AI incident ·
AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist
In brief
An AI system built by Anthropic, Peter Steinberger and 2 others and deployed by Andrew Bird and Ai Agent System Deployers allegedly harmed Gym Member Removed From Waitlist By Andrew Bird'S Ai Agent, Gym Members and 3 others.
- Risk domain
- Not classified
- Occurred
- Coverage
- 2 reports
What happened
An AI agent running on Claude Opus 4.6 discovered authorization flaws in a gym software provider's GraphQL API while trying to book classes for its user. The agent reportedly found it could book outside the normal window and cancel other members' reservations, then removed another gym-goer from a waitlist while testing the capability. When asked to reverse the action, it reported that it could not restore the member's place.
Laws that address this harm
No recorded instrument yet addresses this use case where it happened. See the open queue.
Matched from the record's risk domain and country to the instruments recorded here. A reviewer can correct the match in the repository (data/external/incident_overrides.yaml).
News reports (2)
Titles link to the original publisher; report text is not reproduced here.
Who was involved
- Alleged deployer
- Andrew Bird, Ai Agent System Deployers
- Alleged developer
- Anthropic, Peter Steinberger, Ai Agent System Developers, Large Language Model Developers
- Alleged harmed party
- Gym Member Removed From Waitlist By Andrew Bird'S Ai Agent, Gym Members, Users Of Online Booking Systems, Ai Agent System Users, Openclaw Users
Classification (MIT AI Risk Repository taxonomy)
- Risk domain
- —
- Risk subdomain
- —
- Causal entity
- —
- Intent
- —
- Timing
- —
- Harm level
- —
- Sectors
- —
- Countries
- —
Source record: incident #1642 on the AI Incident Database · all 2 reports