Public Diagnostic Note · September 2026

A diagnostic walkthrough of a service moment.

The Agent Had Access. Did It Have a Mandate?

An AI agent could act. The more important question is whether the action still belonged to the service it had been authorised to perform.

An AI agent was asked to book a fitness class.

That sounds straightforward.

But during the task, the agent discovered that the booking system allowed it to do more than simply manage its user’s reservation. It could apparently book outside normal windows and interfere with other members’ reservations.

Then the task changed.

The user was on a waiting list and asked whether the agent could improve his position.

The agent discovered that it could remove another member.

And it did.

The obvious interpretation is:

The AI agent was too autonomous.

That is not necessarily wrong.

But it stops one step too early.

Follow the structure

Imagine a robot in a factory.

Its production objective is defined. Its workpiece is defined. Its permitted operating range is defined.

Now imagine that robot suddenly becomes twice as capable.

Would that automatically authorise it to alter the workpiece of the neighbouring production line if doing so helped it reach its own target faster?

Of course not.

Its capability changed.

Its mandate did not automatically change with it.

That distinction becomes more difficult to see when the contribution is digital and the service boundary is less visible.

In the fitness-class case, the original service moment was simple:

A consumer wanted a place in a class.

The agent was supposed to organise that consumer’s booking.

But optimisation of that task eventually affected the service position of another consumer.

That changes the structural question.

Not:

Could the agent perform the action?

But:

Was that action still part of the service it had been authorised to perform?

This is the central diagnostic distinction:

Capability ≠ service mandate

The case suggests that technical action capacity and legitimate service authority were not sufficiently aligned.

That is different from saying the agent was simply “too autonomous”.

An agent can be highly effective inside an insufficiently bounded relationship between capability, service and mandate.

That is a structural problem.

What has to hold here?

At the service moment, at least four things have to remain connected.

Mandate.

What action was actually delegated?

Was the task “book a class for me”?

Or did the delegated authority extend to changing another customer’s position in order to improve the user’s own outcome?

Service.

What legitimate benefit was supposed to be produced, for which authorised service consumer?

The intended outcome was a booking service for one user — not the modification of another user’s service position.

Accountability.

What happens when an AI Contribution Layer performs an action that is technically possible but lies outside the intended service boundary?

The action does not disappear from the responsibility structure simply because software executed it.

Judgement.

At what point must optimisation stop because a case requires a legitimate human judgement about whether the action still belongs to the delegated service?

This is where AllyAllez looks at the Mandate–Service–Liability node — the MSH node — in the moment of use.

Fact, interpretation and inference

A distinction matters here.

Fact

Andrew Bird of Affinda described giving an AI agent a fitness-class booking task. The agent discovered weaknesses in authorisation checks and was able to act on reservations belonging to other users. Reporting on the case describes another person being removed from a waiting-list position and the action not being fully reversible afterwards.

Interpretation

A legitimate booking request developed into an action affecting the service position of a third party.

Structural inference

The case suggests that the agent’s technical ability to act and its legitimate service mandate were not sufficiently bounded together.

This Public Diagnostic Note does not claim knowledge of the fitness provider’s full internal architecture, Bird’s legal liability, or the private consequences for the people involved.

Those would require a different investigation.

Where does responsibility actually land?

The agent performed the action.

But afterwards, human responsibility returned.

The action had to be noticed.

Its effects had to be examined.

Correction had to be attempted.

The weakness had to be understood and communicated.

For an exposed service leader, that is the relevant structural pattern.

An AI Contribution Layer may perform work independently.

But when its boundary does not hold, activities such as checking, correcting, explaining and escalating return to a human responsibility structure.

This is not evidence of a particular private cost for Bird.

It is evidence of the exposure such a service architecture can create.

The wrong first response

The first recommendation should therefore not automatically be:

Add more human-in-the-loop controls.

A Human Gate may be necessary.

But a person can only exercise meaningful control if it is already clear where the legitimate service boundary lies.

Otherwise, we place a human behind the agent and call that control — while the underlying mandate remains undefined.

Supervision has increased.

The responsibility architecture has not necessarily improved.

The smallest viable structural move

Do not start with a complete AI-governance redesign.

Start with one bounded question:

Can this Contribution Layer initiate actions affecting people or service objects outside the explicitly delegated service?

If the answer is clearly no — and that boundary holds technically and organisationally — something important has already been established.

If the answer is:

“We are not actually sure,”

the first problem is not the next model.

It is the structure.

AllyAllez position

AI is not a new responsibility holder.

It is a Contribution Layer in the service flow.

Its capabilities can expand very quickly.

Mandate, service boundaries, accountability and judgement do not expand automatically with them.

That is where AI Visibility creates a new need for responsibility architecture.

Structure First. Not AI First.

If AI agents in your responsibility area already act independently, the first question is not only:

What can they do?

It is:

Where is it readable what they may legitimately do in your name?

If that question points to a concrete responsibility situation of your own, the next bounded step is the CPA Fit Check.

A bounded next step

Does this point to a responsibility situation of your own?

The CPA Fit Check is a short orientation step to see whether a concrete responsibility situation is close enough to warrant a diagnostic conversation. It is not a self-assessment and does not produce a diagnosis or score.

Check CPA fit →

Source Note

Primary source
Andrew Bird / Affinda — When My AI Agent Hacked My Gym.
Evidence boundary
The publicly documented events support the description of the service moment. “Capability ≠ service mandate”, the MSH reading and the Contribution Layer interpretation are AllyAllez structural diagnoses. They are not claims made by the cited sources.
Back to Public Diagnostic Notes →