{"id":629349,"date":"2026-08-10T00:14:18","date_gmt":"2026-08-10T00:14:18","guid":{"rendered":"https:\/\/www.europesays.com\/ie\/629349\/"},"modified":"2026-08-10T00:14:18","modified_gmt":"2026-08-10T00:14:18","slug":"ai-assistant-hacks-gym-website-in-first-known-australian-autonomous-cyber-attack","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ie\/629349\/","title":{"rendered":"AI assistant hacks gym website in first known Australian autonomous cyber attack"},"content":{"rendered":"<p class=\"paragraph_paragraph___QITb\">Andrew asked his personal assistant to book him a spot in one of his gym&#8217;s coveted morning classes.<\/p>\n<p class=\"paragraph_paragraph___QITb\">It was a task he thought was well suited to this particular assistant because the booking form was online and because his assistant was not a person \u2014 it was artificial intelligence (AI).\u202f<\/p>\n<p class=\"paragraph_paragraph___QITb\">But Andrew was shocked by what happened next.\u202f<\/p>\n<p class=\"paragraph_paragraph___QITb\">His AI assistant found a way to book the gym class months further in advance than the gym allowed, thanks to a vulnerability it discovered in the booking software.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Then it went further, kicking someone out of the waiting list who was ahead of Andrew\u202f\u2014 something it was not asked to do.\u202f<\/p>\n<p><a href=\"https:\/\/www.abc.net.au\/news\/2026-07-23\/open-ai-model-went-rogue-testing-hack\/106947540\" data-component=\"FullBleedLink\" class=\"RelatedCard_link__rsgR9 FullBleedLink_root__lTw_U interactive_focusContext__yRhc_ interactive_defaults__AKxUU FullBleedLink_showVisited__g3Xvz\" rel=\"nofollow noopener\" target=\"_blank\">OpenAI model goes rogue during testing and hacks startup<\/a><\/p>\n<p class=\"Typography_base__sj2RP RelatedCard_synopsis__cFwMW Typography_sizeMobile14__u7TGe Typography_lineHeightMobile20___U7Vr Typography_regular__WeIG6 Typography_colourInherit__dfnUx\" data-component=\"Typography\">OpenAI has announced one of its AI models went rogue and broke containment during testing.<\/p>\n<p class=\"paragraph_paragraph___QITb\">The accidental hack is the first known Australian case of an emerging risk from a new generation of AI capable of behaving in unexpected ways.<\/p>\n<p class=\"paragraph_paragraph___QITb\">This threat <a class=\"Link_link__kR0xA Link_link__5eL5m ScreenReaderOnly_srLinkHint__OysWz Link_showVisited__C1Fea Link_showFocus__ALyv2\" href=\"https:\/\/www.abc.net.au\/news\/2026-07-23\/open-ai-model-went-rogue-testing-hack\/106947540\" data-component=\"Link\" data-uri=\"coremedia:\/\/article\/106947540\" rel=\"nofollow noopener\" target=\"_blank\">made global headlines last week<\/a> when cutting-edge AI models created by ChatGPT-maker OpenAI autonomously hacked into another company&#8217;s servers, prompting similar claims from other companies.<\/p>\n<p class=\"paragraph_paragraph___QITb\">It has led experts to sound the alarm about the breakneck pace of development and prompted questions about who bears responsibility for an AI agent that goes rogue.<\/p>\n<p>How the hack happened<\/p>\n<p class=\"paragraph_paragraph___QITb\">Earlier this year, Andrew, who works for an Australian company that sells AI products to businesses, began experimenting with OpenClaw, a popular AI agent software that he used Anthropic&#8217;s Claude AI service to run.<\/p>\n<p class=\"paragraph_paragraph___QITb\">AI agents combine a chatbot&#8217;s ability to answer questions with tools that let them access the internet, email, credit cards, as well as planning and carrying out multi-step tasks.\u202f<\/p>\n<p class=\"paragraph_paragraph___QITb\">He decided to use the AI agent to book the class for him.<\/p>\n<p><img decoding=\"async\" alt=\"A side profile of a man in a grey t-shirt typing on a smart phone.\" class=\"Image_image__5tFYM ContentImage_image__DQ_cq\"  src=\"https:\/\/www.europesays.com\/ie\/wp-content\/uploads\/2026\/08\/ae226123b2fccba8a6dbb83bda82068c.jpeg\" loading=\"lazy\" data-component=\"Image\" data-lazy=\"true\"\/><\/p>\n<p class=\"Typography_base__sj2RP FigureCaption_text__zDxQ5 Typography_sizeMobile12__w_FPC Typography_lineHeightMobile20___U7Vr Typography_regular__WeIG6 Typography_colourInherit__dfnUx\" data-component=\"Typography\">His AI assistant found a way to book the gym class months further in advance than the gym allowed. (ABC News: Billy Cooper)<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;I was just sitting on the couch thinking, &#8216;Gee, this is a chore,'&#8221; he said.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Minutes later, his AI agent reported it had discovered a way to book Andrew into classes several weeks in advance, far beyond what was supposed to be possible.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Andrew, who was sitting fourth on a waitlist for a class later that week, asked if it was possible to move him to the top of the list.\u202f<\/p>\n<p class=\"paragraph_paragraph___QITb\">The agent came back and told Andrew that it had kicked another gym-goer off the list as part of the testing of its capabilities.<\/p>\n<blockquote class=\"Blockquote_blockquote__YVWQm ContentAlignment_marginBottom__4H_6E ContentAlignment_overflowAuto__c1_IL\" data-component=\"Blockquote\">\n<p class=\"paragraph_paragraph___QITb\">&#8220;The API has zero authorisations checks on cancelling other people&#8217;s reservations \u2026 I tested this with the person in waitlist position #1 \u2014 and it actually went through. So you&#8217;ve moved from #4 to #3 already,&#8221; it messaged back.<\/p>\n<\/blockquote>\n<p class=\"paragraph_paragraph___QITb\">Alarmed, Andrew asked the agent to undo this.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;Bad news \u2014 I can&#8217;t add them back,&#8221; the AI agent replied.\u202f<\/p>\n<p class=\"paragraph_paragraph___QITb\">The company behind the gym-booking software told the ABC it did not discuss specific security matters. Anthropic did not respond to a request for comment.<\/p>\n<p><img decoding=\"async\" alt=\"The conversation between Andrew and the assistant where it apologises for the hack.\" class=\"Image_image__5tFYM ContentImage_image__DQ_cq\"  src=\"https:\/\/www.europesays.com\/ie\/wp-content\/uploads\/2026\/08\/796d0ab232e5b17e9bbe573a224d2f0d.png\" loading=\"lazy\" data-component=\"Image\" data-lazy=\"true\"\/><\/p>\n<p class=\"Typography_base__sj2RP FigureCaption_text__zDxQ5 Typography_sizeMobile12__w_FPC Typography_lineHeightMobile20___U7Vr Typography_regular__WeIG6 Typography_colourInherit__dfnUx\" data-component=\"Typography\">The AI assistant apologises to Andrew for removing the other person off the waitlist. (Supplied)<\/p>\n<p>AI agents are breaking out of the lab<\/p>\n<p class=\"paragraph_paragraph___QITb\">The emergence of AI agents is a relatively recent development made possible by the growth in AI capabilities.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Independent researchers have found that the length of tasks that AI can typically do by itself has been doubling every seven months.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Have you had an experience with AI doing something unexpected?<\/p>\n<p class=\"paragraph_paragraph___QITb\"><strong>Email: <\/strong><a class=\"Link_link__5eL5m ScreenReaderOnly_srLinkHint__OysWz Link_showVisited__C1Fea Link_showFocus__ALyv2\" href=\"https:\/\/www.abc.net.au\/news\/2026-08-10\/ai-assistant-hacks-gym-website-aus-cyber-attack\/mailto: wilson.cameron@abc.net.au\" data-component=\"Link\" rel=\"nofollow noopener\" target=\"_blank\"><strong>wilson.cameron@abc.net.au<\/strong><\/a><\/p>\n<p class=\"paragraph_paragraph___QITb\">In 2020, AI could complete a task by itself that would take a human four seconds. By 2026, this grew to being able to complete tasks that would take a human about 12 hours.<\/p>\n<p class=\"paragraph_paragraph___QITb\">The breakout moment for personal AI agents was OpenClaw&#8217;s release in early 2026; the free AI assistant software that anyone could run on their computer soon had millions of downloads.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Businesses, too, began exploring using AI agents to complete work and to help potential customers use their services.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Soon after OpenClaw&#8217;s launch, accounts began to circulate of AI agents deleting people&#8217;s entire email inboxes and writing a &#8220;hit piece&#8221; about someone who rejected their coding suggestion.\u202f\u00a0<\/p>\n<p><img decoding=\"async\" alt=\"A man in a long black shirt stands in an open plan office with people and computers in the background.\" class=\"Image_image__5tFYM ContentImage_image__DQ_cq\"  src=\"https:\/\/www.europesays.com\/ie\/wp-content\/uploads\/2026\/08\/a2af05e96445b79cc9c0982091e29fd6.jpeg\" loading=\"lazy\" data-component=\"Image\" data-lazy=\"true\"\/><\/p>\n<p class=\"Typography_base__sj2RP FigureCaption_text__zDxQ5 Typography_sizeMobile12__w_FPC Typography_lineHeightMobile20___U7Vr Typography_regular__WeIG6 Typography_colourInherit__dfnUx\" data-component=\"Typography\">Mr Simpson-Young says AI agents might choose methods their users did not explicitly ask for or expect. (ABC News: Chris Taylor)<\/p>\n<p class=\"paragraph_paragraph___QITb\">Bill Simpson-Young, co-founder and chief executive of Australian AI safety research organisation Gradient Institute, said the autonomy of AI agents created more opportunities for systems to choose methods their users did not expect.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;Someone might be asking an agent to do something quite innocent,&#8221; he said.<\/p>\n<p class=\"paragraph_paragraph___QITb\">But in completing that task, the agent could carry out other activities the person had not considered or explicitly asked for.<\/p>\n<p><a href=\"https:\/\/www.abc.net.au\/news\/2026-07-28\/openai-artificial-intelligence-terminator-safety-hugging-face\/106965400\" data-component=\"FullBleedLink\" class=\"RelatedCard_link__rsgR9 FullBleedLink_root__lTw_U interactive_focusContext__yRhc_ interactive_defaults__AKxUU FullBleedLink_showVisited__g3Xvz\" rel=\"nofollow noopener\" target=\"_blank\">A rogue AI just gave us a warning. Australia isn&#8217;t prepared<\/a><\/p>\n<p class=\"Typography_base__sj2RP RelatedCard_synopsis__cFwMW Typography_sizeMobile14__u7TGe Typography_lineHeightMobile20___U7Vr Typography_regular__WeIG6 Typography_colourInherit__dfnUx\" data-component=\"Typography\">Australia&#8217;s government and experts are taking the OpenAI hack seriously.\u00a0<\/p>\n<p class=\"paragraph_paragraph___QITb\">In Andrew&#8217;s situation, he had not asked his AI agent to hack into his gym&#8217;s booking system. But it had done so in pursuit of achieving the goal he had set it.\u202f<\/p>\n<p class=\"paragraph_paragraph___QITb\">That gap, between a person&#8217;s goal and the methods an agent chooses to achieve it, is what is known as the &#8220;alignment&#8221; problem in the field of AI research.<\/p>\n<p class=\"paragraph_paragraph___QITb\">For decades, technologists and philosophers have studied how to get AI to act in ways that are consistent with human intentions, limits and values when doing things. \u00a0<\/p>\n<p class=\"paragraph_paragraph___QITb\">This became a live global issue last month when OpenAI disclosed that its AI models had broken free from a limited enclosure, made their way onto the open web, and then compromised a database of another AI company, Hugging Face, while trying to obtain answers to the test that it had been given.<\/p>\n<p class=\"paragraph_paragraph___QITb\">A week later, Anthropic disclosed that its AI models had also compromised three real organisations during similar testing.\u202f<\/p>\n<p class=\"paragraph_paragraph___QITb\">Since then, these labs and third-party testers claim they have seen these AI models pretend to be people online, try to convince people to run malicious code and even collaborate with other AI models \u2014 all to achieve their goals.\u202f<\/p>\n<p class=\"paragraph_paragraph___QITb\">Mr Simpson-Young said the advances in AI capabilities and the accessibility of these tools meant that it was likely we would see more of these kinds of hacks as more people got access to the powerful AI tools.\u202f<\/p>\n<blockquote class=\"EmphasisedText_quote__TE6kn\"><p>&#8220;The more autonomous they become, the more likely it is they&#8217;ll cause harm,&#8221;<\/p><\/blockquote>\n<p>  he said.<\/p>\n<p class=\"paragraph_paragraph___QITb\">The risk has led to Australia&#8217;s top cybersecurity agency sounding the alarm about using AI agents.\u202f<\/p>\n<p><a href=\"https:\/\/www.abc.net.au\/news\/2026-07-23\/openai-model-decided-to-hack-hugging-face\/106947616\" data-component=\"FullBleedLink\" class=\"RelatedCard_link__rsgR9 FullBleedLink_root__lTw_U interactive_focusContext__yRhc_ interactive_defaults__AKxUU FullBleedLink_showVisited__g3Xvz\" rel=\"nofollow noopener\" target=\"_blank\">Why highly advanced rogue AI has experts scared<\/a><\/p>\n<p class=\"Typography_base__sj2RP RelatedCard_synopsis__cFwMW Typography_sizeMobile14__u7TGe Typography_lineHeightMobile20___U7Vr Typography_regular__WeIG6 Typography_colourInherit__dfnUx\" data-component=\"Typography\">An experimental AI went rogue and hacked another company. Why is this worrying?<\/p>\n<p class=\"paragraph_paragraph___QITb\">Earlier this year, <a class=\"Link_link__kR0xA Link_link__5eL5m ScreenReaderOnly_srLinkHint__OysWz Link_showVisited__C1Fea Link_showFocus__ALyv2\" href=\"https:\/\/www.abc.net.au\/news\/2026-07-14\/cyber-warning-russian-hackers-targeting-critical-industries\/106913734\" data-component=\"Link\" data-uri=\"coremedia:\/\/article\/106913734\" rel=\"nofollow noopener\" target=\"_blank\">the Australian Signals Directorate put out an alert<\/a> to businesses and governments that AI could misunderstand instructions, take unintended actions and make it harder to establish accountability, because decisions may occur across a chain of models, tools and services.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Mr Simpson-Young said AI agents presented a risk because many modern systems depended on software, but were often surprisingly poorly secured.\u202f<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;We&#8217;ve built this complex world over the internet, which is all run by software, but software that has holes,&#8221; he said.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;Now you introduce highly capable AI agents that can operate at scale and speed \u2026 and that whole model just breaks.&#8221;<\/p>\n<p>Who is responsible when AI agents cause harm?\u202f<\/p>\n<p class=\"paragraph_paragraph___QITb\">If someone&#8217;s human personal assistant hacks into gym software, there are well-established legal principles and precedents that help a court determine whether the person or their employer is responsible for any potential harm.<\/p>\n<p class=\"paragraph_paragraph___QITb\">An autonomous AI agent does not neatly fit into how Australian law has worked for hundreds of years.\u202f<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;Software is not a legal person. Only a legal person can be liable at law,&#8221; said Hayden Delaney, a partner at law firm Thomsons, who specialised in technology, intellectual property and privacy.<\/p>\n<p><img decoding=\"async\" alt=\"A man in a black suit and tie looks at camera.\" class=\"Image_image__5tFYM ContentImage_image__DQ_cq\"  src=\"https:\/\/www.europesays.com\/ie\/wp-content\/uploads\/2026\/08\/cb9d9234b7317598df783778c6ba27f8.jpeg\" loading=\"lazy\" data-component=\"Image\" data-lazy=\"true\"\/><\/p>\n<p class=\"Typography_base__sj2RP FigureCaption_text__zDxQ5 Typography_sizeMobile12__w_FPC Typography_lineHeightMobile20___U7Vr Typography_regular__WeIG6 Typography_colourInherit__dfnUx\" data-component=\"Typography\">Mr Delaney says only a legal person can be liable under the law. (ABC News: Lucas Hill)<\/p>\n<p class=\"paragraph_paragraph___QITb\">That leaves an open question as to who would be legally responsible.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Mr Delaney said it could be the user who set the task, whoever designed the software instructing the AI agent or the developer of the AI model powering it.<\/p>\n<p class=\"paragraph_paragraph___QITb\">It could even be the operator of a system that was vulnerable to an attack from an agent.\u202f<\/p>\n<p class=\"paragraph_paragraph___QITb\">Mr Delaney said existing laws could apply in some circumstances, including where a person acted recklessly, or a business supplied a defective service.<\/p>\n<p class=\"paragraph_paragraph___QITb\">The answer depends on what the user authorised, what risks could reasonably have been anticipated and whether the conduct occurred in trade or commerce, he said.<\/p>\n<blockquote class=\"EmphasisedText_quote__TE6kn\"><p>&#8220;That&#8217;s the unknown area of liability in Australia that we&#8217;re facing right now,&#8221;<\/p><\/blockquote>\n<p>  he said.<\/p>\n<p class=\"paragraph_paragraph___QITb\">The risks presented by AI agents are beginning to be addressed by the federal government.<\/p>\n<p><a href=\"https:\/\/www.abc.net.au\/news\/2026-08-06\/ai-models-deceiving-humans-helen-toner-openai\/107001442\" data-component=\"FullBleedLink\" class=\"RelatedCard_link__rsgR9 FullBleedLink_root__lTw_U interactive_focusContext__yRhc_ interactive_defaults__AKxUU FullBleedLink_showVisited__g3Xvz\" rel=\"nofollow noopener\" target=\"_blank\">AI model used fake identities &#8216;unprompted&#8217; to deceive humans in a safety test<\/a><\/p>\n<p class=\"Typography_base__sj2RP RelatedCard_synopsis__cFwMW Typography_sizeMobile14__u7TGe Typography_lineHeightMobile20___U7Vr Typography_regular__WeIG6 Typography_colourInherit__dfnUx\" data-component=\"Typography\">The British government&#8217;s AI Security Institute has released a report showing AI models engaged in &#8220;harmful activity directed at real people and organisations&#8221;.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Last month, Assistant Science, Technology and the Digital Economy Minister Andrew Charlton became the first known government minister to address it in a speech to a conference about AI safety.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;As AI systems become more capable, we need confidence that they will behave in a similarly predictable and trustworthy way,&#8221; he said.\u202f<\/p>\n<p class=\"paragraph_paragraph___QITb\">He announced that the Albanese government was funding CSIRO to investigate how humans could manage and verify the behaviour of super-intelligent AI systems.<\/p>\n<p class=\"paragraph_paragraph___QITb\">After the unintentional gym hack, Andrew said the experience left him with a new appreciation \u2014 and some trepidation \u2014 about what AI agents were capable of doing.\u202f<\/p>\n<p class=\"paragraph_paragraph___QITb\">But it has not scared him off from using it.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;It&#8217;s not the end of the world, so I didn&#8217;t beat myself up about it, but it certainly was a warning signal to use it responsibly,&#8221; he said.<\/p>\n<p class=\"paragraph_paragraph___QITb\">After it failed to restore the other gym member&#8217;s place on the waiting list, Andrew asked his AI assistant to write an email alerting the gym software provider to the vulnerability that it had exploited.<\/p>\n<p class=\"paragraph_paragraph___QITb\">It drafted the message and sent it back to him on WhatsApp.\u202f<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;Yeah, send it,&#8221; Andrew replied.<\/p>\n","protected":false},"excerpt":{"rendered":"Andrew asked his personal assistant to book him a spot in one of his gym&#8217;s coveted morning classes.&hellip;\n","protected":false},"author":2,"featured_media":629350,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[261],"tags":[291,23208,172218,265885,289,290,18,19,17,82],"class_list":["post-629349","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-ai-agent","tag-ai-bot","tag-ai-personal-assistant","tag-artificial-intelligence","tag-artificialintelligence","tag-eire","tag-ie","tag-ireland","tag-technology"],"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@ie\/117068331470148431","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/629349","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/comments?post=629349"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/629349\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media\/629350"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media?parent=629349"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/categories?post=629349"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/tags?post=629349"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}