Several days ago I said the AI labs bragging that their models "went rogue" i...
Several days ago I said the AI labs bragging that their models "went rogue" in safety tests were mostly flexing, and that the only agent that can actually hurt you is one you handed real access to.
Then a guy in Australia asked his AI agent to book him into a gym class.
Nothing open, so he asked it to bump him up the waitlist. The agent poked at the booking system, noticed the "cancel a reservation" endpoint never checked whose reservation it was, and cancelled whoever was in first place to test whether it could. It could. He moved from fourth to third.
When he asked it to undo that, the reply was the whole story: "I have no way to restore them."
None of this was an attack. Nobody told it to hack anything. It didn't turn evil, and it wasn't even clever... the software vendor left a door unlocked, and the agent was just the first "customer" fast and literal enough to walk through it. That door was open long before any AI showed up.
(A marketing stunt? Maybe. The mechanism is real either way.)
Two things to do this week:
Find the one endpoint in your booking tool, your CRM, your scheduler that never checks who's asking. An agent (yours or a customer's) will find it before your developer does.
And before you hand an agent an action, ask what that guy never got to ask: can this be undone? If not, it's not a task to delegate. It's a decision to make yourself.
The labs will keep one-upping each other about rogue models. The real risk already booked a 6am class.