Third-party risk management has a new threat actor to account for: an AI agent capable of finding a weakness, exploiting it and adapting its actions with minimal human intervention.
Spain’s data-protection authority, the AEPD, says it has received the country’s first known notification of a personal-data breach allegedly executed autonomously by an AI agent using a recognised large language model.
The agent reportedly entered the organisation using valid credentials, identified further vulnerabilities, modified personal data and viewed invoices and billing information. The affected organisation, model and provider have not been named. The investigation remains open, and there is no indication that the model itself or its provider’s infrastructure was compromised.
The response window just got shorter
The underlying security problems are familiar: valid credentials, excessive access and exploitable vulnerabilities. What changes is the speed and persistence with which an autonomous system can combine them.
That matters for procurement because a buyer’s exposure depends on more than its own controls. A critical supplier may hold customer data, connect to internal systems or possess credentials that allow activity inside the buyer’s environment. If that supplier needs hours of manual investigation before it can understand what happened, an agent may already have completed hundreds of actions.
A credible third-party assessment should now establish which human, service and agent identities can access customer environments; whether their permissions and tool use are constrained; how anomalous actions are stopped; which execution logs are retained; and whether those logs are available to affected customers.
Contracts need to recognise agent incidents
Many security schedules define an incident around malware, unauthorised human access or confirmed data loss. That language may not deal cleanly with an autonomous agent using valid credentials or chaining together actions that appear legitimate in isolation.
Procurement should test whether the contract requires notification when an agent acts outside its authority, even before the supplier has confirmed a conventional breach. The notification clock, evidence requirements and escalation route need to reflect the speed of the activity.
This is also why annual questionnaires are becoming less useful as the centre of TPRM. Evidence collected once a year says little about whether a supplier can identify an agent-driven incident today, reconstruct its actions and disable its access before the damage spreads.
The bottom line
The AEPD has received a breach notification, not completed a forensic investigation. This is the first known report of its kind in Spain, not a verified global first.
But the direction is clear. TPRM must now assess whether suppliers can detect, contain and explain autonomous activity at something close to the speed at which it occurs.
If your supplier’s incident process runs through email, it is not ready for an attacker that runs continuously.
Sources: Reuters · Cinco Días
