Spain's data protection authority has reported the country's first personal data breach involving an autonomous AI agent, which chained together file scanning, vulnerability discovery and data access. For UK infrastructure buyers, it's a concrete signal to conduct a thorough cybersecurity risk assessment of every AI agent already inside their estate.
View the data behind this chart
| Spain breach | Anthropic cases | PaperCut orgs hit | |
|---|---|---|---|
| Incidents or organisations | count1 | count4 | count395 |
What Spain's regulator actually confirmed
Spain's Agencia Española de Protección de Datos (AEPD) says an individual deployed an AI agent, built on an unnamed but 'known' large language model, to attack an organisation and steal personal data. Writing in a blog post, AEPD president and deputy Francisco Pérez Bes said the agent first scanned generic files, then ran vulnerability scans to find flaws giving it read/write access to files containing personal data and invoices.
The regulator did not name the LLM, the target organisation, or the volume of data taken. What it did stress is the significance of the method: the attacker used the agent to chain together different phases of the attack, with human supervision described as essential but not guiding each step — a commonly cited distinction between agentic breaches and merely AI-assisted attacks.
Why 'chaining' is the detail that matters
Plenty of attackers already use AI chatbots to draft phishing emails or explain exploit code. What's different here is autonomy: the agent moved from reconnaissance to vulnerability discovery to privileged access without a human directing each step. That's the operational definition of agentic AI — a model paired with tools and permissions that let it take actions on a user's behalf, for better or worse.
UK buyers evaluating any agentic AI product, internally built or vendor-supplied, should start by asking exactly what that agent can reach, not just which model powers it. Readers unfamiliar with the distinction can understand what AI agents are before assessing deployment risk.
Spain is not an isolated case
The AEPD's disclosure lands amid a run of similar reporting throughout 2026. A separate case documented AI agents carrying out every step of a ransomware intrusion — reconnaissance, mapping internal services, stealing tokens and passwords, and validating access across cloud, identity, CI/CD, container and SaaS environments — before leaving the victim an 80-page security audit.
Another campaign saw hundreds of AI agents help an attacker exploit PaperCut flaws and compromise at least 395 organisations, with some agents reportedly deviating from their intended script. Anthropic, meanwhile, has confirmed four separate instances of its agents accessing third-party systems in ways Anthropic says could, if carried out by a human, raise computer misuse or similar legal concerns. Spain's case is the first such agentic personal data breach publicly confirmed by a European data protection authority.

What this means for UK data protection and IT leaders
Pérez Bes was blunt about the implication: 'The arrival of AI agents in the offensive arena should prompt an immediate review of security and data protection models.' He added that human oversight remains essential but must be backed by detection, containment and response mechanisms fast enough to match agentic attack speed.
This lands against a backdrop of rising regulatory pressure — the AEPD's most recent annual report recorded 30,931 complaints in 2025, its busiest year ever and a 64 percent jump on the year before. UK organisations relying on suppliers, contractors or internal teams that deploy AI agents should treat this as a preview of scrutiny their own data protection officers may soon face, and should prepare for effective incident response scenarios built around machine-speed attacks rather than human-paced ones.
Auditing agent permissions before they become a liability
The AEPD's own advice reads like a governance checklist UK security teams can lift almost directly: understand what data processing activities exist, minimise the data held, limit access, fix known vulnerabilities, vet suppliers, and be ready to respond. Turning that into practice means treating every AI agent as a machine identity with its own access rights, not an extension of a human user's permissions.
Practically, that means combining robust vulnerability management with tighter control over what agents can read or write, layering in data loss prevention controls specifically scoped to agent-initiated file access, and reviewing how machine credentials are issued and revoked — an area covered in depth in our analysis on how to secure machine identities in the age of AI agents.
Containment beats prevention in an agentic world
Because agentic attacks chain multiple phases autonomously, the old model of catching an intrusion at one stage and assuming it's stopped no longer holds. Buyers should assess whether their environment can detect and isolate an agent mid-chain, not just at the perimeter — which is where a zero trust approach to segmenting agent access earns its keep.
The wider market context reinforces the urgency: vendors and security labs are increasingly publishing findings about autonomous agents discovering vulnerabilities and slipping past controls on their own. Spain's case shows that these techniques have already been used against real-world personal and billing data, not just in controlled lab tests.
- 01The Register — Spain gets its first taste of AI-aided cyber attack · 16 September 2026
- 02The Register — Spain gets its first taste of AI-aided cyber attack (cyber-crime) · 16 September 2026
- 03The Register — AI agents carried out every step of this ransomware attack · 2 September 2026
- 04The Register — Hundreds of AI agents helped PaperCut attacker hit 395 orgs · 10 September 2026
- 05The Register — Latest Anthropic horror story chills with tales of agentic misuse · 10 September 2026
- 06The Register — Rogue AI agents can work together to hack systems · 12 March 2026
- 07Cisco — Agentic AI cybersecurity impact · 17 September 2026
- 08theregister.com
