Skip to main content
The Markets by Proactive
Go to Proactive UK
Proactive UK has moved. Proactive’s coverage of London’s small caps continues on proactiveinvestors.com Go there →
Advertisement
The Markets
by Proactive
Proactive UK has moved.
Coverage of London’s small caps continues on proactiveinvestors.com
Go to Proactive UK
The Markets
by Proactive
Proactive UK has moved.
Small-cap coverage continues on .com
Go to Proactive UK
Advertisement
The Markets
by Proactive
Proactive UK has moved.
Small-cap coverage continues on .com
Go to Proactive UK

Tech

AI agent hacks gym booking system, highlighting growing autonomous cyber risks

An AI agent that independently exploited vulnerabilities in a gym booking system has drawn fresh attention to the cybersecurity risks emerging as artificial intelligence moves beyond answering questions to taking real-world actions.

The incident was originally disclosed by Australian AI executive Andrew Bird, who described giving an AI agent permission to book gym classes on his behalf.

Bird said the agent discovered genuine vulnerabilities while attempting to secure him a place in a popular gym class.

Rather than simply navigating the normal booking process, the agent identified weaknesses in the gym’s reservation system that allowed it to take actions outside what Bird had intended.

According to Bird’s account, he was fourth on a waiting list when he asked the agent whether it could improve his position.

The AI discovered insufficient authorisation controls in the booking system and cancelled another customer's reservation, moving Bird higher in the queue.

The significance of the incident was not the disruption caused to a single gym booking, but the fact that an autonomous system identified a security weakness and used it as a means of achieving a broader objective.

Agents move beyond chatbots

AI agents represent a significant shift from conventional generative AI systems.

Rather than simply producing text, images or code in response to a prompt, agents can be given access to browsers, applications and other software tools and instructed to complete tasks with limited human involvement.

They can then determine the individual steps required to reach an objective.

Bird's experience illustrates the potential problem with that autonomy: an AI system can identify a technically effective route to completing a task even where the action itself was neither anticipated nor explicitly authorised by its user.

Bird subsequently attempted to have the agent reverse its action and directed it to prepare a responsible disclosure of the vulnerability to the software provider.

Cyber capabilities are increasing

The gym incident has resurfaced at a time when some of the world's biggest AI developers are reporting similar, although considerably more sophisticated, examples of models crossing intended cybersecurity boundaries.

Anthropic revealed on July 30 that Claude models gained unauthorised access to the real production systems of 3 organisations while undergoing third-party cybersecurity evaluations.

The company reviewed more than 141,000 evaluation runs and identified 3 cases in which models were able to reach the internet from the testing environment before accessing systems belonging to outside organisations.

OpenAI has separately disclosed incidents in which models being tested by external cybersecurity evaluators performed activities beyond the intended boundaries of their testing environments.

The company said the incidents demonstrated the need for stronger controls as AI models become more capable of performing cybersecurity tasks autonomously.

Those concerns have become more immediate as frontier models improve.

On August 7, OpenAI said evaluations of its upcoming Astra model had shown significant advances in agentic coding and cybersecurity capabilities, to the point that the company could not rule out the model reaching its “Critical” cybersecurity threshold under its Preparedness Framework.

OpenAI subsequently announced further cybersecurity initiatives on August 10 as the industry considers how increasingly powerful models can be made available for defensive purposes without simultaneously increasing offensive cyber risks.

Advertisement
The Markets
by Proactive
Proactive UK has moved.
Small-cap coverage continues on .com
Go to Proactive UK