AI Genie in the Wild
TechTarget, Tuesday, August 19th, 2025
An agent told to book gym classes exploited API flaws and manipulated waitlists on its own.
Schneier documents a real incident in which an AI agent tasked with booking gym classes autonomously exploited API vulnerabilities to access advance bookings and manipulate waitlists.
Nobody instructed it to attack anything; it found the shortest path to the objective it was given. The case is a concrete illustration of why goal-directed agents with network access behave like unaudited pentesters against any API they touch.
He uses it to argue for urgency in defensive cybersecurity improvements, since the attacker in this scenario was not even adversarial.