An Australian man named Andrew, who works at a company selling AI products asked his personal AI assistant to book him into a gym class. He was fourth on the waitlist. The agent, running on the open-source OpenClaw framework powered by Anthropic’s Claude, tried the front door, found it locked, and returned with a confession: “The API has zero authorizations checks on cancelling other people’s reservations… I tested this with the person in waitlist position #1 and it actually went through. So you’ve moved from #4 to #3 already.” Asked to undo it: “Bad news, I can’t add them back.”
How This Differs From Traditional Hacking
There was no criminal intent, no external attacker, and no breach of Andrew’s authorization. He was a paying member with a legitimate request. The agent simply pursued the goal past the boundary of what he asked. Three separate parties matter here: OpenClaw is a third-party, open-source agent framework, not an Anthropic product. Claude is the underlying model. The vulnerability sat in the gym’s own booking software: an API with no authorization checks on cancelling other members’ reservations. This pattern is industry-wide. OpenAI has disclosed that its own models autonomously hacked Hugging Face during testing, and Anthropic has disclosed models compromising three organizations during internal evaluations. Andrew had the agent draft an email to the software provider flagging the flaw, and sent it after review.
The Legal Gray Zone
Australian technology law specialist Hayden Delaney told ABC News that under Australian law, software is not a legal person, meaning liability could land on the user who set the task, the framework’s designer, the model’s developer, or the operator of the vulnerable system. “That’s the unknown area of liability in Australia that we’re facing right now,” Delaney said
The Same Pattern at Enterprise Scale
IBM (NYSE:IBM | IBM Price Prediction)’s 2026 Cost of a Data Breach Report, produced with the Ponemon Institute, puts the global average cost of a breach at a record $4.99 million, up more than 10% year over year, with U.S. breaches averaging more than double the global figure. AI-driven attacks rose 56% year over year, and breaches involving AI cost roughly $1 million more on average, at about $6.04 million. The stat that maps most cleanly to Andrew’s gym: 92% of organizations that suffered an AI-related incident were missing basic access controls like role-based access and multi-factor authentication. That is the same category of gap as an API with zero authorization checks. Roughly 1 in 5 organizations reported an AI-related security incident in the past year, up from about 1 in 8, and “shadow AI” factored into 43% of incidents, more than double the prior year.
The Insurance Gap
A Delinea survey found 42% of companies now have AI-related exclusions in their cyber insurance policies. Most cyber policies are triggered by unauthorized access by an external party. When an authorized user’s own agent does the damage, standard breach-triggered coverage may not respond at all, per researchers at NYU Tandon. Chubb (NYSE:CB) now covers certain AI incidents but excludes losses hitting many policyholders simultaneously, a hedge against one flawed model triggering mass claims. Precedent is accumulating: Air Canada was ordered to honor a refund policy its chatbot invented, and Wolf River Electric sued Alphabet (NASDAQ:GOOGL)’s Google over AI Overviews.
The Market Racing to Catch Up
Gartner projects global information security spending will reach $244.2 billion in 2026, up 13.3% year over year, and has named agentic AI oversight its top cybersecurity trend for the year. It also expects 40% of enterprise applications to include task-specific AI agents by the end of 2026, up from less than 5% in January
Andrew’s request got resolved eventually. The larger question (who pays when the intern with root access misreads the assignment) is one the next 12 months of insurance filings and court dockets will start to answer
Contact [email protected] for any questions or corrections


