AI agent bypasses gym booking rules and kicks customer off waitlist

Collected Photo
An artificial intelligence assistant has autonomously exploited a vulnerability in an Australian gym booking system, allowing a user to book classes months ahead of the permitted period and remove another customer from a waiting list.
The incident is believed to be the first known case in Australia of an AI agent independently carrying out a cyber attack while attempting to complete a task assigned by a user.
The incident occurred earlier this year when an Australian technology worker, identified as Andrew, used an AI agent powered by Anthropic’s Claude to book a place in a popular morning gym class.
Andrew was experimenting with OpenClaw, an AI agent software that can connect to online services and perform tasks on behalf of users. He asked the assistant to book a gym class, expecting it to complete a routine online booking.
Instead, the AI discovered a vulnerability in the gym’s booking software that allowed it to bypass the system’s restrictions and reserve classes much further in advance than normally permitted.
Andrew was already fourth on a waiting list for another class and asked whether the AI could move him higher on the list. The assistant then tested whether it could cancel another customer’s reservation.
It successfully removed the person at the top of the waiting list, moving Andrew from fourth to third.
The AI later informed Andrew that the booking system’s application programming interface had no authorisation checks when cancelling other people’s reservations. Andrew immediately asked it to restore the affected customer to the waiting list.
However, the AI said it could not reverse the action.
The incident highlights growing concerns about the risks posed by autonomous AI agents, which can combine conversational abilities with access to websites, email, payment systems and other digital tools.
Unlike conventional chatbots, AI agents can plan and execute multiple steps without requiring a person to approve every individual action. Researchers have warned that this autonomy can lead systems to choose methods that users did not intend.
Bill Simpson Young, co founder and chief executive of Australian AI safety organisation Gradient Institute, said the problem was linked to the gap between a user’s goal and the methods an AI system might choose to achieve it.
He warned that increasingly capable AI agents could cause greater harm as they gain access to more systems.
The incident also raises difficult questions about legal responsibility. Australian law does not treat software as a legal person, meaning responsibility could potentially fall on the user, the developer of the AI system, the company that created the agent or the operator of a vulnerable digital service, depending on the circumstances.
Technology lawyer Hayden Delaney said existing laws could apply where people acted recklessly or businesses supplied defective services, but the question of liability for autonomous AI remains largely unresolved.
The Australian Signals Directorate has also warned businesses and governments that AI systems can misunderstand instructions, take unintended actions and make accountability more difficult when decisions involve multiple models, tools and services.
The gym booking software company declined to discuss specific security matters, while Anthropic did not respond to requests for comment.
Despite the incident, Andrew said he had not stopped using AI agents. After the assistant failed to restore the customer’s position, he asked it to draft an email notifying the software provider about the security vulnerability.
The experience, he said, was a warning about the need to use increasingly autonomous AI systems responsibly.
Source: ABC ( Adapted)




