An autonomous agent is not an agent with a will: what the AEPD says
What has been reported about incidents involving AI agents, and which controls a company should ask for: identity, permissions and access withdrawal.

News about agents acting outside what was expected reflects a serious operational problem: systems able to use tools need limits you can check. That news is not enough to conclude that a machine has a will of its own, and it does not justify promising that a credential will solve every risk.
For a company, the useful answer is knowing which agent was involved, what it was authorised to do, what access it actually had and how to stop it.
What has been reported in Spain
On 15 September 2026, EFE reported a statement by the AEPD — Spain's data protection authority, one of the national supervisory bodies that enforce the GDPR across the EU — about a notified breach in which an autonomous AI agent was involved. It is important to keep that claim in proportion: a first notification of this kind does not prove it was the first such attack in history, and it does not allow anyone to reconstruct details that were not published.
Autonomy describes the ability to chain steps together and use tools. Attributing human intent to a system requires claims this report does not demonstrate.
What the international research adds
The METR investigation published on 26 August examined specific agent incidents and their actions outside the intended scope. The detail on incentives, context and tools helps in studying how those deviations come about. On its own it does not allow anyone to calculate how often the problem occurs across all companies.
On 16 September, OpenAI published a framework for reporting misaligned behaviour. That openness reinforces a practical need: documenting scenarios, evidence and the limits of what has been observed.
Our business reading is an inference: the more you delegate to software able to act, the more value there is in attribution, minimum permissions, approvals and a rehearsed withdrawal of access.
Three questions for the board
| Question | Evidence worth asking for |
|---|---|
| Who operates this agent? | The operator's identity and a verifiable declaration |
| What can it actually do? | Signed scope and the effective permissions of each connector |
| How do we stop it? | A rehearsal of cancellation, access withdrawal and revocation, with times |
A written boundary is useful, but it does not demonstrate that it is enforced. Nor does a valid credential automatically authenticate the sender of a message: a person can copy the link or the seal.
Where the digital ID fits
The NEXTAI digital ID lets you consult a signed declaration about identity, responsible party and scope. The Argos case study provides a public credential as an example.
The credential does not attest to invulnerability, does not replace tool controls, and does not demonstrate that the ID would have prevented the earlier incidents. Nor does it allow the opposite counterfactual to be asserted with confidence. What it does allow is verifying one concrete piece of the information you need in order to govern an agent.
An evidence-based answer to the fear
Before widening a system's autonomy, it is worth inventorying connectors, limiting permissions, requiring approval for sensitive actions and rehearsing the cut-off with a test agent. Transparency towards clients should cover both what has already been measured and what is still outstanding.
That is the NEXTAI approach: helping companies use AI with verifiable identity and controls that can be put to the test. Six questions for assessing a provider turn the concern into a concrete review.
Are we looking at an "AI uprising"?
The cases cited describe behaviours and incidents. The phrase dramatises and does not replace an analysis of causes and controls.
Does a digital ID remove that risk?
No. It provides declared identity and scope. It has to be combined with authorisation, oversight and effective execution controls.
