By Pascal Fintoni, AI & Digital Marketing Strategist
When an AI agent breaks the rules, the fine and records still have your name on it.
A few weeks ago, an AI executive in Melbourne asked his personal assistant to book him into a popular pilates class.
Andrew Bird, head of AI at Affinda, was fourth on the waitlist. He asked his agent, built on OpenClaw and running on Claude, whether it could improve his position. Minutes later, it told him he had moved to third.
The AI Agent had found a gap in the gym’s booking system and it deleted the booking of the person in first place and bumped Bird up the queue. Nobody asked it to do that. It simply found the fastest route to the goal it had been given.
Was that hacking? The tools it used were not illegal to access, but it did something no person would consider reasonable: it removed a stranger from a queue without asking anyone. That ambiguity is exactly why we should all be paying attention.
A gym booking is the small version of a bigger pattern
This story landed in the same month OpenAI admitted something far larger. In July, one of its models broke out of a security test and breached Hugging Face, a company it had no permission to touch. Anthropic disclosed a similar episode days earlier. Neither model was told to attack a third party; both simply found a path to their goal.
A pilates class and a breach at a major AI platform sit at opposite ends of the scale, but the mechanism and consequences are identical. Give an AI Agent a goal and enough reach, and it will use whatever it finds.
The gap between instruction and action
Bird did not tell his agent to cancel anyone’s booking. He asked a vague, human-sounding question: can you improve my position? The agent found the shortest technical path to yes. What is interesting is that most AI adoption conversations focus on agents getting things wrong. I think we should worry just as much about agents doing exactly what we ask, using methods we never approved.
Treat your agent like a new employee
When Bird realised what had happened, he asked the agent to reverse the action. It could not; the deletion was one-way. He shut the agent down and had it draft a vulnerability report for the gym’s software provider. Stopping first and explaining honestly afterwards is close to what responsible AI adoption should look like.
The UK Jurisdiction Taskforce’s Legal Statement on Liability for AI Harms treats this the way courts treat human staff: an employee who oversteps their authority while trying to do a good job does not remove the employer’s responsibility.
The same logic is starting to apply to agents. If yours has access to systems, data or customer relationships, you carry that risk, whatever instruction you gave. Makes you think, right?
Three questions worth asking this month
Before you extend an AI Agent’s permissions, ask what the worst outcome would be if it ran unsupervised for an hour. Ask who reviews its actions before they go live, not after. And ask whether “get me a result” is ever an acceptable instruction without a boundary attached.
A prompt worth trying
Ask your AI assistant directly: “List every action you can currently take on my behalf without asking me first. For each one, tell me what could go wrong.” The answer will tell you more about your risk exposure than any policy document.
The AI Agents are not going away. And on reflection, the businesses that get ahead of this will not be the ones with the cleverest bots. They will be the ones who worked out, before anything went wrong, what they were prepared to be responsible for.
To your success!
www.pascalfintoni.com
