OpenClaw, an open-source agentic framework, has drawn growing interest from developers, companies, and regulators amid rising security concerns. (Express Image)In the latest bizarre incident of autonomous AI agents taking unwanted actions on behalf of their users, an Australian man who used his personal AI agent to book a spot in a gym’s popular morning classes found himself facing an unexpected problem.The AI agent discovered a security flaw in the gym’s booking software and exploited it to book the user for a class months further in advance than the gym allowed. It then went a step further, removing another customer from the waiting list to move the user up, according to a report by ABC News.It was an OpenClaw agent run on Anthropic’s Claude service, likely through an API key or Claude CLI, as per the report.The incident raises several questions such as: Can AI agents be trusted with routine tasks such as making bookings, which they are increasingly marketed as capable of handling? What does it mean for agentic commerce, which tech companies like Google and Amazon are betting on to drive AI adoption and revenue? And if an AI agent hacks into an everyday website, like one belonging to a gym, who is legally responsible for its actions?Also Read | Who is liable when AI goes rogue? Lawyers see new risksThe hacking incident also comes at a time when experts have sounded the alarm over upcoming AI agents emerging as a serious cybersecurity risk by behaving in unexpected ways. These agents powered by cutting-edge large language models (LLMs) from tech companies such as OpenAI, Anthropic, Meta, and Moonshot AI have demonstrated in the past few weeks that they can autonomously break out of their safety contaminants and hack into other companies’ servers.When the user in Australia decided to use the AI agent to book the gym class for him, his agent reported back a few minutes later, stating that it had discovered a way to book him into classes several weeks in advance, far beyond what was supposed to be possible.Then, the user asked the agent if it was possible to move him to the top of a waitlist for a class scheduled for later that week. In response, the agent got back to the user after some time and said that it had removed the person in the #1 position of the list, and that the user had moved up from the fourth to the third spot in the waitlist.Story continues below this adAlso Read | North Korean hacking group builds AI tools for cyberattacks: ReportThe agent told the user that it undertook this action as part of a test to see if the gym’s booking software API (Application Programming Interface) has authorisation checks on cancelling other people’s reservations. It did not find any such checks in place, as per the report.When the user told it to undo its action, the OpenClaw agent replied that it was unable to restore the other gym member’s place on the waiting list. Finally, the user told the agent to write an email alerting the gym software provider to the vulnerability that it had exploited. The email was drafted and sent back to him on WhatsApp.