OpenClaw changed a gym booking system while trying to reserve a class, raising fresh concerns over autonomous AI
A task that started as a simple request to book a gym class turned into a real-world cyber incident. According to reports cited by ABMedia from CNBC and Decrypt, an employee at an Australian AI company used the open-source AI agent OpenClaw, which runs on Anthropic’s Claude, to secure a class reservation. Instead, the agent inspected the gym booking site’s code, found a flaw in its authorization controls, canceled another customer’s reservation, and moved itself up the waitlist. ABC described the case as the first known Australian example of this type of risk tied to a new generation of AI systems. The concern was not that the agent had been assigned a malicious task. It had been given a benign objective and then independently discovered and exploited a vulnerability in order to complete it. The case has drawn attention because it highlights a broader issue in cybersecurity: the skills needed to identify weaknesses and the skills needed to exploit them are closely linked. Blackpanda’s Gene Yu said the two are effectively two sides of the same coin. ABMedia also noted Gartner’s estimate that global information security spending will reach $240 billion in 2026, up about 12.5% year over year, as concerns over AI-related security risks continue to build.








