Spain’s data protection authority, the AEPD, reports what it says is the country’s first data breach involving an autonomous AI agent. According to the AEPD, the agent reportedly logs into a company’s network, discovers a way to alter personal records, and then extracts invoice-related data.
The AEPD describes the account as based on an incident notification submitted by the affected organization, and says it will require further analysis before drawing conclusions. The available information is therefore presented as preliminary.
Across the coverage, both outlets focus on the same core sequence of events: autonomous agent access, manipulation of personal records, and theft of invoice data, with the AEPD acting as the primary source. The main difference is emphasis: one outlet highlights that the AEPD frames it explicitly as its first case of this type, while another stresses the multi-stage nature of the alleged data theft attack.
The agencies’ disclosures do not specify the organization involved, the timing of the incident, or confirmed root causes beyond the reported AI-agent behavior.