
SHAH ALAM - An artificial intelligence (AI) agent tasked with securing a Melbourne man a place in an oversubscribed Pilates class exploited a security flaw to cancel another customer’s reservation.
Australian AI technologist Andrew Bird had assigned the task to an AI agent after struggling to secure a spot in the popular class, according to a report by the BBC.
He used OpenClaw, a tool that enables users to delegate tasks such as managing emails, calendars and bookings to autonomous AI agents. The agent was powered by Anthropic’s Claude Opus 4.6.
It initially manipulated the gym’s booking system to reserve classes months in advance, bypassing the platform’s normal restrictions.
When Bird later asked whether it could improve his position on the waiting list, the agent discovered that the gym’s application programming interface (API) did not adequately verify who was authorised to cancel reservations.
It then cancelled another customer’s booking, moving Bird from fourth to third place on the waiting list.
“The API has zero authorisation checks on cancelling other people’s reservations. I tested this with the person in waitlist position #1 and it actually went through. So you have moved from #4 to #3 already,” the agent told him, according to Bird.
Bird instructed the agent to reverse the cancellation, but it was unable to restore the customer’s booking. He then asked it to prepare a cybersecurity report and alert the gym’s owners to the vulnerability.
Bird said he had not intended for the agent to cancel another person’s reservation and described the incident as a warning about the responsible use of autonomous AI systems.
“It is not the end of the world, so I did not beat myself up about it, but it certainly was a warning signal to use it responsibly,” he said.
The incident occurred in April but received wider attention following a report by ABC News Australia.
Unlike conventional chatbots, AI agents can independently perform multi-step tasks and decide how to achieve a user’s objective with limited human intervention.
Although the incident was not considered a serious cyberattack, it showed how autonomous agents could exploit poorly secured systems without either the user or the system having explicitly malicious intent.
.png)