Kiteworks Agent Marketplace
Which AI assistant do you use?
Brief

What Spain's first AI-agent breach means for your agents

Spain's data protection authority received its first breach notice attributed to an AI agent. What it reported, and what to check in your own agents.

  • Access & Sharing
  • Governance & Retention
  • GDPR

A breach notice received by Spain's data protection authority describes an attack in which an AI agent did the probing and the exploiting. The facts are not yet verified, but the lesson for anyone running agents on business files does not depend on them: decide what each agent can reach, and keep a person in front of every action that changes something.

What the AEPD reported

On September 14, 2026, the Agencia Española de Protección de Datos (AEPD) published a blog post about the first notification it has received of a personal data breach that "would have been executed by means of an AI agent that used a well-known language model". According to the notification, the agent searched generic files for vulnerabilities and logged in successfully. Once inside, it searched the application for weaknesses on its own, which let it modify personal data and access invoices. (Quotations from Spanish sources in this brief are our translations.)

Three details matter as much as the story itself:

  • The AEPD writes that the information "comes from the notification submitted by the affected organisation" and still has to be analysed. It does not name the organisation, the sector, or the model.
  • A third party allegedly used the agent as the instrument of the attack. This is not a case of a company's own assistant going rogue.
  • The AEPD stresses that the use of a particular model does not mean the model or its provider was compromised, and that one notification does not establish a statistical trend.

Why it matters for the agents you run

Most organisations will use agents on their own files, with permission, rather than meet one as an attacker. The AEPD's advice covers both situations. The same fundamentals remain decisive, it writes: "knowing the processing operations, minimising data, limiting access, correcting vulnerabilities, controlling suppliers and being prepared to respond." It also warns that "an agent that obtains an account, API key or over-permissioned token can operate at machine speed", and that human oversight remains essential but needs detection and response that can keep up.

That is an argument about access, not about models. An agent that can reach only the folder it needs, and cannot change anything until a person says yes, limits what goes wrong when its input is hostile or its credentials leak.

A test from the AEPD's own guidance

In February 2026 the AEPD published guidance on agentic AI from a data protection perspective. It includes the "Rule of 2", a cybersecurity rule first written for the Chromium browser in 2021 and since adapted for AI agents by others, including Meta. The three properties are processing untrusted input, reaching sensitive information, and acting automatically. The guidance's example is an email agent that has all three, and its verdict is plain: "That would be an agent configuration that should not be permitted." Where an agent handles untrusted input and reaches sensitive data, it says, any automatic action with an effect inside or outside the organisation must be prevented without human supervision. The AEPD itself calls the rule a minimum and a starting point for analysis, not a complete data protection assessment.

Apply it to a document agent. Files that arrive from outside the organisation are untrusted input: a document can carry instructions aimed at the model. The folder the agent reads may hold personal data. So the property to remove is the third one, acting on its own.

How marketplace agents map onto the test

Marketplace agents run in Claude through the Kiteworks connector, on a folder you choose, with the connector permissions of the person running them. Most of them only read and report. Where an agent writes, its instructions require confirmation first. Sharing Auditor saves a report only after you confirm where, and has no tool to change sharing. Invoice Organizer renames files only after you approve the proposed names. Before a pilot, read each listing for what the agent reads, what it can write, and what it cannot see.

Two agents also help with the fundamentals the AEPD lists first. Sharing Auditor shows which folder trees in a scope are shared and where the sharing starts, so you know what an agent, or anyone else, could reach through them. Sensitive Content Scanner finds sensitive terms and common personal data in a folder, which tells you which scopes to keep away from agents that handle outside documents. Both report; neither changes a share or a file.

Questions before you connect an agent

  • Which folders will the agent read, and do they hold personal data it does not need?
  • Where does its input come from, and could an outside party have written any of it?
  • What can it change, and does every change wait for a named person's approval?
  • Whose credentials does it use, and how quickly could you revoke them?
  • Does your risk analysis now include AI-assisted attacks, as the AEPD asks controllers to consider?
  • Who reviews the agent's report, and where is the decision recorded?

If you want to test an agent against these questions before a pilot, email sales@kiteworks.com or start a conversation. You do not need Claude or MCP setup to ask. See the agent catalog for each agent's stated limits.

Sources

  1. Primera notificación de una brecha de datos personales causada por un ataque ejecutado mediante un agente de IA · Agencia Española de Protección de Datos (AEPD) ·
  2. Inteligencia Artificial Agéntica desde la perspectiva de protección de datos · Agencia Española de Protección de Datos (AEPD) ·
  3. Agents Rule of Two: A Practical Approach to AI Agent Security · Meta AI ·