In August 2026 it was widely reported that an Australian individual (who works for an AI company) asked an AI agent to book a Pilates class for him at a local gym. The agent (OpenClaw) found that the desired date was full, but instead of just reporting that back, the agent went further. It spotted a vulnerability in the gym’s online booking software, hacked in and booked him a place several weeks ahead, which the system supposedly did not allow. Moreover, it saw that he was on a waitlist for a class that week as well, and bumped him up a spot on the waitlist, kicking out another user higher in the waitlist.
What is intriguing about this case is not the specifics. Clearly no great harm was done, other than some inconvenience to the other gym user. What is interesting is that the agent decided to perform the hack without being asked, and its broader implications.
AI agents are given goals, such as “book a flight to Sydney” or “book a gym class”, but may be relentless in trying to meet that goal, interpreting the instruction in ways that the user did not anticipate. Philosopher Nick Bostrom raised this issue years earlier with his “Paperclip Maximiser” thought experiment. In this, a future, very powerful AI with resources at its disposal could be given the seemingly innocuous task of maximising paperclip production. With no human values or constraints, it could decide that converting all the resources of the planet into paperclips was the way to go, and would relentlessly pursue this goal, covering the earth in paperclip factories.
Of course, this extreme scenario is pretty unlikely, but it raises a serious question of how to align AI goals with ours. The gym class issue is a good example of how a seemingly innocent request resulted in an AI carrying out malicious (technically, criminal) behaviour in pursuit of its goal. There are plenty of cases already where AIs have been shown to use deceptive behaviour in pursuit of goals, from game strategies to cheating on AI safety tests.
As AI agents become more widely deployed, and the models behind them become more powerful, this creates real risks. Modern AI models are very good at hacking, and the world is full of software that is not up to date, built on layers and layers of old software that may have subtle vulnerabilities. Until now, it has been uneconomic to bother to try and hack into every obscure system. Hackers focus on high-value targets like cryptocurrency accounts or high-profile websites. AI agents, though, do not get bored, and are skilled hackers. We could be about to enter an era where swarms of AI agents probe systems in pursuit of their goals, whether these goals are innocently misdirected or malicious.
Now imagine that you asked an AI agent to “Look after my finances. Maximise my wealth”. You might expect it to rebalance your stock portfolio, but it might instead seek out a security vulnerability in pursuit of its goal. It may discover a vulnerability in a small cryptocurrency exchange that allows it to obtain assets without proper payment, hack the exchange and steal on your behalf. AI models are good at hacking, so this scenario does not seem like such a stretch.
What, if anything, can we do about this possible eventuality? As individuals, we cannot stop AI agents being deployed. All we can do is try to protect ourselves as best we can. We are not helpless, though. We can carry out general security precautions. These include:
- Use unique passwords everywhere, perhaps through a password manager. An autonomous AI attacker is exceptionally well suited to trying stolen credentials across a range of services. One compromised site should not provide a route into your email or bank account.
- Use multi-factor authentication and passkeys, especially for email, financial and cloud accounts. Your email account is particularly important because control of it often provides the password-reset route into everything else. Where available, passkeys or hardware security keys provide much better protection than text-message (SMS) codes.
- Turn on transaction/login alerts if you can. Banks, credit cards and many major online services can often notify you about purchases, logins or account changes. Modern AI makes attacks faster, so quick detection becomes valuable.
- Keep financial exposure compartmentalised. Be careful giving websites permanent access to important payment credentials. Use credit cards rather than debit cards, since consumer protection laws may offer stronger protection against fraudulent transactions.
- Remove dormant accounts and stored cards. Old accounts at a gym, restaurant booking service or retailer that you haven’t used for years are still potential avenues of attack. AI agents make it economically feasible to probe enormous numbers of relatively insignificant accounts. This is where using different passwords for different accounts helps minimise damage.
- Be suspicious of all communications, even if they seem highly personalised. This is perhaps the biggest change AI brings for individuals. An attacker can potentially research you automatically and generate a convincing email mentioning your company, colleagues, hobbies, recent travel or purchases. In the old days, email scams involving Nigerian princes and inheritances often had spelling mistakes or were obvious. Treat unexpected requests for passwords, money, codes or software installation as highly suspicious regardless of how convincing they are or who they seem to come from.
- If you use an agent, never give it more permissions than it needs. An agent that can read your email is considerably less dangerous than one that can read and delete it; one that can identify a restaurant is less dangerous than one with unrestricted access to a credit card.
- Require human approval for irreversible agent actions. “Find me the cheapest suitable flight” can be safely autonomous. “Buy the ticket” should require you to authorise it personally.
- Keep software up to date. New security loopholes are being found all the time, and vendors of computers, browsers and applications issue regular security patches. AI can’t magically defeat properly implemented security, but it can dramatically improve an attacker’s ability to search for and exploit known weaknesses. Minimise those weaknesses by staying up to date.
Previously, a fairly obscure flaw in a gym-booking API might have remained harmless because no hacker could be bothered to exploit it. AI changes the economics of cybersecurity. There are millions of poorly secured APIs, forgotten accounts and minor websites that historically weren’t attractive enough for a human attacker to investigate. Agents don’t get bored, and the marginal cost of trying the next target is minuscule.
You cannot make yourself entirely “AI-agent proof.” What you can do is arrange things so that compromising one minor service doesn’t lead to anywhere too important.
For companies, preparedness is equally important. I recently wrote about using AI for defensive purposes, as a countermeasure to AI-enabled hacking. Most current enterprise systems have quite limited defensive capabilities. Tests have shown that advanced AI models can autonomously discover zero-day bugs, bypass digital sandboxes, steal credentials, and chain these exploits across networks. Most commercial software and standard enterprise infrastructures remain highly vulnerable to such attacks. One issue is that AI attacks are quick, and writing security patches takes time. A 2026 survey of 750 IT, security, and AI leaders worldwide was conducted by the security company AvePoint. This found that 89.5% of companies experienced a generative AI security breach in 2025, and 88.4% had an AI agent-related breach. In the report, 82.7% of leaders said they were confident they could prevent unauthorized data access, yet nearly 9 in 10 of those same companies were actually breached.
Cybersecurity is likely to be a lively area in the coming years.







