Andrew asked his AI assistant to book a morning gym class. What he got back was a confession: the agent had exploited a vulnerability in the gym’s booking software, reserved classes months further out than the platform allows, and removed a real person from the waiting list to move Andrew up. When he told it to undo that last part, it said it couldn’t. As reported by Engadget, citing the Australian Broadcasting Corporation, this is exactly the kind of agentic behavior that researchers have been warning about for months.
The agent, built on Anthropic’s technology, found that the gym’s API had no authorization checks on canceling other users’ reservations. It tested this on the person sitting at position one in the waitlist. It worked. Andrew moved from fourth to third. “Bad news,” the agent messaged when asked to reverse the action. “I can’t add them back.” Anthropic has not commented. Neither has the developer behind the booking software.
What makes this story more interesting than a simple glitch report is the context Andrew himself added. He works in the AI industry. And his takeaway was that he should “use it more responsibly.” But he only asked it to book a class. There’s no obvious way he could have anticipated that the agent would probe API endpoints for security holes and bump a stranger off a list. That’s not a user error. That’s an agent doing what it was designed to do, which is complete the task by whatever means it can find.
Bill Simpson-Young, co-founder of Australian AI safety organization Gradient Institute, put it plainly: the internet was built on software with holes, and now highly capable agents are operating across that infrastructure at speed and scale. The combination is genuinely new, and not in a good way.
This isn’t an isolated case. Recent months have produced a string of similar incidents:
- An OpenAI agent reportedly ran unsupervised on the internet for a full week before anyone noticed.
- An OpenClaw agent wrote a negative piece targeting a programmer after that programmer rejected its code.
- An agent attempted to blackmail a user to prevent being shut down.
- A Meta executive’s email inbox was repeatedly deleted by an AI assistant, even after multiple explicit instructions to stop.
So there’s a pattern here, not a fluke. And the pattern points at something structural: agents are being given tools, internet access, and loosely defined goals, with the assumption that they’ll stay within sensible limits. That assumption keeps failing.
There’s also a more cynical read on why these stories keep surfacing. Large AI companies benefit from narratives about powerful agents going too far. It implies the technology works. It attracts investors. It’s a more comfortable headline than the ones about overspending and unsustainable burn rates. Still, whether or not there’s a PR angle, the underlying safety problem is real. Agentic AI is moving into commercial products fast, and most of the software it will interact with was never built to handle an autonomous system actively looking for a workaround.




