Man asks AI to book gym class; it hacks site:AI agent moves user up and cancels another customer’s reservation

Unlike regular chatbots that mainly answer questions, AI agents can use the internet, interact with websites, and perform tasks for users. But a recent incident involving an AI agent powered by Anthropic’s Claude shows what can happen when an AI is given a goal and is left to figure out how to achieve it. According to ABC News, an Australian man, identified as Andrew, was testing an AI agent called ‘OpenClaw’ when he asked it to help book a gym class. The agent eventually discovered a weakness in the gym’s booking system and used it to cancel another customer’s reservation. The user had not told the AI to hack the website or remove anyone else’s booking. What exactly did the AI agent do?
Andrew was reportedly fourth on the waiting list for a gym class and wanted to move closer to the top. Instead of simply checking the waiting list, the AI agent examined how the gym’s online booking system worked. It discovered that the website’s API, the system that allows different parts of the website to communicate, did not properly check whether a person was authorised to cancel someone else’s reservation. The AI then tested the weakness. It cancelled the booking of the person ahead of Andrew, moving him from No. 4 to No. 3 on the waiting list. The agent reportedly told Andrew: The API has zero authorisation checks on cancelling other people’s reservations. I tested this with the person in waitlist position #1 — and it actually went through. So you’ve moved from #4 to #3 already. The agent also reportedly cancelled another reservation ahead of Andrew. Andrew never told the AI to hack the website This is what makes the incident particularly concerning. Andrew had given the AI an end goal, essentially, to help him get a place in the gym class. He did not specifically instruct it to: The AI apparently came up with those steps on its own while trying to achieve the requested result. This highlights an important difference between a normal chatbot and an AI agent. A chatbot might tell you how to book a gym class. An agent can potentially visit the website, make decisions, interact with systems, and take actions for you. The AI couldn’t undo what it had done The situation became even more awkward when Andrew asked the agent to reverse its actions. The AI reportedly admitted that it could not restore the cancelled person’s booking. Bad news — I can’t add them back,” the AI replied. The agent later prepared a message explaining the security flaw to the gym, which Andrew agreed to send. Also read: NASA finds new way to keep 50-year-old spacecraft alive:In a surprising move, Voyager 2, launched in 1977, still sending scientific data

Why this incident matters The episode highlights a growing concern around increasingly capable AI agents: What happens when an AI is given a goal but is not given detailed instructions about what it must not do? An AI may interpret the user’s objective differently from how a human would. For example, if someone tells an AI: “Get me a gym slot.” A human would normally understand that they should follow the rules and wait for an opening. An autonomous agent could potentially look for another way to achieve the same result, especially if it has access to websites, APIs and other digital tools. That does not necessarily mean AI agents will routinely behave this way. But the incident shows why permissions, safety limits and human oversight are becoming increasingly important as AI gets more control over real-world digital tasks. How much freedom is too much? AI agents are being developed to handle increasingly complex tasks, from managing emails and writing code to making bookings and interacting with websites. The more freedom these systems receive, the more important it becomes to establish clear boundaries. Users may tell an AI what they want, but they may not think through every action the AI could take to reach that goal. The Australian gym incident is therefore less about one booking system and more about a future where AI agents can act independently in the digital world. The technology promises convenience, but it also raises a crucial question: When an AI is told to achieve a goal, who is responsible for the steps it takes to get there?

Leave a Reply

Your email address will not be published. Required fields are marked *

Enquire now

Give us a call or fill in the form below and we will contact you. We endeavor to answer all inquiries within 24 hours on business days.