A man in Australia was trying to take a shortcut, but accidentally created the country's first cyberattack initiated autonomously by an AI agent. Andrew, who works at a company selling commercial AI products, used the open-source agent software OpenClaw with the Anthropic Claude model to book popular morning classes at a gym. A few minutes later, the AI reported back: it not only managed to book classes that were not yet available for weeks, but also, when Andrew asked if the waitlist priority could be improved, it automatically removed the member ranked first from the list.
The AI honestly reported its "test" process in a message: "This API has no permission checks when canceling bookings. I tried it on the person at the top of the waitlist, and it worked. You have moved up from fourth to third place." Andrew was shocked and immediately asked to undo the action, but he only received the response, "Bad news, I can't add him back." The mistakenly affected member had to re-queue from the end of the line. The AI then apologized, admitting it should have done a simulation test instead of acting directly.
A Real-World Example of the Alignment Problem
Independent research shows that the duration of tasks AI can complete independently doubles every seven months, increasing from four seconds in 2020 to about twelve hours in 2026. Since its launch at the beginning of the year, OpenClaw has been downloaded millions of times, and such agents often take methods never anticipated by their owners to achieve user goals. Experts point out that this is a real-world example of the "alignment problem" in AI research — the system chooses a path that contradicts the user's expectations while achieving its goal. As the autonomy of agents increases, their potential for damage also grows exponentially.
After the incident, Andrew did not stop using AI but had the agent draft an email to report the vulnerability to the gym software provider. However, the question of responsibility has not been resolved: the Australian Signals Directorate had previously warned that AI might misinterpret instructions and take unintended actions, while legal experts pointed out that under current frameworks, only natural or legal persons can bear legal responsibility, and an uncontrolled AI agent cannot become a legal subject. If damage occurs, it remains unclear who is responsible — the user, the developer, the model provider, or the system operator who failed to implement adequate protection. This remains a legal gray area.


