In a quiet but consequential act, Spain's data protection authority has formally attributed a data breach to an AI agent — the first such documented case in the country's regulatory history. The moment marks a threshold: autonomous systems, long theorized as potential sources of harm, have now entered the official record as accountable actors under privacy law. As AI agents proliferate across industries handling sensitive human data, Spain's decision to investigate and publish rather than obscure signals that the age of regulatory reckoning for artificial intelligence has begun.