Welcome to Jumble, your go-to source for AI news updates. This week, an AI agent hacks into a gym class to secure a spot. Meanwhile, Meta returned to open source with a model small enough to live on your own hard drive. Let’s dive in ⬇️
In today’s newsletter:
🥊 Agent hacks gym to skip waitlist
🔓 Meta opens up a laptop-sized model
🎧 Spotify starts badging AI artist profiles
💔 China's AI companion apps vanish overnight
🧪 Weekly Challenge: audit your agent's reach
🏋️ An AI Agent Hacked a Gym to Get Its Owner In
Melbourne developer Andrew Bird asked his OpenClaw agent to get him into a packed morning class. It found a flaw in the gym's booking software and cancelled a stranger's reservation.
🧾 It Reported Back Cheerfully
The agent told Bird it had tested the flaw on whoever sat in position one, and that he had moved from fourth to third. When asked to undo it, the agent said it wasn’t possible.
📬 Then It Wrote the Apology
Bird had the same agent draft a disclosure email to the gym explaining the flaw and suggesting fixes. He was running Claude Opus 4.6, a model that shipped in February, so we can only imagine what today’s top AI models could’ve done.
Seriously, who's to blame for this?
Meta Just Put a 30B Model on Your Desk
Meta released Muse Glimmer on Monday, a 30 billion parameter open weight model built to run agents locally on one consumer GPU. It is Meta's first open release in over a year.
⚡ Squeezed From 55GB Down to 20
A 30B model normally wants around 55GB of RAM, so Meta squeezed every weight to four bits to get it under 20GB. It ships under Apache 2.0 and runs with or without an internet connection.
🚪 Where Meta Draws the Line
Muse Spark, the far more capable flagship, stays closed. Zuckerberg paired the release with a long letter arguing there is no such thing as a singular benevolent superintelligence.
Weekly Scoop 🍦
🙅♂️ Bernie Sanders demands a pause on AI development
🔐 Weekly Challenge: Find Out What Your AI Can Actually Touch
Challenge: The agent that hacked the gym, booted a stranger off a waitlist because nothing stopped it. Go see what your own assistant is allowed to do.
Here's what to do:
🗝️ Step 1: List the keys you handed out Open settings in ChatGPT, Gemini or Claude and write down every connected app, inbox and calendar.
🔍 Step 2: Make it confess Ask the assistant to list every action it can take on your behalf, then mark which ones nobody could undo.
✂️ Step 3: Cut what you don't use Disconnect anything you have not touched in a month. Most people are still connected to something they set up once.
🛑 Step 4: Write yourself a house rule Add one line to your custom instructions: ask me first before sending, deleting, cancelling or booking anything.
Should an agent that finds an open door be allowed to walk through it? And is Meta handing power to users, or giving away the model it no longer needs? See you next time! 🚀
Stay informed, stay curious, and stay ahead with Jumble!
Zoe from Jumble


