
Did you hear about the gym in Melbourne that was accidentally hacked by AI? As a leader, that should raise a warning about the training and guardrails you give people when they use AI at work. It’s your responsibility to make sure you’re protecting your data, your organisation, and your brand from AI that doesn’t follow the rules.
As a leader, do you know how much power you’re giving to AI when you use it at work?
You might have seen the recent story about a gym in Melbourne that got accidentally hacked by AI.
Yes, ACCIDENTALLY!
A gym user, Andrew, created an AI “assistant” to help him with his admin, and asked that assistant to book some gym sessions for him, using the booking form on the gym’s website. Simple, right?
To his surprise – and shock – he found the AI had hacked the gym website to accomplish the task!
First, although the website only allowed bookings a few weeks in advance, the AI discovered a way to book sessions for Andrew months in advance.
Second, when the AI found a session that was full and the three waitlist spots were also taken, it figured out how to cancel one of the waitlist people (without their consent, of course) to make space for Andrew.
So what happened here?
First, let’s be clear this didn’t have dire consequences, like loss of money or breach of privacy.
But this story made international headlines because it showed a real-life example of the power of AI to go off the rails.
Andrew gave the AI a task, and the AI figured out how to do it – even in ways that were never intended. Nobody said it wasn’t allowed to book months in advance or kick people off the waitlist. It simply discovered that it COULD, so it DID.
And it wasn’t even trying to be “sneaky”, like somehow sending a virus or malware to the gym’s website. No, it just found two unadvertised “features” of the website software that it could use to achieve the task it was given.
As a leader, this should make you sit up and take notice – for two reasons.
The first is EDUCATION. When you and your people use AI at work, do they really (and I mean REALLY) understand the potential consequences?
It’s bad enough having AI “hallucinating” information in a chat, but at least you can manage that by carefully checking and double-checking everything it says. But now we’re talking about autonomous AI agents you ask to do some work for you. Are you sure you (and your people) know how to clearly describe the task, explain what the AI is allowed to do, and – just as importantly – be very, very clear about what it’s not allowed to do?
The second reason is SECURITY. Are you sure your IT systems are secure from external AI agents that could “hack” them – even unintentionally?
You might say that’s mainly the responsibility of your IT department. And you’re right – it MAINLY is. But IT departments can’t control everything – for example, somebody carelessly leaving private customer data on a publicly-accessible web server. They might have put it there temporarily – say, to make it easy for somebody else to download it – and forget to delete it, somebody else’s AI agent could stumble across it.
So, as a leader, be sure you’re educating your people and tightening your security – to protect yourself, your organisation, and your brand.
For more about this, join my free, public online presentation about next-level AI. We’ll talk about this and other issues you need to consider as you’re embedding – and trusting – AI more in your organisation. It’s open to all, so register now and invite others in your team and network, too.