Spanish Data Protection Agency (AEPD) said the attack used a well-known large language model, but it has not named the model or the organisation that was hit.
According to the notification, the AI agent began by scanning generic files for weaknesses and managed to log in to the system. Once inside, it hunted for flaws in the application on its own and eventually exploited one to change personal data and view invoices.
The watchdog stressed that the details come solely from the affected organisation’s report and still need to be analysed.
It added that using a particular AI model does not mean the model or its provider’s infrastructure was compromised, or that the tool was designed for malicious purposes.
What sets this case apart, according to the AEPD, is that a third party appears to have used an AI agent to chain together several stages of an attack.

The agency said the case is a significant sign that AI-assisted attacks have stopped being a theoretical risk and are now affecting real personal data.
To put the case in perspective, the AEPD received 288 data breach notifications in February 2026 alone.
Cybersecurity experts urged caution before blaming a rogue AI.
READ MORE: Haunted by hackers: How to avoid online shopping scams this Black Friday
Simon Phillips, chief technology officer at security firm CybaVerse, told the Olive Press: “We need to treat this incident with caution and avoid scaremongering the public with stories around AI once again running rogue.
“We don’t have enough information to understand what happened or how the model carried out this breach.”
Phillips said experts would look at three possible explanations. The first is that someone deliberately got around a model’s safety guardrails, possibly through a ‘jailbreak’, and used it to break into a third party.

The second is that this is another case of a model escaping a poorly configured test environment and pursuing a goal set by a human with little supervision. Several such incidents came to light this summer.
OpenAI’s agents gained unauthorised access to Hugging Face, Anthropic found that its Claude model had hacked organisations, and a Meta model exploited a vulnerability at another company after a testing contractor’s error gave it internet access.
The third is that a penetration tester built a tool on top of a popular LLM and used it without permission.
“Out of all these scenarios, the first is the most concerning because it would highlight an actor has been able to bypass the controls enforced by an AI model’s operators,” Phillips said.
“Hopefully we will understand more soon, because organisations need to know what they are facing with AI and where to invest their defences.
“There is currently too much hype around AI capabilities, and organisations are struggling to understand its impact on their environments. As an industry, we need to put an end to this.”
Click here to read more Technology News from The Olive Press.




