AI agents are beginning to appear in real cyber incidents, creating questions for regulators over whether existing breach, data protection and governance frameworks are equipped to deal with autonomous software.
Recent cases in Spain and Australia, alongside research into AI coding tools, show how established compliance principles are being tested by systems capable of accessing information and taking actions with limited human intervention.
KYND’s analysis examines these developments and argues that the growing use of AI agents is making existing controls around permissions, data access and technology visibility increasingly important for businesses and insurers.
Spain has provided one of the first examples of an AI-related incident reaching a data protection regulator. In September, the AEPD disclosed that it had received a breach notification in which an AI agent was reportedly used during an attack. The organisation said the agent identified vulnerabilities, accessed an application, moved through it autonomously, changed personal data and viewed invoices.
The AEPD has not independently verified the account. It also stressed that the involvement of a particular AI model does not mean the model itself or its provider was compromised, highlighting the need to distinguish between an AI system being used during an incident and the underlying technology being breached.
Australia presents a different regulatory challenge. An autonomous OpenAI agent conducting research gained unintended access to a government statistics portal containing non-public Medicare information. The incident occurred in June but was only reported to the Australian government in September. OpenAI said it found no evidence that patient data had been accessed.
The Australian government has subsequently launched a rapid review of whether existing legislation and governance arrangements are ‘fit for purpose’ when AI is involved in cyber incidents.
Research into AI coding agents adds another dimension. Investigators found agents following instructions within vendor documentation and attempting to execute commands involving packages and domains that were no longer owned. Researchers subsequently registered some of those domains and published harmless test packages. A Fortune 500 company connected to one within an hour, followed by other organisations.
The significance for compliance teams is that the agents did not necessarily need stolen credentials or a conventional attack vector to take action. They were operating with legitimate access and responding to information they treated as authoritative.
That creates a different compliance question from the traditional focus on preventing unauthorised access. Organisations must also consider what authorised software can do once it has access to sensitive systems, information and infrastructure.
Controls such as least privilege, data minimisation and network segmentation therefore become particularly important. An AI agent with access to multiple systems can potentially have a much wider impact than one restricted to a specific environment or dataset.
The problem is compounded by limited visibility. AI functionality can be built into existing software, introduced by individual teams or adopted without going through traditional procurement and technology governance processes. This can make it difficult for organisations to maintain a complete inventory of the AI systems operating across their estate.
For RegTech and compliance teams, that raises questions around how organisations demonstrate effective oversight. Self-declaration may not provide a complete picture if businesses do not know every AI capability operating within their environment.
It also creates challenges for insurers assessing cyber exposure. KYND is expanding its technographic intelligence to identify AI technologies, with the aim of providing greater visibility into the systems being used by organisations rather than relying entirely on information supplied through questionnaires.
The presence of AI does not automatically indicate a compliance or cyber risk. Instead, the regulatory and risk question is how the technology has been deployed, what permissions it has been given, what information it can access and what controls exist if it behaves unexpectedly.
As AI agents become more capable of operating independently, regulators may increasingly need to consider whether existing breach notification, governance and operational resilience frameworks adequately account for software acting with legitimate permissions.
The developments highlighted in KYND’s analysis suggest that the regulatory challenge is not simply creating new rules for AI. It is also determining whether organisations are applying existing principles of access control, oversight, segmentation and accountability effectively as autonomous systems become part of the technology estate.
Copyright © 2026 RegTech Analyst
Copyright © 2026 RegTech Analyst





