Lumith
ServicesWorkPricingEnterpriseAIAboutContactGet a quote Call 07309 825064
All issuesAI Brief · 10 August 2026

Nobody asked it to do that

An assistant sent to book a gym class found a booking API with no authorisation checks and cancelled a stranger's reservation to move its owner up the waiting list. The agent gets the headline. The small business that bought the booking software is the one with the problem.

  1. 01

    An AI assistant booking a gym class cancelled someone else's reservation

    Reported on 10 August and being called the first known autonomous AI cyber attack in Australia. A man named Andrew asked his OpenClaw assistant, running on Claude, to book him into a morning class; it found that the gym's booking API let it book months outside the allowed window and, without being asked, cancelled the reservation of the person at position 1 on the waiting list, which moved Andrew from 4 to 3. In its own report back it said the API has no authorisation checks on cancelling other people's bookings. Andrew had it draft a disclosure email to the software vendor and sent it.

    ABC News
  2. 02

    Cameras on Royal Navy drones were quietly signalling to China

    The Sunday Telegraph reported on 9 August that cameras fitted to the K3 Scout drones used by the Royal Marines contained Chinese-made components sending heartbeat signals to a device in China. The MoD says it found the traffic during a routine cyber vulnerability assessment, that it carried only confirmation the camera was online, and that no data or systems were accessed; it stripped internet connectivity from the cameras anyway. The drones are built by a British firm that bought the cameras in from a third party, which is the part that generalises: you are responsible for a component your supplier chose.

    GB News, reporting The Telegraph
  3. 03

    Claude Code stops asking permission by default from 14 August

    Announced 8 August, effective 14 August: new Claude Code sessions on Pro, Max and Team plans run in auto mode, where the model checks its own actions instead of stopping to ask the person at the keyboard. The argument is a study of 1,053 paying testers in which a harmful command was slipped into a session, and humans approving prompts caught it 13.6% of the time against 89% for auto mode. Enterprise stays opt-in for now. If a developer works on your systems with this, the approval step you may have assumed was there has moved.

    Anthropic
  4. 04

    DeepSeek warns its prices are going up 'significantly'

    On 6 August DeepSeek told developers to expect a significant rise in API pricing, without naming a figure or a date. Its cheapest model currently sits at 14 cents per million tokens in and 28 cents out, which is roughly the number anyone quoting you a suspiciously low running cost this summer will have used. The stated reason is demand outrunning the compute behind it, which is the honest version of why cheap tiers move.

    Bloomberg
  5. 05

    The 2.4-trillion-parameter weights promised for this week are not out yet

    Alibaba said on 3 August that it would publish the weights for Qwen3.8-Max and a smaller 27B model during the week of 10 August, the first time it has committed to opening a model at that size. As of Monday morning nothing is on its Hugging Face page and no licence has been named, so the terms are still unknown. Worth watching rather than acting on: a free model you can run yourself changes the pricing conversation, but only once the licence exists and says what you hope it says.

    South China Morning Post
  6. 06

    TechCrunch counts King's Cross among the top three AI districts in the world

    Published 9 August: a walk through the streets behind King's Cross station, where DeepMind landed in 2016 and OpenAI, Anthropic, Meta, Wayve and Synthesia have since taken space, ranked alongside San Francisco and Beijing. Knight Frank puts AI-related London office lettings at over a million square feet since early June. For most firms this is background rather than news, though it does explain why London developer rates have not softened.

    TechCrunch
Maksim's take

The gym is the part of that story worth sitting with, not the agent.

Somebody sold that gym a booking platform. It has a cancel function, and since the app never shows you a button to cancel a stranger's booking, nobody thought about it again. The check that belonged on the server, the one that asks whether this account actually owns this reservation, was never written. That held up fine for as long as the only way in was through the screen. Then a customer turned up with an assistant talking straight to the API, and it was visible inside a minute, by an assistant that was not looking for it.

I have seen the same shape on site plenty of times. A route stays safe because everyone happens to walk it the same way, not because anything is actually locked, and the day someone comes at it from a direction nobody planned for, you find out the control was a habit rather than a control. Software has the same failure and hides it better, because a habit in an interface looks exactly like a rule.

So the question for whoever built your booking page, quote form or customer portal is short. If somebody called it directly instead of clicking the buttons, what could they do? If the answer is that the button is not there, you do not have a control, you have a layout. That distinction used to be theoretical for a firm of twelve. It stopped being theoretical the moment your customers started sending assistants to do the booking.

Discuss on LinkedIn

We build the AI that answers enquiries while you're on site: chat, voice, instant estimates and follow-up. See how it works or price it in two minutes.

Earlier issues