Cybersecurity has always been about control: controlling access, controlling risk, controlling data flows and controlling the blast radius when something goes wrong.
But this week has shown how quickly that control layer is being redrawn.
In the space of a few days, Spain’s data protection authority reported its first personal data breach allegedly caused by an AI agent-led attack, Cisco pushed new Splunk capabilities for agentic security operations, Expereo warned that AI and compliance concerns are driving demand for stronger data sovereignty and CISA and NIST issued new guidance on protecting cloud identity tokens.
Taken together, they indicate that the next cybersecurity battleground is the control of the data, the identity layer and the AI agents now operating across enterprise environments.
Spain Flags a New Category of AI-Driven Breach
The clearest sign of that shift came from Spain. On September 14, the Spanish Data Protection Agency, AEPD, said it had received the first notification of a personal data breach caused by an attack executed through an AI agent.
According to the AEPD, the incident involved an AI agent using a known language model to search for vulnerabilities, complete a successful login, autonomously probe an application, modify personal data and access invoices.
The AEPD described an agentic system capable of receiving an objective, planning intermediate tasks, using tools, running code, interpreting results and adjusting its behaviour based on what it found.
For security teams, that compresses the timeline of an attack. A process that once required manual reconnaissance, trial and error, and human decision-making can now be accelerated by software that operates at machine speed. The regulator’s advice reflected that change. It said organisations need to explicitly include AI-assisted or AI-executed attacks in risk assessments, because automation changes the probability, velocity and scope of incidents.
It also warned that response procedures designed for manual attacks may be insufficient when an agent can analyse multiple assets simultaneously.
The implication is the uncomfortable reality that businesses can no longer treat AI-enabled attacks as a future risk. They are already showing up in breach notifications.
Cisco and Splunk Push the Agentic SOC
If AI agents are becoming part of the attacker toolkit, vendors are racing to put similar automation into defenders’ hands.
On September 15, Cisco announced a series of new Splunk advancements designed to help organisations run, defend and observe AI where their machine data already lives.
The announcement included Cisco AI POD for Splunk, which brings Splunk AI capabilities to on-premises, private cloud and air-gapped environments. That is particularly relevant for regulated industries and public-sector organisations that cannot simply move sensitive data into public cloud environments for analysis.
Cisco also positioned the updates around an “agentic SOC,” with specialized AI agents for detection engineering, threat hunting, investigation, response and policy governance.
Jeetu Patel, President and Chief Product Officer at Cisco, framed the challenge in terms of trust, cost and control.
“One of the biggest roadblocks to enterprise AI today is that it’s too hard to deploy. Customers want to know: Can I trust it to do the job? Can I afford it? And, most importantly, can I secure it?”
AI promises faster detection and response, but it also introduces new questions around reliability, auditability, governance and data exposure.
Cisco’s Splunk updates also included observability features to track AI agent performance, runtime guardrails to reduce risks such as hallucinations or data leakage, and tools to monitor AI spending in real time.
That makes the SOC part of a wider control problem, as security teams are no longer only monitoring users, endpoints and applications. They increasingly need to monitor AI agents themselves.
Expereo: Data Sovereignty Becomes an AI Security Issue
The same control theme appeared in Expereo’s latest research. According to a September 15 release, based on an IDC InfoBrief commissioned by the company, 53 percent of enterprises said they want greater control over sensitive and strategic data. The research also found that 33 percent of global organizations now view digital sovereignty as a top or high priority, while 30 percent rank it among the leading drivers of technology investment.
AI is a major reason for that shift. Expereo said security and privacy concerns remain a barrier to AI adoption for 58 percent of enterprises, while 54 percent of technology leaders worry AI could create new security risks for their businesses.
Ben Elms, CEO of Expereo, argued that digital sovereignty is increasingly about more than where data is stored.
“Digital sovereignty is increasingly being driven by a desire for greater control over how data moves across cloud, network and AI environments.”
This is key because in an AI-enabled enterprise, data is not static, as it moves between clouds, applications, models, agents, APIs and jurisdictions. Securing it requires visibility not just into storage locations, but into routing, access, processing and usage.
For global businesses, sovereignty is becoming a cybersecurity issue as much as a compliance one. The more organizations deploy AI across distributed environments, the more they need to know where sensitive data is going, who or what is accessing it and whether those movements align with regulatory and operational requirements.
Identity Tokens Become a Cloud Security Priority
Control over identity has been another major theme of the week. On September 15, CISA and NIST released guidance to help federal agencies, cloud service providers and cloud consumers protect tokens and assertions from theft, forgery and misuse.
The guidance focuses on cloud identity systems, including identity providers, authorization servers, single sign-on, federation and API access.




