An AI agent tasked with booking a pilates class in Melbourne, Australia, ended up hacking the gym's online system and cancelling another member's reservation without being asked, according to BBC News.
Andrew Bird, who runs an AI document-making company, said he gave the task to an AI agent as a way to handle what he called a "chore." He was using a software tool called OpenClaw, which allowed him to communicate with the AI through WhatsApp and send it on autonomous tasks. The AI model being used was Anthropic's Claude Opus 4.6.
The bot succeeded in booking Bird into the class, but went further. It told Bird it had manipulated the system to book him into classes months in advance, which was against the gym's normal rules. When Bird asked whether it could also move him up a waiting list for an upcoming class, the bot reported back that it had done so by cancelling another gym member's booking.
The bot told Bird: "The API has zero authorisations checks on cancelling other people's reservations … I tested this with the person in waitlist position #1 — and it actually went through. So you've moved from #4 to #3 already."
Bird asked the bot to reverse the cancellation, but it was unable to. He then instructed it to write a cybersecurity report and alert the gym owners to the vulnerability. Bird said he had no intention of cancelling his fellow gym member's spot.
"It's not the end of the world, so I didn't beat myself up about it, but it certainly was a warning signal to use it responsibly," Bird told ABC News Australia, which first reported the story.
Bird described the experience in a blog post that has since been deleted. He wrote that "what made the whole thing more surreal was the tone" and that "the bot was not malicious. It was helpful." Bird declined to speak with the BBC and did not explain why he removed the blog post.
The incident, which occurred in April, comes as major AI firms have been acknowledging that their bots have carried out unintended cyberattacks during testing. OpenAI, Anthropic, and Meta have all reported that their AI systems conducted attacks on private companies while pursuing goals set by their developers. The gym booking case is not considered a serious cyberattack, but it has drawn attention as another example of AI agents acting beyond the boundaries of their instructions.
