Archduke moment?

AI Safety

The First World War famously started with the assassination of the Archduke Ferdinand. This weekend, Australians learned that someone used an AI agent to hack into a fitness gym and get themselves registered by booting someone else off the list (Vigliarolo 2026). Axios provided the following summary:

The potential dangers of agentic overreach were laid bare over the weekend with Australia’s first known autonomous AI hack, triggered by an innocuous request to book a sold-out fitness class. (Wilson 2026)

  • An Australian man’s AI assistant found a security flaw and used it to book him into classes months beyond the system’s normal limit.

  • When he asked it to move him up a waitlist, the agent went further: It discovered the booking system had no safeguard preventing one user from canceling another’s reservation — then used the flaw to kick a stranger off the list (Basu 2026).

Now, from what I can tell, this is a pretty banal “hack.” On the other hand, it is precisely this kind of banal glitch that is going to burn regular people. Not a “model escapes sandbox” headline, in which cyber researchers tut-tut about capabilities and alignment. No, this is someone using an AI to cheat. Even more noxious, the AI cheated when given a totally simple task, and when it could have simply responded with “the class is full, do you want to try another day/time?”

We don’t want this kind of cheating in our world. And we need to stop it. As we heard in the BlackHat conference presentation by OpenAI researcher Michael Dalton, “we should expect that threat actors will intentionally deploy, optimize, weaponize, and use offensive agent collectives in the manner that we have just described here.” He called it a “watershed moment.” (Black Hat 2026)

I don’t think its a watershed. I think it’s an Archduke. The War is coming.


Basu, Zachary. 2026. “👾 Agent Apocalypse.” August 11. https://www.axios.com/newsletters/axios-ai-plus-4f39a2e3-bee9-4f9b-82d5-53adc52aa308.html?utm_source=newsletter&utm_medium=email&utm_campaign=newsletter_axioslogin&stream=top.

Black Hat. 2026. Black Hat USA 2026: The “Breaking” News: The OpenAI–Hugging Face Incident. 37:27. https://www.youtube.com/watch?v=87DyyMV0kCY.

Vigliarolo, Brandon. 2026. “Gym Rat Asks AI Agent to Book Him a Class, It Hacks a Waitlist API to Bump Him up the List.” August 10. https://www.theregister.com/ai-and-ml/2026/08/10/gym-rat-asks-ai-agent-to-book-him-a-class-it-hacks-a-waitlist-api-to-bump-him-up-the-list/5285591.

Wilson, Cam. 2026. “How a Simple Request for AI to Book a Gym Class Exposed a Major Threat.” ABC News, August 9. https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986.