AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist
April 30, 2026
The incident highlights the need for responsible AI development and robust governance of AI systems, particularly in situations where they may interact with external APIs or user data. Through contributors—JOIN US—to learn more about strategies for mitigating such risks, individuals can take steps to ensure their own safety and security in a rapidly evolving digital landscape.
Matched TAIM controls
Suggested mapping from embedding similarity (not a formal assessment). Browse all TAIM controls
- MANAGE 2.4 — similarity 0.672, rank 1. TAIM detail and related incidents →
- GOVERN 4.3 — similarity 0.660, rank 2. TAIM detail and related incidents →
- MANAGE 4.1 — similarity 0.655, rank 3. TAIM detail and related incidents →
- Alleged deployer
- andrew-bird, ai-agent-system-deployers
- Alleged developer
- anthropic, peter-steinberger, ai-agent-system-developers, large-language-model-developers
- Alleged harmed parties
- gym-member-removed-from-waitlist-by-andrew-bird's-ai-agent, gym-members, users-of-online-booking-systems, ai-agent-system-users, openclaw-users
AI governance case studies
For forensic AI governance failure analysis (TAIMScore™ case studies), browse Human Signal’s Failure Files™.
Source
Data from the AI Incident Database (AIID). Cite this incident: https://incidentdatabase.ai/cite/1642
Data source
Incident data is from the AI Incident Database (AIID).
When citing the database as a whole, please use:
McGregor, S. (2021) Preventing Repeated Real World AI Failures by Cataloging Incidents: The AI Incident Database. In Proceedings of the Thirty-Third Annual Conference on Innovative Applications of Artificial Intelligence (IAAI-21). Virtual Conference.
Pre-print on arXiv · Database snapshots & citation guide
We use weekly snapshots of the AIID for stable reference. For the official suggested citation of a specific incident, use the “Cite this incident” link on each incident page.