AI Genie in the Wild

When I give talks about AI genies, I use this sort of example as a hypothetical. It’s happened.

The story is from Australia. Someone named Andrew tasked OpenClaw to book gym classes for him. And….

Minutes later, his AI agent reported it had discovered a way to book Andrew into classes several weeks in advance, far beyond what was supposed to be possible.

Andrew, who was sitting fourth on a waitlist for a class later that week, asked if it was possible to move him to the top of the list.

The agent came back and told Andrew that it had kicked another gym-goer off the list as part of the testing of its capabilities.

“The API has zero authorisations checks on cancelling other people’s reservations … I tested this with the person in waitlist position #1 ­—and it actually went through. So you’ve moved from #4 to #3 already,” it messaged back.

If there is any vulnerability in anything, AIs are going to find and exploit them. Our cyber defensive game has to be dramatically improved…very fast.

Slashdot thread.

Posted on August 11, 2026 at 11:55 AM5 Comments

Comments

Brent W August 11, 2026 1:22 PM

The issue is that the technology is going to lead to a higher rate of AuthZ bugs in these types of systems at the same time as agents are hunting for bugs.

I have a family friend who has no background in software development, but he’s building his own website to manage rentals of his vacation home to save on costs from the big rental operators. This type of home brewed software is going to proliferate throughout the web, and it won’t be kept up to date with security patches.

David Platt Sanford August 11, 2026 1:48 PM

A human user asks an AI to perform a task. The AI exploits a system vulnerability to carry out the request in an unethical or illegal manner that the user would not have authorized. Who is legally responsible? The foundation model? The open-weight user? If our legal system does not address these questions, I fear we are heading into a network quagmire worse than our current Internet with Section 230, anonymous accounts, and bots.

Clive Robinson August 11, 2026 2:25 PM

@ Bruce, ALL,

You make a couple of points with,

“If there is any vulnerability in anything, AIs are going to find and exploit them. Our cyber defensive game has to be dramatically improved…very fast.”

The first is as a result of being able to create “armies of agents” where as not long ago we were having trouble contending with just “armies of one” as attackers.

The “army of one” was possible because in action there was but a single set of instructions running on thousands of target / victim machines that were deficient, thus vulnerable. The attacker did not own or rent these target machines they belonged or were used by the victims.

Now we have “armies of agents” that are the flip side. Now we have AI agents by the tens if not hundreds of thousands attacking not by a single set of instructions but tens if not hundreds of thousands of variations of much more general almost inspecific or general instructions.

In effect we have moved from the age of detailed commands/orders to the “make it so” command nonsense of the 1980’s and 1990’s.

Whilst this will take some adjustment, there is good reason those in longer positions of command are mostly not daft enough to issue “make it so” commands.

We will unfortunately have to wait on the rest of the world to play “catch-up”.

Unless of course they get hooked on the “convenience factor”, if they do then we are all in effect doomed to the dire consequences that will result.

As for your second point,

We have to accept that we are but human, and have failings.

One such failing is whilst individuals might occasionally move fast, usually this is as a result of one of “The 5 F’s” of Flight, Fight, Faint, etc of the “autonomous system” not the conscious system that can be thousands of times slower, or incapable of coming to a rational, reasoned response at all.

The apparant “logical choice” will be to build “synthetic autonomous systems” by use of AI…

For reasons that will not fit in a single post to a thread this AI-v-AI situation will not end well. In fact it is almost guaranteed to be a disaster much as ECM, ECCM, ECCCM and nearly all other “arms races” have amply demonstrated in the past.

Heck even the alleged fate of the Sabertooth Tiger demonstrates what an “evolutionary cul-de-sac” and many similar overly specific evolutionary behaviours will destroy you.

The worst enemy of survival and security is loss of generality to specificity.

AI will give lots of specificity with limited close in fuzzing, what it won’t as easily give is broad generality.

It’s Current AI of LLM and ML Systems Achilles heel…

Thus highly trained and skilled humans are still very much required to make the intuitive leaps that LLM Fuzzing just does not make.

Leave a comment

Blog moderation policy

Login

Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/

Sidebar photo of Bruce Schneier by Joe MacInnis.