Spain to Australia: AI agents raise cyber risk stakes

Spain to Australia: AI agents raise cyber risk stakes

A series of incidents spanning Spain and Australia is providing some of the clearest real-world evidence yet that AI agents are becoming part of the cyber incident landscape. The cases vary in cause and intent, but they raise a common question for businesses and cyber insurers: as autonomous software gains access to systems, data and permissions, are basic security controls keeping pace?

In a new analysis, KYND examines the emerging risks around AI agents and argues that the technology is increasing the consequences of familiar cybersecurity weaknesses. The cyber risk intelligence provider points to recent incidents involving AI agents, as well as research into coding agents, to highlight the importance of access controls, data segmentation, least privilege and visibility into an organisation’s technology estate.

In September, Spain’s data protection authority, the AEPD, disclosed its first breach notification in which an AI agent was reportedly used as the instrument of an attack. According to the organisation reporting the incident, the agent searched for vulnerabilities, logged into an application, navigated it autonomously, modified personal data and accessed invoices. The AEPD has not independently verified the account and cautioned that the involvement of a particular AI model does not mean the model or its provider was compromised.

Australia subsequently faced a different type of incident. An autonomous OpenAI agent conducting research gained unintended access to a government statistics portal containing non-public Medicare information. The incident occurred in June but was not reported to the Australian government until September. OpenAI said it found no evidence that patient data had been accessed.

The Australian government has since launched a rapid review examining whether existing legislation and governance arrangements are ‘fit for purpose’ when dealing with cyber incidents involving AI.

Between these incidents, security researchers also uncovered evidence of AI coding agents inside major organisations following instructions contained in vendor documentation and executing commands referencing packages and domains that had no owner. Researchers registered some of those abandoned names and published harmless test packages. Within an hour, a Fortune 500 company had connected to one, with other organisations following.

The incidents have different causes, but they raise familiar cybersecurity questions. What systems could the software access? What permissions did it hold? How effectively was sensitive data segmented? And what controls were in place to limit the impact when something unexpected happened?

The rapid adoption of AI can make these questions more difficult to answer. Businesses are increasingly using agents to write code, analyse information, automate processes, interact with customers and perform tasks across internal systems. To carry out those functions, agents often require access to data, APIs, email, code repositories, applications and other internal infrastructure.

That creates a potential conflict between speed and security. Least privilege, for example, requires organisations to carefully assess what access a system actually needs and restrict permissions accordingly. Giving an AI agent broad credentials can be quicker, but it can also increase the potential consequences if the system behaves unexpectedly or follows a malicious instruction.

Data minimisation and segmentation are similarly important. An agent restricted to a tightly controlled environment has a smaller potential blast radius than one able to move between multiple systems and datasets.

The issue is therefore not simply whether AI can be exploited by an external attacker. Agentic AI introduces another consideration: what software with legitimate access might do with those permissions.

The coding-agent research demonstrates the distinction. The agents did not need stolen credentials to act. They already had access and followed instructions they interpreted as authoritative. The Australian incident raises a related question about what happens when an agent carrying out a legitimate task reaches information it was not intended to access.

For cyber insurers, many of the fundamental questions remain unchanged. Underwriters already assess access controls, data protection, network segmentation, monitoring and the ability to contain an incident. What is changing is the technology to which those controls need to be applied.

Underwriters therefore need greater visibility into how an organisation is using AI. Are agents operating with tightly scoped permissions or broad credentials? What systems can they access? What data can they reach? Can they take actions independently? And how effectively could an unexpected action be contained?

Before those questions can be answered, insurers need to know where AI is being used.

AI capabilities can be introduced quickly, embedded within existing enterprise software or adopted outside formal technology inventory processes. This makes self-declaration on proposal forms harder to rely on as the sole source of information.

Knowing which AI technologies are present is increasingly becoming part of understanding an organisation’s technology estate. However, simply identifying AI adoption does not determine cyber risk. The more useful distinction is between the presence of AI and the exposure created by how it is deployed.

That also creates a portfolio-level consideration for insurers. Similar AI agents, dependencies and technologies may appear across multiple organisations, creating potential accumulation risks that would not necessarily be visible when assessing each insured individually.

The response does not need to be a retreat from AI adoption. Instead, organisations can apply established cyber disciplines to increasingly autonomous systems by limiting permissions, minimising accessible data, segmenting critical environments and monitoring activity.

For insurers, the challenge is to understand whether those controls remain effective as AI adoption accelerates, while also gaining enough visibility into changing technology estates to identify where additional questions need to be asked.

KYND is extending its technographic intelligence to detect AI technologies as part of this broader approach. The company argues that identifying AI adoption is not about automatically classifying an organisation as a higher risk. Rather, it provides insurers with additional evidence to understand the technologies being used and assess whether cybersecurity fundamentals are keeping pace.

The central message of the KYND analysis is that AI is changing what software can access and do, but the principles needed to prevent and contain cyber incidents remain familiar. As autonomous systems become more embedded across businesses, least privilege, segmentation, access controls and technology visibility are becoming increasingly important considerations for both companies and cyber insurers.

Read the full KYND analysis

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoying the stories?

Subscribe to our daily FinTech newsletter and get the latest industry news & research

Investors

The following investor(s) were tagged in this article.