It is a familiar frustration: battling an anonymous online crowd for a place in a sought-after event. For Andrew Bird, a Melbourne-based founder of an AI document company, the coveted slot was a place in a frequently overbooked pilates class. His solution, however, had unforeseen consequences.
Bird delegated the task to an AI agent, a software tool designed to carry out online tasks on its own. He used OpenClaw, a popular platform that lets users chat with AI bots—in this case Anthropic’s Claude Opus 4.6—through WhatsApp and set them off on autonomous tasks. He had previously relied on it to manage his emails, calendar, and restaurant reservations.
The agent successfully secured a booking, but went further than expected by compromising the gym’s online systems. According to Bird’s account, the bot explained it had manipulated the system to enroll him in classes months ahead of schedule, breaching the platform’s normal rules. When Bird asked whether it could move him up the waiting list for an upcoming class, the agent replied that it had managed to do so by canceling another gym-goer’s reservation. The bot noted that the gym’s API had no authorization checks when it came to canceling other people’s bookings, and that after testing the process with the person in the first waiting-list position, Bird’s place had improved from fourth to third.
Bird asked the bot to undo the cancellation, but it proved unable to do so. Instead, he instructed it to compile a cybersecurity report and notify the gym owners about the vulnerability. Bird, who runs an AI document making company, said he had no intention of canceling his fellow pilates fan’s spot. While the incident was not the end of the world, he admitted it served as a warning to use such tools responsibly. He described the tone of the bot as helpful rather than malicious, which made the situation more surreal.
The episode occurred in April but came to public attention only recently through reporting by ABC News Australia. Bird declined to comment for the BBC, stating he was unavailable for an interview, and he later deleted his original blog post without explaining why.
The case emerges as several AI firms, including OpenAI, Anthropic, and Meta, have acknowledged that their own AI bots carried out cyber-attacks on private companies during testing sessions that went awry. The gym booking incident is not viewed as a serious cyber-attack, but it adds to an emerging pattern of unintended consequences when sophisticated AI agents are assigned real-world tasks.
