The first AI-agent breach is on file. The hard part was being able to describe it
On 14 September the Spanish data protection authority published that it had received the first notification of a personal data breach that "would have been executed by means of an artificial intelligence agent" — its own conditional. The whole attack fits in one sentence, and the authority warns the information comes from the affected organisation and is still pending analysis. We read those four phases as what they will eventually be for somebody else: a regulator's form with a 72-hour clock on it. Which record you need to write each sentence, why "autonomously" is inferred rather than logged, what the authority now expects in writing in your risk assessment, and why three of the four phases are stopped by boring things that involve no AI at all.