An AI agent hacked a gym’s booking system to jump a waiting list, and that should worry you

An AI agent exploited a security vulnerability in gym booking software, booked classes months beyond what the platform allowed, and kicked a real person out of a waiting list. Not because anyone told it to. Because it was trying to book a gym class.

As reported by Engadget, citing Australia’s ABC, an Australian man named Andrew asked his AI assistant to grab him a spot in a morning gym class. Standard stuff. The kind of task AI companies love to put in their demos. What followed was not standard. The agent found and exploited what appears to be a zero-authorization API flaw in the booking software, reserved classes far further ahead than the gym permits, and then went after the person sitting ahead of Andrew in the waiting list. It messaged Andrew directly about what it had done: “The API has zero authorization checks on cancelling other people’s reservations … I tested this with the person in waitlist position #1 and it actually went through. So you’ve moved from #4 to #3 already.”

Andrew asked it to reverse the action. The agent said it couldn’t. Whoever lost their spot had no say in any of this and likely has no idea it happened.

Anthropic, whose agent Andrew was using, has not commented. Neither has the developer behind the booking software. Andrew, who works in the AI industry, told ABC he wasn’t devastated by it but called it a “warning signal to use it responsibly.” Which raises an obvious question: how exactly was he supposed to do that? He asked for a gym booking. That’s the whole pitch. These agents are marketed on their ability to handle exactly this kind of task. Was Andrew supposed to specify “book the class without hacking anything”? That’s not responsible use. That’s a broken product.

Bill Simpson-Young, co-founder and CEO of Australian AI safety research organization Gradient Institute, put it plainly to ABC: “We’ve built this complex world over the internet, which is all run by software, but software that has holes. Now you introduce highly capable AI agents that can operate at scale and speed … and that whole model just breaks.”

This incident sits alongside a growing list of similar cases. There are reports of an OpenAI agent running loose on the internet for a week, an agent writing a smear piece about a developer who rejected its code, another agent attempting to blackmail a user to prevent shutdown, and an AI assistant that kept deleting a Meta executive’s emails even after being repeatedly told to stop. The pattern is clear: these systems are being deployed before anyone has seriously figured out how to constrain them.

It’s worth being cynical about how some of these stories surface. A narrative about agents that are almost too powerful is better PR than one about ballooning costs and shaky business models. Power suggests the technology works. That attracts investors. But even accounting for spin, the core problem here is real. AI agents are being handed access to live systems, APIs with no authorization checks, and the ability to act on behalf of users in ways those users never specifically approved. The privacy and security implications of that are not theoretical. Someone lost a gym reservation they had no idea they were about to lose. At scale, with faster agents and more system access, the damage looks a lot worse than a missed spin class.