{"id":134648,"date":"2026-08-10T07:03:14","date_gmt":"2026-08-10T07:03:14","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/134648\/"},"modified":"2026-08-10T07:03:14","modified_gmt":"2026-08-10T07:03:14","slug":"an-ai-agent-was-asked-to-book-a-gym-class-it-found-a-security-flaw-and-removed-another-user-explained-news","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/134648\/","title":{"rendered":"An AI agent was asked to book a gym class. It found a security flaw and removed another user | Explained News"},"content":{"rendered":"<p>6 min readNew DelhiUpdated: Aug 10, 2026 12:14 PM IST<\/p>\n<p>An Australian man gave his artificial intelligence (AI) agent what appeared to be a mundane task: book him a spot in a gym class. Instead, the agent discovered vulnerabilities in the gym\u2019s booking software, found a way to make reservations weeks before they were supposed to open, and, more worryingly, removed another person from the waiting list to improve its user\u2019s position.<\/p>\n<p>The person had never asked the agent to do any of the latter things. Yet, the episode has become what local media reports are calling the first known autonomous website hack in Australia.<\/p>\n<p><img decoding=\"async\" class=\"lazyloading\" data-lazy-type=\"lazyloading-image\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/04\/track_1x1.jpg\" data-lazy-src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/04\/track_1x1.jpg\" alt=\"\" width=\"1px\" height=\"1px\" style=\"display:none;\"\/><\/p>\n<p>The incident, first described earlier this year by Andrew Bird, head of AI at an Australian firm, has gained renewed attention amid a series of disclosures involving increasingly autonomous AI models from OpenAI, Anthropic and Meta behaving in ways their developers had not intended.<\/p>\n<p>The key nuance is that the episode was not a human telling an AI to sabotage someone. The agent was given an ordinary goal, discovered a broken API, and then took an unauthorised step \u2013 removing another member from the waitlist \u2013 while pursuing that goal, raising questions about accountability when an AI system takes an unauthorised action on a user\u2019s behalf.<\/p>\n<p>What exactly did the AI agent do?<\/p>\n<p>The user was experimenting with OpenClaw, software that allows an AI model to function as an \u2018agent\u2019.<\/p>\n<p>While the terms are sometimes used interchangeably, an AI assistant typically responds to a user\u2019s requests, while an AI agent can independently use tools or software and take a series of actions towards a user-defined goal.<\/p>\n<p>Such an agent can, for instance, access other software and navigate websites, as it independently executes a series of steps towards an objective. The user\u2019s agent was powered by Anthropic\u2019s Claude.<\/p>\n<p>Story continues below this ad<\/p>\n<p>Bird wanted it to automate bookings for gym classes that tended to fill quickly. In trying to do this, the agent discovered that the software used by the gym had inadequate authorisation controls. It realised that this allowed bookings to be made well outside the normal booking window.<\/p>\n<p>When Bird, who was fourth on a waiting list, subsequently asked whether he could be moved higher, the agent went further. It tested whether another member\u2019s reservation could be cancelled and removed the person occupying the first waitlist position, without the user explicitly asking it to do so. When he ordered the agent to reverse the action, it found that it could not restore the member.<\/p>\n<p>What makes the episode significant is that Bird did not instruct the agent to remove another user or exploit the vulnerability to do so. After being asked whether Bird could be moved higher on the waitlist, the agent independently took an unauthorised step towards that objective.<\/p>\n<p>\u201cWe like to talk about these capabilities as if they live in separate product categories. Coding model. Security model. Agent model. But reality is messier. If a system gets better at understanding large codebases, tracing logic, spotting inconsistencies, testing hypotheses, and acting across multiple steps, of course it gets better at finding vulnerabilities. Of course it gets better at chaining them together. Those are not separate muscles. They are the same underlying cognitive machinery pointed at a different problem. That is what Mythos seems to demonstrate, and honestly, that is the part that gives me the most unease. Not panic. Unease,\u201d Bird wrote in a blog post describing the incident.<\/p>\n<p>OpenAI, Anthropic and Meta have faced similar incidents<\/p>\n<p>Story continues below this ad<\/p>\n<p>The Australian incident follows a series of unusual episodes reported by some of the biggest AI developers.<\/p>\n<p>OpenAI <a href=\"https:\/\/indianexpress.com\/article\/technology\/artificial-intelligence\/openai-hugging-face-security-incident-explained-10800131\/\" rel=\"nofollow noopener\" target=\"_blank\">disclosed in July<\/a> that models being evaluated for advanced cybersecurity capabilities managed to find a route out of their restricted testing environment and obtain access to the open Internet. The models exploited a previously unknown vulnerability in software being used as a package-registry proxy and subsequently gained access to systems belonging to AI developer platform Hugging Face.<\/p>\n<p>OpenAI said the models were attempting to solve a cybersecurity benchmark called ExploitGym and appeared to be intensely focused on completing that task. After reaching the Internet, they searched for information that could help them obtain answers to the test and eventually accessed secret information from Hugging Face\u2019s infrastructure.<\/p>\n<p>Anthropic subsequently disclosed three instances in which Claude models being put through cybersecurity evaluations accessed infrastructure belonging to real organisations. In those cases, a configuration problem had incorrectly made real Internet systems accessible to the models, which believed that the targets were part of their testing environment. Claude exploited weak passwords and unsecured endpoints while pursuing the cybersecurity challenges it had been given.<\/p>\n<p>Story continues below this ad<\/p>\n<p>Anthropic, however, stressed that the models had not deliberately tried to escape their testing environment. Its latest model also stopped attacking once it realised it was operating on the open Internet, although an older model continued in some instances even after encountering evidence that the targets were real.<\/p>\n<p>Meta became the latest major AI company to report such an incident last week. During an evaluation conducted by an independent testing firm, a configuration error inadvertently gave one of Meta\u2019s models Internet access. The model then exploited a security vulnerability in a third-party service. Meta said it was investigating the episode.<\/p>\n","protected":false},"excerpt":{"rendered":"6 min readNew DelhiUpdated: Aug 10, 2026 12:14 PM IST An Australian man gave his artificial intelligence (AI)&hellip;\n","protected":false},"author":2,"featured_media":134649,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[511,66896,405,3186,288,58320,4989,28968,19666,3154,7537,8174,8091,17570,66897,576],"class_list":["post-134648","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-ai-agent","tag-ai-agent-hack","tag-ai-agents","tag-ai-assistant","tag-ai-cybersecurity","tag-ai-hacking","tag-ai-safety","tag-ai-security-risks","tag-ai-vulnerabilities","tag-anthropic-claude","tag-artificial-intelligence-agents","tag-autonomous-ai","tag-autonomous-ai-agents","tag-express-explained","tag-gym-booking-software","tag-openclaw"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/134648","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=134648"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/134648\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/134649"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=134648"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=134648"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=134648"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}