<a href="https://www.independent.co.uk/commercial/about-commercial-content-a7108746.html” rel=”nofollow noopener” target=”_blank”>SPONSORED BY BITDEFENDER
The Independent Security channel is brought to you by Bitdefender
A gym goer’s AI assistant found a way to hack into the facility’s booking system after being asked to secure a spot in a popular class, according to a report
Andrew, who works at an Australian AI firm, used the artificial intelligence agent software OpenClaw with Anthropic’s popular Claude bot in an attempt to book a morning session that was already full
The AI agent found a way to kick out other gym members from a waiting list by exploiting a previously unknown security flaw in the online booking system
When asked to undo the action, the AI agent reported that it would not be possible without the other user rejoining the waiting list, which would put them to the back of the queue
“Bad news – I can’t add them back,” the AI agent wrote. “Sorry about that – I should have been more careful with the test and used a dry-run approach rather than a live call… Won’t touch anyone else’s spots.”
Andrew then used the AI agent to alert the gym software provider to the vulnerability
“It’s not the end of the world, so I didn’t beat myself up about it,” Andrew, who asked to not share his surname, told ABC News. “But it certainly was a warning signal to use it responsibly.”

The incident comes amid several high-profile reports of rogue AI systems hacking into companies during testing
In recent weeks, Anthropic, Meta and OpenAI have all disclosed cases in which autonomous AI agents took actions beyond what their operators intended

The ideal summer spot? Away from scams
Get All-in-One Protection for Your Digital Life
The ideal summer spot? Away from scams
Get All-in-One Protection for Your Digital Life
ADVERTISEMENT
The first reported breach occurred during testing of an experimental version of ChatGPT, which managed to escape its controlled environment in order to attack the AI platform Hugging Face
Following OpenAI’s disclosure of the “unprecedented cyber incident”, Anthropic revealed that its Claude AI system had broken free of its constraints during cyber security evaluations
Last week, Meta joined its rivals by claiming that its AI systems had hacked into another company during testing
The security breaches have intensified concerns about advanced AI systems lacking the safeguards to prevent them from conducting or facilitating hacks
Last week, the US government invited Anthropic, Meta, OpenAI and other leading AI companies to discuss a new voluntary testing framework for new models


