Offensive AI: When Artificial Intelligence Accelerates Risks to Data Protection
Artificial intelligence (AI) has transformed digital services, including those used by cybercriminals, who use it, particularly AI agents, to accelerate cyberattacks, reduce intrusion times and exploit vulnerabilities in an automated way. The succession of massive personal data breaches highlights a paradigm shift in cybersecurity. This shift requires analysing the vulnerabilities of digital resources, as well as reflecting on the measures that should be taken in both the short and long term.
Designed by Magnific.
Offensive AI is the use of artificial intelligence systems to enhance, automate, or execute actions aimed at compromising, damaging, or exploiting computer systems, infrastructures, organisations, or people. LLMs used in isolation still have limitations in generating sophisticated and operational malware. However, with agentic AI systems and the expertise of an experienced attacker, they can become a significant capability multiplier. This combination significantly increases the quality, speed, scale, and degree of automation of different phases of a cyberattack.
The most relevant impact of offensive AI is the virtual disappearance of the so-called "exposure window", i.e. the interval between the discovery of a vulnerability and its exploitation. Due to the speed of AI agents, a newly discovered vulnerability can become a weapon almost immediately, reducing the average time between initial access to a system and data exfiltration to a matter of minutes. To this must be added a change in approach: no longer an isolated vulnerability is attacked, but AI analyses and exploits the weaknesses of an entire ICT infrastructure.
The key to the success of AI can be seen in the description made by its creators in a real case: A particular piece of code had an extremely rare crash, about one in a million runs, that nobody on our team had explained in four to five years. Every model I tried, missed it. What did AI do? It disassembled an external vendor library, matched it against the core dump, and traced the crash to a bug inside that vendor’s code. The time it would have taken to conduct that analysis is hard to justify. Not impossible. Not beyond human ability. Just economically irrational to attempt. This description already shows serious pre-existing structural cybersecurity problems: legacy systems, undocumented systems, the persistence of known N-day vulnerabilities, failures in the supply chain and, ultimately, a lack of accountability.
The above example shows the magnitude of the problem: rather than being merely a specific vulnerability affecting a particular organisation, we are dealing with a systemic weakness. This has its origin in a certain way of understanding digitalisation policy and in the way in which connected services and automation have been deployed, in general, which have led to the creation of an ICT infrastructure that is "insecure by design". Behind all this there is an attitude of resignation, assumed over the years, to the idea that ICT systems have errors and vulnerabilities and that it is up to users to patch them continuously, unlike what happens in other key industrial sectors, such as aerospace, automotive or energy.
This lack of quality in ICT applications and services had been more or less sustainable, although they had already produced serious disruptions in essential services even on a global scale, such as cloud services outages. However, the irruption of offensive AI, whose capacity is growing exponentially, has made the current cybersecurity status quo unsustainable. Therefore, addressing this problem requires us to ask how we have reached this situation.
The question asked admits many answers. Among them is the abandonment of robust systems-development methodologies in favour of agile methodologies, and even, more recently, the so-called vibe coding with AI, without a real commitment to code quality, accountability and development according to adequate specifications, including strict security and testing requirements. The problem is not limited to code; many ICT services are fragile by their very architecture, due to lack of segmentation, isolated environments, process recovery procedures (not only data), and excessive internet connectivity and poorly understood interoperability. Added to this is the limited capacity for control over the supply chain of services and systems, as there is a strong dependence on large external providers (third-party software, cloud, AI, etc.) subject only to contractual oversight, without any real capacity to audit those third parties, and an interdependence between dozens of services from different providers that, although efficient in the short term, means that the fall of just one of them can collapse entire sectors. The latter can be seen in the personal data breaches that occur in a few data processors, but that affect hundreds or thousands of data controllers in a sector that is technologically dependent on them. In relation to the above, it is observed that massive outsourcing erodes the internal technical knowledge of organisations (know-how) and leads to the deployment of components that function as genuine black boxes.
Some decision-making bodies lack solid knowledge of ICT systems, which translates into a lack of critical analysis in strategic decisions, which are conditioned by the expectations generated by solution providers, technological fashions and short-term policies. A market for "insecure by default" products tends to be assumed as inevitable and there is a poor understanding of both the risks, especially for the rights and freedoms of natural persons, and the costs, in time and resources, required to select, design, test, deploy and maintain a system with guarantees. As a result, many organisations have fallen into a policy of minimum security, of "ticking boxes", not adapted to the peculiarities of each processing activity, in which norms and standards are used more as an instrument of legal certainty than as a guide for effective cybersecurity.
Faced with this scenario, the response to offensive AI should combine two time horizons: short-term strategies, which reduce the impact of a risk that is already materialising, and long-term strategies that eliminate this structural vulnerability to make the digitalisation model itself sustainable and preserve confidence in the digital economy in the face of future AI
Among the short-term measures, it could be suggested that organisations become aware of the high probability of massive personal data breaches (notifications to the AEPD have increased by 150% in 2026 compared to 2025) and to carry out a risk analysis and management that is not limited to cybersecurity or legal certainty, but is systematic and multifaceted, and especially focused on the rights and freedoms of natural persons. Hence, act accordingly: inventory of the attack surface and edge devices, analyse scenarios of potential breaches, assume a Zero Trust approach, include phishing-proof MFA, least privilege, establish separate administrative accounts, review permissions, audits and automatic decision-making processes in the event of massive or unusual access, perform secret/token management and reduce persistent credentials, minimise exposure to the internet and isolate or restrict the connectivity of critical systems, take offline any data not in immediate use, purge data outside the retention period and uncontrolled copies, ensure the ability to restore data, processes and services, and increase privacy (OSINT footprint) against social engineering.
In addition, there are other short-term measures such as introducing out-of-band authentication, establishing human-supervised checkpoints in automated processes, shutting down access to unauthorised services, removing or strictly controlling the use of personal devices (BYOD) and mobile devices that do not offer sufficient guarantees. Also, establish procedures that allow incidents to be detected, escalated, evaluated and documented immediately and have the capacity to make notifications to the data protection authority, CSIRT or other authorities, establish real coordination between the DPO and the security officer and, where appropriate, communicate the breach to affected persons without undue delay. All these procedures must be tested in simulations of serious security incidents.
Unsupervised automatic patching as a short-term solution requires careful consideration. A patch is, in practice, an untested modification in the specific environment in which it is installed; automating its deployment is equivalent to accepting changes in production without prior validation. Its application transfers to the supplier a decision that is the responsibility of the organisation, when the software supply chain is today a priority target, and automatic patching is its natural entry point. If thousands of organisations update at the same time and without control, a single compromised patch becomes an incident of global impact. Automating patching with AI agents adds an additional layer of opacity. If it is used, real impact should be prioritised, ring deployment and tested rollback should be performed, and other controls applied while validating.
Structural problems require long-term strategies that ensure sustainability. These include the real governance of digital technologies throughout its entire life cycle and, in particular, for AI services. It must be assumed that there are no perfect systems or technological miracles and that, therefore, it is essential to dedicate time to analysis, development and testing, providing each project with the necessary resources. Security training should focus on strategic decision-makers, who must have a real and well-founded knowledge of the capabilities, limitations and vulnerabilities of ICT systems, as well as the management of their organisations' processes.
Equally essential is the strengthening of the Record of Processing Activities (ROPA) as an effective management tool – controlling what data is processed, how, where, who does it and for what purpose – the redesign of processing with strict data minimisation criteria, the management of identity architecture as a critical factor, the deployment of automation systems as untrusted users and the incorporation of robust development methodologies by default. Added to this is the need to recover technical knowledge within organisations, to have realistic infrastructures and contingency plans, equipped with resources, that guarantee resilience to external service failures, internal attacks or power outages, and to develop the ability to operate in degraded mode, with manual procedures for critical processes and "switches" that allow automations to be stopped.
These long-term strategies are complemented by the achievement of digital sovereignty, which requires effective control of supply chains, security of systems by design and transparency throughout the value chain of digital systems, including AI and agentic systems, without accepting black boxes or only contractual security. Added to this are the reduction of concentration and dependence on single suppliers, together with automatic auditing and real control over them, a specific policy for legacy systems and the incorporation of trust limits, infrastructure segmentation and minimum necessary interoperability in the design of ICT services.
In short, it is about organisations being able to manage the complete life cycle of data, the processes and the systems that implement them in the long term.
This blog article is related to other materials published by the Innovation and Technology Division of the AEPD, such as:
- Primera notificación de una brecha de datos personales causada por un ataque ejecutado mediante un agente de IA [sept 2026] [in Spanish]
- Blog Article Operational sovereignty in the processing of personal data [feb 2026]
- Personal Data Breach: Security Focused on Processing [mar 2024]
- Guidelines for the validation of cryptographic systems in data protection processing [may 2023]
- ValidaCripto RGPD_Guidance for the validation of cryptographic systems in data protection [oct 2023]
- Personal Data Breaches: Development and Pre-Production Environments [apr 2022]
- Without privacy there is no cybersecurity [feb 2022]
- Personal data breaches: Ransomware and risk management[dic 2020]