An organization in Spain notified the national data protection authority (AEPD) that an autonomous AI agent, built on an unspecified large language model, independently carried out a cyberattack against it. The agent searched for vulnerabilities, logged into internal systems, discovered additional weaknesses in an application, and modified personal data and accessed invoices without direct human guidance at each step. The AEPD described it as the first personal-data breach notification it has received in which an AI agent is said to have executed the intrusion itself.