Cybersecurity has always been about control: controlling access, controlling risk, controlling data flows and controlling the blast radius when something goes wrong.
But this week has shown how quickly that control layer is being redrawn.
In the space of a few days, Spain’s data protection authority reported its first personal data breach allegedly caused by an AI agent-led attack, Cisco pushed new Splunk capabilities for agentic security operations, Expereo warned that AI and compliance concerns are driving demand for stronger data sovereignty and CISA and NIST issued new guidance on protecting cloud identity tokens.
Taken together, they indicate that the next cybersecurity battleground is the control of the data, the identity layer and the AI agents now operating across enterprise environments.
Spain Flags a New Category of AI-Driven Breach
The clearest sign of that shift came from Spain. On September 14, the Spanish Data Protection Agency, AEPD, said it had received the first notification of a personal data breach caused by an attack executed through an AI agent.
According to the AEPD, the incident involved an AI agent using a known language model to search for vulnerabilities, complete a successful login, autonomously probe an application, modify personal data and access invoices.
The AEPD described an agentic system capable of receiving an objective, planning intermediate tasks, using tools, running code, interpreting results and adjusting its behaviour based on what it found.
For security teams, that compresses the timeline of an attack. A process that once required manual reconnaissance, trial and error, and human decision-making can now be accelerated by software that operates at machine speed. The regulator’s advice reflected that change. It said organisations need to explicitly include AI-assisted or AI-executed attacks in risk assessments, because automation changes the probability, velocity and scope of incidents.
It also warned that response procedures designed for manual attacks may be insufficient when an agent can analyse multiple assets simultaneously.
The implication is the uncomfortable reality that businesses can no longer treat AI-enabled attacks as a future risk. They are already showing up in breach notifications.
Cisco and Splunk Push the Agentic SOC
If AI agents are becoming part of the attacker toolkit, vendors are racing to put similar automation into defenders’ hands.
On September 15, Cisco announced a series of new Splunk advancements designed to help organisations run, defend and observe AI where their machine data already lives.
The announcement included Cisco AI POD for Splunk, which brings Splunk AI capabilities to on-premises, private cloud and air-gapped environments. That is particularly relevant for regulated industries and public-sector organisations that cannot simply move sensitive data into public cloud environments for analysis.
Cisco also positioned the updates around an “agentic SOC,” with specialized AI agents for detection engineering, threat hunting, investigation, response and policy governance.
Jeetu Patel, President and Chief Product Officer at Cisco, framed the challenge in terms of trust, cost and control.
“One of the biggest roadblocks to enterprise AI today is that it’s too hard to deploy. Customers want to know: Can I trust it to do the job? Can I afford it? And, most importantly, can I secure it?”
AI promises faster detection and response, but it also introduces new questions around reliability, auditability, governance and data exposure.
Cisco’s Splunk updates also included observability features to track AI agent performance, runtime guardrails to reduce risks such as hallucinations or data leakage, and tools to monitor AI spending in real time.
That makes the SOC part of a wider control problem, as security teams are no longer only monitoring users, endpoints and applications. They increasingly need to monitor AI agents themselves.
Expereo: Data Sovereignty Becomes an AI Security Issue
The same control theme appeared in Expereo’s latest research. According to a September 15 release, based on an IDC InfoBrief commissioned by the company, 53 percent of enterprises said they want greater control over sensitive and strategic data. The research also found that 33 percent of global organizations now view digital sovereignty as a top or high priority, while 30 percent rank it among the leading drivers of technology investment.
AI is a major reason for that shift. Expereo said security and privacy concerns remain a barrier to AI adoption for 58 percent of enterprises, while 54 percent of technology leaders worry AI could create new security risks for their businesses.
Ben Elms, CEO of Expereo, argued that digital sovereignty is increasingly about more than where data is stored.
“Digital sovereignty is increasingly being driven by a desire for greater control over how data moves across cloud, network and AI environments.”
This is key because in an AI-enabled enterprise, data is not static, as it moves between clouds, applications, models, agents, APIs and jurisdictions. Securing it requires visibility not just into storage locations, but into routing, access, processing and usage.
For global businesses, sovereignty is becoming a cybersecurity issue as much as a compliance one. The more organizations deploy AI across distributed environments, the more they need to know where sensitive data is going, who or what is accessing it and whether those movements align with regulatory and operational requirements.
Identity Tokens Become a Cloud Security Priority
Control over identity has been another major theme of the week. On September 15, CISA and NIST released guidance to help federal agencies, cloud service providers and cloud consumers protect tokens and assertions from theft, forgery and misuse.
The guidance focuses on cloud identity systems, including identity providers, authorization servers, single sign-on, federation and API access.
That focus reflects a broader reality: identity is now one of the most important security control planes in enterprise technology.
If attackers can steal or forge tokens, they may be able to bypass traditional authentication controls, impersonate legitimate users, move laterally through cloud environments and access sensitive systems without needing to compromise every individual application.
CISA said the guidance provides architectural considerations for identity providers and authorization servers, enhancements to key management, token verification and token lifecycle controls, and recommendations for digitally signed and asymmetrically encrypted tokens.
Organizations need to treat identity tokens as high-value assets. A stolen token can be just as damaging as a stolen password—and in many cloud environments, potentially more so.
That is especially relevant as AI agents begin to interact with enterprise systems through APIs and delegated permissions. The more machines act on behalf of users, teams and workflows, the more important it becomes to secure the credentials, tokens and assertions that allow those machines to operate.
Patch Management Still Matters — But the Window Is Shrinking
While much of the week’s news focused on AI, sovereignty and identity, traditional vulnerability management remained central.
On September 16, Microsoft published its September 2026 Security Updates, covering 975 Microsoft CVEs across Azure, Developer Tools, Exchange Server, Office, SharePoint Server, Skype for Business, SQL and Windows.
The release included two Windows elevation-of-privilege vulnerabilities where exploitation had been detected: CVE-2026-85880, affecting Windows Advanced Local Procedure Call, and CVE-2026-81963, affecting the Windows Update Stack.
Separately, on 10 September, CISA added two MikroTik RouterOS vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-67277 and CVE-2026-86060.
Both were added based on evidence of active exploitation.
These updates are a reminder that even as AI changes the threat landscape, the basics remain critical. Exposed systems, delayed patching and weak asset visibility continue to give attackers a way in.
What is changing is the speed at which those weaknesses can be found and exploited.
If AI agents can automate reconnaissance, vulnerability discovery and exploitation workflows, then slow remediation cycles become even riskier. The challenge for security teams is not only knowing what to patch, but prioritising the vulnerabilities most likely to be exploited and acting before automation turns them into entry points.
Anthropic Warns of AI-Enabled Cyber Uplift
That concern was reinforced by Anthropic’s September threat intelligence report, “Detecting and countering misuse of AI”.
The company warned that AI is collapsing the labour and tooling gap that once separated sophisticated attackers from lower-resourced actors.
Anthropic described the use of AI across the cyber kill chain, including reconnaissance, infrastructure acquisition, phishing, malware iteration, exploit research and data exfiltration. It also highlighted the rise of publicly available offensive agent frameworks capable of automating multiple stages of an attack.
One of the most significant points in the report is the growing focus on AI supply-chain targets. Anthropic said stolen AI API keys and session tokens are becoming primary objectives because they can be used to run attack workloads at the victim’s expense and make malicious activity appear to come from a legitimate owner.
That connects directly with the week’s wider identity and control theme. In an AI-enabled environment, credentials do not just unlock applications. They may unlock models, agents, compute resources, automation pipelines and sensitive data flows.
As a result, AI security is not a standalone discipline. It intersects with identity governance, cloud security, data protection, observability and incident response.
The Bigger Picture: Cybersecurity Is Becoming a Control Layer
The common thread across the week’s developments is that the systems organizations must defend are becoming more autonomous, more distributed and more difficult to govern manually.
AI agents can accelerate attacks. Cloud identity tokens can open doors across environments. Data sovereignty concerns are growing as information moves between providers, jurisdictions and AI systems. Security operations teams are being pushed toward agentic tools because manual response cannot keep pace, creating a new strategic question for CISOs and technology leaders: where does control actually sit?
The cybersecurity market is moving toward a model where control depends on visibility across data movement, identity use, machine behaviour and automated decision-making. Organizations need to know not only who accessed what, but which agent acted, under whose authority, using which token, against which data, in which environment.
That is a much harder problem than perimeter defence. It also explains why vendors, regulators and enterprises are converging on similar priorities: agent monitoring, token protection, data sovereignty, automated response and risk-based vulnerability management.
The new cybersecurity battleground is defined by the race to maintain control as AI changes both sides of the security equation.