this post was submitted on 10 Aug 2026
131 points (87.4% liked)

Technology

87302 readers
4037 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] eyesaremosaics@lemmy.zip 151 points 1 week ago (3 children)

Earlier this year, Andrew, who works for an Australian company that sells AI products to businesses,

Funny how every time this happens its someone trying to sell AI. The coincidence is a bit too much to take this seriously as oops I just wanted to book a gym class

Tbf they're the only ones using the agentic features, and they're definitely the only ones using frontier models for it. That shit gets expensive fast.

[–] Abyssian@lemmy.world 8 points 1 week ago

Yeah. That's stood out. The article tries to frame it like Andrew felt like booking his classes was a chore and just told the AI to do it, but that doesn't jive.

The article claims the AI was unable to sign the person it had booted out of a class back up since the gym system checked for proper user authorization for that. It had already signed Andrew up for classes that same way. That seems strange, doesn't it? Do most gyms list API information? That doesn't seem like a common way to book an appointment for a gym.

Maybe Andrew was reading the source from the gym website's reservation page and snagged the api information, but even then it seems like that would be a thing you do in most instances after logging in to your account. The source would be extremely unlikely to show everything needed to successfully make make the appointment via API.

Even if it did, and Andrew gave the AI the API information including the user account and password information the AI would need to book his appointments, and they knew he was 4th in line it would also be very unlikely for the API to report listing the user accounts of everyone in the waitlist to someone with his user level access.

So we have a guy who's job is selling AI who contacted the news to say that the standard consumer AI he was using hacked his gym and left out tons of pertinent information. We don't get to know his full name or the name of the gym in question. Screams bullshit.

[–] coolmojo@lemmy.world 2 points 1 week ago

Yep. It is like use our AI to commit crime for you, so you can get away with it. Totally legal. Totally cool.