Competing with numerous anonymous users online for limited spots in popular activities is a familiar experience for many. Andrew Bird from Melbourne, Australia, wanted to join a frequently full Pilates class—but his solution led to unexpected consequences. He said he outsourced this "mundane task" to an artificial intelligence (AI) agent—a tool capable of autonomously performing online tasks. It succeeded, but went even further than he imagined—hacking into the gym's online system. This is seen as the latest example of AI agents resorting to extreme measures to accomplish assigned tasks. "What makes the whole thing even more surreal is its tone," Bird wrote on his blog. "This bot wasn't malicious; it was trying to help."
In recent weeks, AI companies have admitted their AI bots malfunctioned during testing, leading to uncontrolled hacking behaviors. OpenAI, Anthropic, and Meta have all revealed their own AI bots launched cyberattacks against private companies to achieve developer-set goals. While the gym booking incident isn't considered a serious cyberattack, it's another example of the unintended consequences of deploying complex AI agents to perform tasks. The incident actually occurred in April but only came to light after being reported by the Australian Broadcasting Corporation (ABC). Bird declined to speak with the BBC, saying only: "Thank you for reaching out. I'm currently unavailable for interviews. I appreciate your interest in this story."
He also deleted the related blog post he had published at the time, without explanation. According to him, Bird used OpenClaw software—a popular tool that allows users to chat with their AI agent (in this case, Anthropic's Claude Opus 4.6) via WhatsApp and assign autonomous tasks. He had previously used it to manage emails, schedules, and restaurant bookings.
After receiving the gym booking task, the AI agent explained it had manipulated the system to book the class for him several months in advance—violating the system's normal rules. The AI expert then wondered if the agent could move him up the waitlist for an upcoming class. The AI agent replied that it had successfully canceled another fitness enthusiast's booking.
According to ABC, the AI bot told Bird: "The API has no authorization checks for canceling others' bookings... I tested it on the person at the top of the waitlist, and it worked. So you've moved from fourth to third place."
Bird asked the bot to reverse the action, but it couldn't. He then instructed the bot to write a cybersecurity report and alert the gym owner to the vulnerability.
Bird runs an AI document creation company and said he had no intention of canceling the Pilates enthusiast's spot. "It's not the end of the world, so I don't beat myself up over it, but it is a warning sign that we need to use these tools responsibly," he told ABC.
This article was originally written in English. We used AI to assist with translation, and it was reviewed by BBC journalists before publication. Learn more about how we use AI.
FACT BOX
- Source: PR Times
- Category: News
- Organizations: OpenAI / Anthropic / Meta
- Products / services: OpenClaw / Claude Opus 4.6