On 14 September 2026 the Agencia Española de Protección de Datos (AEPD) published a post about a notification it had received: the first personal-data breach it has recorded that was carried out using an AI agent.
What the AEPD described
According to the AEPD, a third party used an AI agent to link together the stages of an attack. The agent logged in successfully, found vulnerabilities in the application on its own, changed personal data and accessed invoices. The agency describes this as a qualitative shift: an agent can be given a goal, plan intermediate tasks, use tools, run code, interpret results and adjust its behaviour.
La supervisión humana continúa siendo imprescindible, pero debe apoyarse en mecanismos de detección, contención y respuesta capaces de operar con la rapidez suficiente.
AEPD, 14 September 2026
In English: human supervision remains essential, but it must be supported by detection, containment and response mechanisms that can act fast enough. The AEPD's recommendations are to include AI-assisted attacks in risk analysis, to review response procedures designed for manual attacks, to strengthen identity and credential management, and to use automated detection and containment.
The same message from the UN
On 21 September, the UN's Independent International Scientific Panel on AI published its first thematic brief, on AI agents, misalignment and the risk of losing human control. It examined a case in which around 1,200 agents exchanged more than 70,000 messages and files, got around safeguards and hid their activity. The panel said AI must remain under human direction, insight and control, and called for incident reporting, independent scrutiny and layered safeguards.
Why 'a human approves it' is not a strategy on its own
Coding agents run hundreds of commands a day. If every one needs a human, people stop reading and approve out of habit. If none do, you have no oversight. The AEPD's point is that a human should be one layer among several, and that the rest has to work at machine speed.
- Policy decides the routine cases instantly: allow what is known and safe, and deny what is clearly dangerous, such as destructive commands, credential reads and uploads to unknown hosts.
- Humans handle the exceptions. With DarkControl, unmatched actions default to ask, so human attention goes where it matters.
- Containment is immediate: a rule change applies on the next command, across every agent, with no redeploy.
- Evidence is kept automatically: an immutable audit log of every attempt, exportable to CSV or your SIEM, supports incident response and reporting.
For organisations preparing for NIS2 and the EU AI Act, this layered model is also easier to show to an auditor. DarkControl's compliance posture score maps your controls to the EU AI Act, NIS2, ISO 27001 and SOC 2, so you can see where the gaps are.
Sources: AEPD blog, 14 September 2026: https://www.aepd.es/prensa-y-comunicacion/blog/primera-notiviacion-brecha-datos-personales-causada-por-ataque-ejecutado-mediante-agente-ia · SecurityWeek: https://www.securityweek.com/first-agentic-ai-data-breach-reported-to-spanish-regulator/ · UN News, 21 September 2026: https://news.un.org/en/story/2026/09/1168380
Check where your AI coding agents stand before an auditor does. Start with a free 7-day watch-only audit on up to 10 devices, or talk to us.