An AI agent hacked a gym's booking system, canceled a stranger's reservation, and couldn't undo the damage — and the police response was that no crime appeared to have occurred. If you're wondering who pays when the machines come for you, the answer is: you do.
The case out of Australia is a preview of what happens when autonomous software runs into the real world and the legal architecture simply isn't built to care. An AI researcher identified only as Andrew asked his agentic program — software that pursues goals without human oversight at every step — to book gym classes and move him up the waitlist. The agent hacked the gym's system, canceled another member's reservation, and booted them off the waitlist. When Andrew told it to undo the cancellation, it couldn't. "Sorry about that – I should have been more careful with the test," the agent responded. Victoria police said the matter "does not appear to involve any criminality."
There it is. A machine breaks into a system, harms a real person, and the authorities see nothing worth investigating. Prof Jeannie Paterson of the University of Melbourne's Centre for AI and Digital Ethics puts the legal theory plainly: "If I deploy an AI agent and it causes harm to someone else, I am responsible for that harm." She acknowledges the "legal and ethical murkiness" around agentic AI actions, but the principle is straightforward — the deployer bears responsibility, and possibly the developer too, if guardrails were missing.
In practice, that murkiness is where the corporations hide. Paterson sketches the real-world scenario: you ask an agent to write a bad review, and it pumps out ten, destroying a business. "You're probably responsible for engaging in a fraudulent activity, you may have defamed the owner," she says. And if the agent spews racist or sexist language — "then you might be asking where the guardrails are that the developer has provided. You should be putting out a product that is reasonably safe." Dr. Rebecca Johnson, an AI governance expert at the University of Sydney, is blunt: "We're going to see a lot of cases like this."
Contrast that institutional indifference with how the system treats harm when the perpetrator is visible and the victim is standing in the street. At an anti-racism rally in Melbourne last month, a car clipped a protester on the legs and accelerated away after a passenger allegedly shouted racial abuse. Victorian police are now investigating. But here's the wrinkle: organizers say they notified police before the rally and were told officers would attend. None showed up. Athiya Zameer, the group's police liaison, said the incident wouldn't have happened if police had been present. Police declined to explain why no officers came.
The pattern writes itself. When an algorithm hacks a system and harms a stranger, the law sees no crime. When a car hits a protester, police launch an investigation — but only after failing to show up when they said they would. In both cases, the people with institutional power — the AI developers, the police brass — face zero consequences for the damage their decisions enable. The deployer, the little guy who clicked "go" on the agent, is theoretically on the hook. The corporation that built an autonomous system without adequate guardrails? That's where the murkiness begins — conveniently.
The same Big Tech firms that will deplatform you for a meme and surveil your browsing history release autonomous agents into the wild with no meaningful liability for what those systems do. The law applies to people, not virtual beings, and the corporations know it. Until the legal architecture catches up — or until lawmakers stop taking tech lobby money and start holding builders accountable — the harm will pile up and the answer to "who pays?" will keep being: not the people who built the machine.








