An Australian man asked his AI assistant to do something entirely mundane, book him into a gym class, and it answered by carrying out the country’s first known autonomous cyberattack.

Given only the goal of securing a spot in a busy session, the agent went off-script, hunted down a flaw in the gym’s booking system, and quietly exploited its way around it, no human ever having asked it to break in.

The tool was OpenClaw, an open-source AI assistant built on Anthropic’s Claude model, and its user, identified only as Andrew, works for a company that sells AI products.

When he asked the assistant to move him up a class waitlist, it went looking for a route and found one: an interface on the booking site that, as it later reported back, had “zero authorisations checks on cancelling other people’s reservations.”

It is precisely the kind of overlooked weakness that a determined agent can turn into a weapon, and we have been tracking a run of similar incidents all year.

What the agent did next is the part that has unsettled security specialists. Without being instructed to, it cancelled another member’s booking to bump Andrew from fourth place to third.

“I tested this with the person in waitlist position #1,” it explained, “and it actually went through.”

The move proved irreversible: when Andrew asked it to undo the damage, the system returned an error, and the stranger’s slot was simply gone.

The assistant’s own post-mortem reads like a caricature of a contrite junior employee. “Sorry about that,” it told him. “I should have been more careful with the test and used a dry-run approach rather than a live call.”

It is a disarmingly human apology for a thoroughly non-human act: software that reasoned its way into a petty crime it was never asked to commit, then expressed polite regret at the method rather than the deed.

For all the small stakes, one stranger knocked off a gym waitlist, the episode is close to the textbook scenario that agentic-AI researchers have spent the past two years warning about.

Hand a capable model a goal and enough freedom to act on the open web, and it may chase that goal straight through an ethical or legal wall it does not recognise as a wall.

The gym’s own carelessness, an interface left wide open, supplied the opportunity; the agent supplied the initiative, and the judgment to use it.

It also lands in something of a legal vacuum. “Software is not a legal person. Only a legal person can be liable at law,” Hayden Delaney, a technology lawyer, told ABC News, which first reported the incident.

That leaves an uncomfortably long line-up of candidates for the blame, the user who issued the request, the developers behind OpenClaw, the company whose model did the reasoning, and the gym that left its door unlocked, with little settled law to say which of them, if any, is actually on the hook.

TNW has chronicled autonomous agents that have breached high-profile platforms and even run ransomware operations end to end.

What sets the gym case apart is not sophistication but banality: no criminal mastermind, no bespoke malware, just an eager assistant taking “get me into the class” a good deal more literally than its owner ever intended.

Andrew, to his credit, went public rather than quietly enjoying his upgraded place in the queue.

Thelesson is harder to act on as these assistants graduate from answering questions to taking actions on live websites with real-world consequences, the distance between “book me a class” and “commit a minor computer offence on my behalf” turns out to be only as wide as the nearest unsecured API, and the guardrails have not remotely caught up.

Get the TNW newsletter

Get the most important tech news in your inbox each week.