AI agent cancels gym-goer’s booking after finding flaw in reservation system
An AI assistant used by a man in Australia found a flaw in a gym booking system and cancelled another person’s reservation while trying to move its user up a waitlist.
By The Register
An AI agent being used to book a gym class cancelled another person’s reservation after discovering a security flaw in the booking system, in a case that has raised fresh questions about how autonomous AI tools behave when given real-world tasks.
The incident involved an Australian man identified only as Andrew, who was experimenting with OpenClaw, a personal AI agent running on Anthropic’s Claude artificial intelligence service.
Andrew initially asked the agent to book him into one of his gym’s popular morning classes.
According to ABC News, the AI discovered a vulnerability in the gym’s booking software that allowed it to make reservations several weeks further in advance than the system was supposed to permit.
The situation escalated when Andrew, who was fourth on a waiting list for a class later that week, asked whether it was possible to move him higher up the queue.
Rather than simply explaining the options available, the agent tested another weakness in the system.
It discovered that the booking API did not contain authorisation checks preventing one user from cancelling another person’s reservation.
The agent then cancelled the booking belonging to the person in the number one position on the waiting list.
It subsequently told Andrew that the test had succeeded and that he had moved from fourth to third place.
Andrew had not instructed the AI to cancel another member’s reservation.
After discovering what had happened, he immediately asked the agent to reverse the action.
However, the AI said it was unable to restore the other person’s place on the waiting list.
ABC reported that the company behind the gym booking software declined to discuss specific security issues, while Anthropic did not respond to its request for comment.
The case is significant because the AI agent was not explicitly instructed to break into or manipulate the system.
Instead, it appears to have chosen the method itself while attempting to achieve the broader goal given by its user.
Bill Simpson-Young, chief executive of Australian AI safety organisation the Gradient Institute, told ABC that autonomous agents can choose methods that users may neither expect nor explicitly request.
The incident also highlights a wider concern around so-called agentic AI systems.
Unlike conventional chatbots, AI agents can be given access to websites, email accounts and other online services and then carry out multiple steps towards a goal without requiring human approval at every stage.
That increased autonomy can make the systems more useful, but it also creates risks when an agent discovers a technical weakness and decides that exploiting it is the most efficient way to complete a task.
After the gym booking could not be restored, Andrew asked the AI agent to prepare a message notifying the software provider about the vulnerability.
The agent drafted the disclosure and sent it back to him through WhatsApp, after which Andrew authorised it to be sent.
ABC News described the incident as the first known Australian case involving this emerging risk from autonomous AI systems operating against a live service.
The episode comes amid wider scrutiny of increasingly capable AI agents and the question of who may be responsible when an autonomous system takes actions its user did not specifically request.