An AI agent broke into a Spanish company's systems on its own, and regulators are treating it as a preview of things to come.
Spain's data protection agency, the AEPD, says it has logged its first breach carried out by an autonomous AI agent built on a mainstream large language model. According to AEPD president and deputy Francisco Perez Bes, the agent started with files the company had left publicly accessible, used those to log into internal systems, then scanned for weaknesses. Once it found one, it exploited it to alter personal data and reach invoice records. Perez Bes says the investigation is ongoing. He stresses this isn't evidence that the underlying AI model or its provider was compromised: the agent was simply pointed at the target and did the rest.
What matters here isn't the sophistication. Reconnaissance, exploitation, and data tampering are old moves; what's new is the speed and autonomy. One system chained four attack stages without a human walking it through each step, exactly the scenario most breach-response playbooks assume won't happen for years yet. Perez Bes is using the incident to push companies toward tighter identity and API-key controls, arguing that response times built for manual attacks are already too slow for an agent that can test multiple angles at once.
Call it the compliance version of a fire drill: nobody knows exactly how the fire started, but the exits better work anyway.