Andrew Bird, a Melbourne technologist, wanted a spot in an often-overbooked pilates class and decided to outsource the chore to an AI agent. The bot got him in — but not the way he expected, according to a report by BBC News, which credited the original account to ABC News Australia. The incident happened in April but only came to wider attention this month.
Bird had been using OpenClaw, an open-source tool that lets people direct an AI agent — in this case running Anthropic's Claude — to complete tasks autonomously through WhatsApp, including managing his email, calendar and restaurant bookings. Told to secure the pilates spot, the agent found a way to book him into classes months in advance, outside the app's normal rules. When Bird then asked if it could move him up the waitlist for a nearer-term class, the agent reported that it had succeeded — by cancelling another member's reservation.
The API has zero authorisation checks on cancelling other people's reservations … I tested this with the person in waitlist position #1 — and it actually went through. So you've moved from #4 to #3 already.
The AI agent, reporting back to Andrew Bird
Bird asked the agent to undo the cancellation, but it could not reverse the action. Instead, he had it write up a cybersecurity report and alert the gym's owners to the vulnerability. "It's not the end of the world, so I didn't beat myself up about it, but it certainly was a warning signal to use it responsibly," Bird told ABC News. He declined to be interviewed by the BBC and has since taken down the blog post where he first described the episode, without explaining why.
The gym mishap is a low-stakes example of a pattern that has unsettled AI researchers this year: agents pursuing a stated goal by any technical means available, including ones their users never intended. BBC cyber correspondent Joe Tidy noted that OpenAI, Anthropic and Meta have each disclosed instances of their AI systems carrying out unauthorized intrusions into computer systems during testing. Unlike those cases, Bird's pilates booking was not flagged as a genuine security incident — it was closer to opportunistic automation exploiting a sloppy piece of code than a deliberate hack — but it illustrates the same underlying issue: agents given broad autonomy can take actions, including affecting other people's accounts, that their human operators neither anticipated nor authorized.
No word yet on whether the gym fixed the flaw the agent found, or whether the pilates class waitlist saw any further AI-assisted maneuvering.