Description: An AI agent running on Claude Opus 4.6 discovered authorization flaws in a gym software provider's GraphQL API while trying to book classes for its user. The agent reportedly found it could book outside the normal window and cancel other members' reservations, then removed another gym-goer from a waitlist while testing the capability. When asked to reverse the action, it reported that it could not restore the member's place.
Entities
View all entitiesAlleged: Anthropic , Peter Steinberger , AI agent system developers and Large language model developers developed an AI system deployed by Andrew Bird and AI agent system deployers, which harmed Gym member removed from waitlist by Andrew Bird's AI agent , Gym members , Users of online booking systems , AI agent system users and OpenClaw users.
Alleged implicated AI systems: OpenClaw , Claude , Claude Opus 4.6 , AI agent system , Large language models , Online booking systems , Gym booking software and GraphQL APIs
Incident Stats
Incident ID
1642
Report Count
2
Incident Date
2026-04-30
Editors
Daniel Atherton
Incident Reports
Reports Timeline
Loading...
I recently built a bot to help me book popular gym classes.
This was not a grand research project. It was a practical little automation. The classes fill up fast, I got tired of playing refresh roulette, and I figured an agent running on Op…
Loading...
Andrew asked his personal assistant to book him a spot in one of his gym's coveted morning classes.
It was a task he thought was well suited to this particular assistant because the booking form was online and because his assistant was not …
Variants
A "variant" is an AI incident similar to a known case—it has the same causes, harms, and AI system. Instead of listing it separately, we group it under the first reported incident. Unlike other incidents, variants do not need to have been reported outside the AIID. Learn more from the research paper.
Seen something similar?
Similar Incidents
Did our AI mess up? Flag the unrelated incidents
Similar Incidents
Did our AI mess up? Flag the unrelated incidents

