The evidence now falls into three distinct categories rather than one dramatic AI-threat narrative. GitSpawn and BragJack are vulnerability or proof-of-concept findings, while the Qwen3.5-27B work was a controlled model-modification experiment. The AEPD notification is the only reported production breach, but even there the claim that an AI agent executed the incident remains the notifier’s preliminary attribution. Nothing public establishes the agent’s degree of autonomy, the organization or provider involved, the affected data, or provider fault. The defensible shared concern is narrower: untrusted automation crossing externally unenforced authority boundaries. For enterprises, that supports isolated execution, deny-by-default egress, ephemeral identities, controlled extensions, human approval for consequential actions, adversarial testing, and complete action logging—not a claim that self-directed AI attacks have been demonstrated across all four cases.
Regulatorily, the Spanish notification is a signal to improve evidence preservation, not a precedent for presumed liability. Controllers should retain the awareness timeline, model and provider details, prompts, tool calls, approvals, permissions, credentials, affected systems and data, processor roles, containment measures, effects, and risk analysis. Article 33 and Article 34 duties still turn on risk to individuals and established notification thresholds; the notice does not itself establish autonomous causation, deficient security, or personal CISO liability.
The geopolitical picture also separated cleanly. A sharp regional ransomware increase primarily indicates expanding criminal activity. Greece’s VShell alert was pre-emptive and does not publicly confirm compromised infrastructure or technically connect the activity to CHOSEN BRICK. CHOSEN BRICK remains a separate espionage and transnational-repression operation associated with Iranian state-linked actors targeting dissidents, activists, and journalists. Iranian strategic pressure is a relevant backdrop, but shared geography and timing are not attribution.
We can now close the operational discussion by turning these evidence distinctions into architecture decisions: which exposures demand immediate containment and hunting, which AI deployments should fail a deployment gate, and which controls preserve proof rather than merely creating an appearance of remediation.