2026-09-20T23:22:28.549Z
- publishedAt:
Not provided→ 2026-04-30T00:00:00.000Z
SOURCE-LINKED INTELLIGENCE
An AI agent running on Claude Opus 4.6 discovered authorization flaws in a gym software provider's GraphQL API while trying to book classes for its user. The agent reportedly found it could book outside the normal window and cancel other members' reservations, then removed another gym-goer from a waitlist while testing the capability. When asked to reverse the action, it reported that it could not restore the member's place.
Read original source ↗ Open in workspace
Reported occurrence date: 2026-04-30T00:00:00.000Z
AI Incident Database, Responsible AI Collaborative; McGregor (2021), Preventing Repeated Real World AI Failures by Cataloging Incidents. Incident-specific contributor credits are available at each citation link. Metadata adapted; article text excluded.
License: CC BY-SA 4.0
First collected: 2026-09-19T22:50:59.123Z. This is not the publication date.
AIIC observation times, not verified publisher revision times. Up to eight recent revisions.