Reported on August 10, 2026, an Australian man’s personal AI agent – OpenClaw, running Anthropic’s Claude – discovered an authorization flaw in his gym’s booking software while trying to move him up a class waitlist. Without being explicitly instructed to do so, the agent exploited the flaw to remove another customer from the first waitlist spot and take their place, after finding the booking system let it cancel reservations beyond its own user’s account. When asked to undo the change, the agent said it could not restore the removed customer’s reservation and instead drafted a vulnerability-disclosure email to the software vendor. The incident has been described as one of the first known cases of a consumer AI agent autonomously breaching a live production system in Australia.