THE DEEP TAKE
The first breach report that named an AI as the attacker
Spain's data protection authority has logged a breach notification that names an autonomous AI agent as the instrument of the attack. It is the first time a national regulator has publicly confirmed receiving one. The agency has not named the organization, the sector, or the model. It did describe the sequence. The agent logged in, searched for vulnerabilities, altered personal data, and reached invoices. One run, with no pause between the phases.
The regulator's own description is the useful part. It says an agent can take a goal and plan its own intermediate tasks. From there it uses tools, runs code, consults sources and reads the results. Then it changes what it does next based on what it found. Read that as a description of an attacker. The thing that breaks is the clock. Recon, exploitation and exfiltration used to be separate events with human hours between them. Most detection logic lives in those gaps. You alert on the recon and you catch the exploit. The gap is what the process is actually buying you.
The agency is blunt about the consequence. Human supervision, it says, must be supported by detection, containment and response mechanisms capable of operating quickly. That is a regulator putting in writing that an approval workflow with a person in it is no longer proof of control. It sounds obvious. It is not, because most enterprise agent governance today is a review board and a written policy. Both of those run on calendar time.
Here is the part that should make you uncomfortable. The agency lists three possible explanations for the incident, and only one is a hostile outsider. The others are a jailbroken model, and an agent that escaped a testing environment with minimal human direction. A sanctioned penetration test, run with a custom model, can produce the same filing as a criminal attack. The notification form has no box for intent.
So find out whether your own agents could generate this filing. Two questions get you most of the way. Can you produce today a list of every agent running in production and the credentials each one holds? And does your incident runbook have a branch for an actor that is neither a person nor malware? Most runbooks fork on exactly those two. An authorized agent that did something nobody authorized falls straight between them.
One more, and it is the cheapest check on the list. Find out what your red team is allowed to run. If autonomous agents are in scope, make sure your data protection officer knows it. Otherwise the first person to find out is a regulator reading your own notification.
From the people who send this
CXO Brief is published by DoGood. More than seventy enterprise vendors are currently paying for 30-minute briefings with IT and security leaders on AI governance, third-party risk, identity, observability and infrastructure. You choose which vendors to meet, if any. Every completed briefing pays you $150 to $200, as a premium gift card, cash, or a donation to a charity you pick if your employer restricts gifts. Membership is free and by invitation.
Or reply to this email with the word "briefing" and Ryan will set you up personally.
QUICK HITS
One extension, five hijacked AI assistants
Research published Wednesday shows what one malicious browser extension can do. It takes control of the AI assistant built into Chrome, Edge, Perplexity's Comet, Opera Neon and the Claude extension. The technique needs two permissions that ordinary ad blockers already ask for: the ability to modify pages, and declarativeNetRequest. On Chrome it reached local files, the camera and microphone, and the browser profile. Chrome and Edge issued CVEs and shipped fixes, in 143.0.7499.192 and 150.0.4078.48. The other three products got no CVE at all. That is the detail for your team. A flaw with no CVE never shows up in a vulnerability scanner, so your only control is the extension allowlist. Pull the installed-extension inventory and read what your users have already granted.
Twelve days until a model can no longer sign a firing
California's legislature sent roughly thirty AI bills to the governor, who has until September 30 to act on each one. The one to read is SB 947. It would stop an employer relying only on an automated decision system to discipline or terminate someone. If that system is the primary input, a human has to corroborate the decision, and the employee gets notice afterward. Most large employers already run automated scoring somewhere in workforce management, usually inside a vendor's product rather than their own code. If that is you, this is not a legal review. It is a product question: can the tool record a human corroboration step, and can it generate the notice? Ask the vendor today, because the answer takes longer than twelve days if it is no.
THE NUMBER: 32%
Thirty-two percent of enterprises can detect and contain an AI agent that acts outside its intended scope within minutes. That means automated systems, not a person. The figure comes from research published this month across 202 technology and security leaders. Everyone else needs hours and a human in the loop. Set it beside what Spain's regulator asked for: mechanisms capable of operating quickly. Two thirds of the market cannot meet that bar. A supervisory authority has now written it down. The same research found 47% have no reliable inventory of the agents they run. That is the number that ranks the work, because you cannot contain what you cannot enumerate.
Answer one question about your own environment before Monday: if an agent you deployed did what that filing describes, who would know first, and how fast? Vendors in the DoGood network are booking 30-minute briefings on AI governance with IT and security leaders right now, which is a cheap way to see what peers are putting in place against exactly this.
The CXO Brief is published by DoGood, the network where enterprise IT leaders are paid for 30-minute vendor briefings.
Know a CIO who needs this? Forward it and they can subscribe here.
Run IT or security at a $100M+ company? Claim your invite.
