Spain's data protection agency has logged the first personal data breach executed by an AI agent. The first thing the agent did was log in successfully.

The AEPD published it on its blog on 14 September. A third party used an agent, running on what the agency calls a well-known language model, to chain the phases of an attack: it scanned generic files for weaknesses, completed a valid login, then searched the application autonomously from the inside, modified personal data and reached invoices.

What this changes for anyone shipping agents in the EU:

1. The scale first, so nobody oversells it. The AEPD received 2,765 breach notifications in 2025, 80% private sector, and escalated 11 for further investigation. This is one notification, and the agency says so itself: it does not permit anyone to assert a statistical trend.

2. The agency declines to blame the model. Its own words: using a particular AI model does not imply that the model or its provider's infrastructure was compromised, nor that the tool was designed for malicious activity. The agent was an instrument. Which leaves the duty where it was, on the controller, under Article 32.

3. The first step was not an exploit. "Realizó un login correcto." Credentials that worked. The agency's third observation names the control: an account, an API key or a token with excessive permissions lets an agent operate at machine speed and reach several services before anyone notices anything anomalous.

4. That is a description of your own agent platform. The widest-scoped non-human identities in most estates went to internal agents - CI, migrations, support tooling - scoped for convenience. Nothing in point 3 requires the agent to be hostile.

5. And the breach here was alteration, not exfiltration. Article 4(12) defines a personal data breach as destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. Article 33(3)(a) asks for its nature and the approximate number of records concerned. Most playbooks are shaped for confidentiality and have no answer to "which rows did it change, and to what?"

My Monday: list every agent token that can write, and log each write with the value it replaced. Article 33 gives you 72 hours from awareness to describe what changed. That log is what makes an answer possible.

A breach is not only a leak. Which records did your agents change last week?

#DSGVO #AIAct #AgenticAI #EUTech #DevSecOps

AI disclosure: the narration voice, the cover art and the brand ident animation in this video are AI-generated. The script, the claims and the source checks are mine.