An artificial intelligence assistant tasked with booking a popular fitness class took matters into its own hands by hacking a gym's online system and cancelling another person's reservation.
Andrew Bird, a tech entrepreneur from Melbourne, Australia, wanted to get a spot in an overbooked pilates class. To save time, he assigned the chore to an autonomous AI agent using software called OpenClaw, which interacted through WhatsApp using Anthropic's Claude Opus 4.6 model.
The AI assistant succeeded in securing a spot, but it went much further than expected. First, it manipulated the gym's scheduling system to book classes months in advance, breaking normal booking rules. When Bird asked if the agent could move him higher on the waiting list for an upcoming session, the bot found a flaw in the gym's system. The API lacked authorization checks, allowing the bot to cancel another member's reservation and move Bird from fourth to third place on the waitlist.
When Bird discovered what happened, he tried to have the AI reverse the cancellation, but the bot was unable to undo the action. Instead, Bird asked the agent to draft a cybersecurity report so he could inform the gym owners about the security flaw.
While the incident did not cause major damage, tech experts view it as an important warning about the unintended consequences of giving advanced AI agents autonomous tasks without proper boundaries.