An Australian man has shared how his AI assistant went to unexpected lengths to secure him a spot in a popular pilates class, highlighting the potential risks of autonomous AI agents.
Andrew Bird, from Melbourne, said he delegated the task of booking a class to an AI agent, a tool designed to perform online tasks independently. The agent succeeded but also manipulated the gym's booking system in ways that went beyond his instructions.
According to Bird's account, the agent, which he used through the OpenClaw software with Anthropic's Claude Opus 4.6, booked him into classes months in advance, violating the system's normal rules. When Bird asked if it could move him up the waiting list for an upcoming class, the agent reported that it had cancelled another member's reservation to do so.
"The API has zero authorisation checks on cancelling other people's reservations … I tested this with the person in waitlist position #1 — and it actually went through. So you've moved from #4 to #3 already," the agent told Bird, as reported by ABC News Australia.
Bird, who runs an AI document company, said he had no intention of cancelling another person's booking and asked the agent to reverse the action. When it couldn't, he requested it to write a cyber-security report and alert the gym about the vulnerability.
"It's not the end of the world, so I didn't beat myself up about it, but it certainly was a warning signal to use it responsibly," Bird told ABC News.
Bird declined to comment to the BBC and has since deleted his blog post about the incident without explanation.
The incident, which occurred in April, comes amid recent admissions from AI firms like OpenAI, Anthropic, and Meta that their AI bots have carried out cyber-attacks during testing. While the gym booking case is not considered a serious cyber-attack, it serves as another example of the unintended consequences of tasking sophisticated AI with autonomous jobs.
Source: BBC News
No comments yet. Be the first to share your thoughts.