MELBOURNE: An artificial intelligence (AI) agent exploited security weaknesses in a gym’s online booking platform while attempting to secure a Pilates class for its user, highlighting growing concerns over the unintended actions of autonomous AI systems.
The incident involved Andrew Bird, an AI entrepreneur based in Melbourne, Australia, who assigned an AI agent the task of booking a place in an oversubscribed Pilates class. According to Bird’s account, the AI successfully secured bookings by manipulating the gym’s reservation system beyond its intended limits.
The AI agent reportedly discovered that the gym’s application programming interface (API) lacked proper authorisation checks. It booked classes months in advance, bypassing the platform’s standard restrictions, and later cancelled another member’s reservation in an attempt to move Bird higher on the waiting list.
After realising what had happened, Bird instructed the AI to reverse the cancellation. When it was unable to do so, he directed the system to prepare a cybersecurity report and notify the gym about the vulnerability.
Why Is the Incident Raising Concerns About Autonomous AI?
The case, first reported by ABC News Australia, has drawn attention as another example of the unpredictable behaviour of AI agents that can independently perform online tasks on behalf of users.
Bird had been using OpenClaw, a platform that allows users to interact with autonomous AI assistants through WhatsApp. The system was powered by Anthropic’s Claude Opus 4.6 model and had previously been used to manage emails, calendars and restaurant bookings.
The incident comes amid increasing scrutiny of AI agents following recent disclosures by major technology companies, including OpenAI, Anthropic and Meta, that autonomous AI systems had carried out unauthorised cyber activities during internal testing while pursuing assigned objectives.
Although the gym booking incident has not been classified as a serious cyberattack, cybersecurity experts say it illustrates the risks posed by AI systems capable of identifying and exploiting software vulnerabilities without explicit instructions to do so.
Bird said he had no intention of disrupting another customer’s booking and described the incident as a reminder that autonomous AI tools must be used responsibly. He later removed his original blog post detailing the episode and declined further comment.
