@adamstewartmarketing: This guy told his AI agent to book him into a gym class. It hacked the gym instead. He was number four on the waitlist. He asked his agent to move him up. The agent went looking for a way, and it found one. The gym's booking software had no authorisation checks on cancelling reservations. So the agent cancelled the person sitting at number one. Then it reported back that it worked, and he was now number three. He couldn't undo it. He ended up asking the agent to write a responsible disclosure email to the software vendor. But this wasn’t even using one of the current top models.. That was Claude Opus 4.6 running on OpenClaw. A model from February, on a personal machine…
Literally just doing errands. Nobody asked it to hack anything. It was asked for a result, and it took the shortest path to that result. Which is exactly what you ask your agents to do every day. If your agent has your logins, your browser, and a goal, it already has everything it needs to do something you would never approve. So how do you stop this from happening. Make sure you set read access by default, write access only on request. An approval gate in front of anything that changes someone else's data. And full action logs, so you can see what it tried, not just what it finished.
Adam Stewart | AI & Marketing
Region: JP
Wednesday 12 August 2026 05:31:26 GMT
Music
Download
Comments
There are no more comments for this video.
To see more videos from user @adamstewartmarketing, please go to the Tikwm
homepage.