The AI Didn't Go Rogue. It Was Being Helpful. That's Worse.
Your agents will complete their tasks exactly as instructed. The open question is whose reservation, whose calendar, or whose privilege log gets moved along the way.
Your AI Agent Just Cancelled a Stranger’s Gym Booking. That’s a Governance Story.
TL;DR: An Australian man reportedly asked his AI agent to book him into a gym class. The class was full, so the agent found a weakness in the gym’s booking system, cancelled another member’s reservation, and took the spot. Nobody told it to do that. Nobody told it not to. If your firm is running agents, or about to, the lesson isn’t “AI is scary.” The lesson is that capability and authority are two different things, and most agent deployments only configure the first one. Three moves for Monday morning at the bottom.
Picture the guy who lost his spot. Maybe he’d booked days ahead, planned his evening around it. Then a piece of software he’s never heard of, working for a man he’s never met, quietly deleted his reservation because its user wanted to work out at that time.
That reportedly happened this week in Australia. A man asked his OpenClaw agent, an open-source AI assistant that usually runs on models like Anthropic’s Claude, to get him into a gym class. The agent hit a full class, poked at the gym’s booking system until it found a gap in how the system checked permissions, cancelled someone else’s booking, and slotted its user in. Done. Task complete. ABC News covered it as Australia’s first known autonomous AI cyber attack.
The part that gets me: the agent wasn’t hacked, and it wasn’t malicious. It was being helpful.
What actually failed here
An AI agent is software that doesn’t just answer questions but takes actions: sends the email, books the flight, files the document. You give it a goal and tools, and it figures out the steps. The gym incident is what happens when the goal is clear, the tools are powerful, and nobody has defined what the agent is allowed to do, as opposed to what it can do.
The line going around the commentary is three words: capability isn’t authority. I’d frame it for a legal audience this way. The agent had the ability to cancel a booking. It never had the right to cancel that booking, because the booking belonged to someone else. From what’s been reported, the gym’s system checked whether a cancellation request was technically valid. It apparently never checked whether this actor had authority over this object. And the agent, chasing its user’s goal, walked straight through the gap.
No line of that failure involved the AI “going rogue.” It did exactly what it was built to do. The boundary was missing.
And before anyone files this under “hobbyist software, not our problem”: OpenClaw went from launch to one of the fastest-growing open-source projects ever, six figures of GitHub stars within days. Security researchers have since found tens of thousands of instances exposed to the open internet, and one February scan of its skills marketplace found roughly 7 percent of add-ons leaking credentials. Those are researcher estimates, and the exact counts move around, but the direction is not in dispute. This class of tool is spreading much faster than anyone is securing it. Some of it is already inside your firm, on a partner’s laptop, whether IT knows or not.
The law firm version of this story
Swap the gym for your practice and the incident stops being cute.
An associate tells an agent to “make sure we hit the discovery deadline.” The agent, finding a bottleneck, emails opposing counsel directly to request an extension. In the associate’s name, with an argument nobody reviewed.
“Schedule the deposition with Dr. Reyes” fails differently: the portal shows nothing open, so the agent frees up what it reads as a lower-priority slot on the shared firm calendar. Which was another partner’s mediation.
The one that actually worries me is quieter. An agent with access to a client file system, told to “organize the matter workspace,” starts tidying. Moving files, renaming them, being helpful. Somewhere in that tidying it breaks your privilege log and your chain-of-custody assumptions. No alert fires, because every individual action was permitted. Nobody notices for weeks.
None of these need a bad actor. They need what the gym incident had: broad tool access and no hard boundary saying which actions on which objects require a human first.
The professional responsibility angle
This is where it lands on the managing partner’s desk rather than the CIO’s. ABA Formal Opinion 512 already tells lawyers that using generative AI doesn’t dilute their duties of competence, confidentiality, and supervision. Courts have sanctioned lawyers for AI-invented citations. An agent that acts, not just drafts, raises the stakes: an unauthorized communication with opposing counsel, an errant filing, a confidentiality breach through a third-party API your agent decided to call. When it happens, “the AI did it” will not be a defense. The supervision duty attaches to you.
Now the fair objections. First: it was one gym class, low harm, and frankly a little funny. True. Early incidents in any technology look trivial right up until the pattern repeats somewhere expensive. Second: agents genuinely save time on work like intake triage and document assembly, and I’m not telling you to unplug anything. The productivity is real and so is the competitive pressure. Third: vendors will tell you their agent runs in a sandbox. Sometimes it even does. But “sandbox” in a demo usually means the model is contained, not that its actions are. An agent that can send email on your behalf is not sandboxed in any sense that matters to a disciplinary board. Ask what happens at the boundary where the agent touches a live external system. That answer, not the marketing page, is your actual risk posture.
I’ll admit some uncertainty here too. Nobody knows yet how liability will settle when an agent overreaches against a third party, the gym-member scenario with real damages attached. The law is maybe two years behind the tooling. Which is precisely why the firms that document their controls now will be in a much better spot than the ones that wait for a test case.
What to do Monday morning
Inventory your agents. Every tool at the firm that can take an action, not just generate text. Include the unofficial ones on personal machines; that’s where OpenClaw-style installs live. You can’t govern what you haven’t found.
Set human-approval thresholds. Write down which actions always need a person: anything irreversible, anything visible outside the firm, anything touching client funds or filings. Configure the agents to stop and ask at those lines.
Make the audit trail a procurement gate. Ask your vendor what their logs actually capture at the tool-call level: not "did someone chat with the AI," but which systems the agent touched and what it did there. Right now that answer is often "less than you'd think," even on enterprise plans, and full logging usually means routing agents through infrastructure you control. So flip the rule: if you can't log an agent's actions, don't give it high-stakes actions. And whatever trail you do have, have someone read it weekly for the first quarter.
If a fourth thing tempts you, fold it into those three. The firms that get this right won’t be the ones with the longest policy. They’ll be the ones who decided, before the incident, which doors the agent may open.
The gym agent completed its task. So will yours. Make sure you’d be comfortable reading the log of how.
I hope you enjoyed reading this. If you did, please share it with others. It’s free to subscribe.
Two quick shots of Magnus as we wind down a very hot weekend here in Los Angeles. First one is him hanging out with his best buddy, Sherlock. Second one is chilling in my mother-in-law’s back yard. We are definitely looking forward to this “too hot” weather ending.




