A Spanish enterprise recently fell victim to a cyberattack carried out by an artificial intelligence (AI) system that acted independently, according to the Spanish Data Protection Agency (AEPD). On September 14, the agency released the first official report of a data breach caused by an AI agent. The AI scanned the company's system, identified a vulnerability in a specific application, and then modified personal data and accessed financial records. According to the AEPD, the AI did not create new hacking methods but enhanced existing techniques, making them faster, broader, and more adaptable in real time. The agency has based its findings solely on the company's internal report, and no outside verification has been confirmed. The AEPD also clarified that the use of a well-known AI model in the attack does not imply that the model’s developer was compromised or that the tool was designed for malicious purposes. Cybersecurity experts like Gérôme Billois, a French specialist from Wavestone, have observed similar behaviors in AI-assisted penetration tests, where AI is used to simulate cyberattacks for security testing. He praised the AEPD for its transparency and suggested that its actions could serve as a model for other regulatory bodies. This incident is part of a growing trend of AI-driven cyberattacks. Earlier this year, a ransomware attack known as JadePuffer used the Langflow AI tool to automate an attack from start to finish. The AI bypassed a failed initial connection attempt in just 31 seconds—far quicker than any human could achieve. However, experts remain uncertain about how autonomous the attack truly was, as the AI made a critical error by generating a fake Bitcoin address to collect the ransom. In July, a more coordinated AI-powered attack targeted systems in Taiwan, with eight AI agents working simultaneously to breach the network. The attack compromised 85 accounts and stole over 2,500 employee records in just four days. Meanwhile, the AI platform Hugging Face, used by developers worldwide, faced an intrusion fully managed by an autonomous AI system, without any human intervention. This attack was notable enough to contribute to Hugging Face’s acquisition by NVIDIA for $13 billion. A report from Anthropic, the company behind the AI model Claude, revealed that fully automated cyberespionage operations have targeted over fifty organizations globally. The speed of these attacks is particularly concerning, as AI agents can complete full intrusions in two to three hours—far faster than a human hacker. Experts agree that AI-piloted cyberattacks represent a new and distinct threat that requires specific defensive strategies. Managing digital identities, such as access keys and user accounts with overly broad permissions, has become increasingly important. Companies are urged to reduce their response times to threats, as human vigilance alone cannot match the speed of AI. Gérôme Billois calls for new, measurable goals for security teams, emphasizing that detection and response times must shift from days to hours. He suggests using AI not just as a tool for attacks, but also as a means to enhance defenses and prevent breaches in the first place.