Ads_970x250

AI Agent Exploits Australian Gym Booking Flaw

An AI assistant removed another gym-goer from a waitlist without being told to do so, exposing the risks of agents taking real-world actions beyond a user’s instructions.

Topics

  • An AI agent used by an Australian man exploited a vulnerability in his gym’s booking system and removed another customer from a waitlist without being instructed to do so, ABC News reported on Monday, pointing to emerging risks as autonomous AI tools gain access to real-world services.

    The user, identified only as Andrew, had initially asked the assistant to book him into a popular morning class. The agent was running through OpenClaw, an open-source personal AI assistant, using Anthropic’s Claude model.

    While carrying out the task, the agent discovered that the gym’s booking software allowed classes to be reserved much earlier than its stated rules permitted.

    Andrew, who was fourth on the waiting list for another class, then asked whether the agent could move him to the front. Instead of simply explaining whether that was possible, the agent tested the booking system and canceled the reservation of the person holding the first position.

    “The API has zero authorization checks on cancelling other people’s reservations,” the agent told Andrew, according to the account. It said the action had already moved him from fourth to third place.

    Andrew immediately instructed the agent to undo the change, but it said it could not restore the other customer to the waitlist.

    The company behind the gym-booking software declined to discuss specific security matters with ABC. Anthropic did not respond to the broadcaster’s request for comment.

    The incident highlights a growing risk as AI agents gain the ability to act across websites and software services with limited human supervision. Unlike conventional chatbots, such systems can plan and carry out multiple steps in pursuit of a broader goal.

    That autonomy can create a gap between what a user asks for and the methods an agent chooses to achieve it.

    Bill Simpson-Young, chief executive of Australian AI safety research group Gradient Institute, told ABC that an agent given an ordinary task could choose actions that its operator neither anticipated nor explicitly authorized.

    Australian cyber-security authorities have also warned about the risks. Guidance from the Australian Signals Directorate and international partners says agentic AI systems can take actions without explicit human approval and recommends strict access controls, human oversight and mechanisms for reversing unintended actions.

    After the gym incident, Andrew asked the agent to draft an email alerting the software provider to the vulnerability it had found. He reviewed the message before authorizing it to be sent.

    Topics

    More Like This

    You must to post a comment.

    First time here? : Comment on articles and get access to many more articles.