AI agents can perform many tasks. Getting you a table at one of New York’s trendiest restaurants might not be the case.
JC Bahr-de Stefano, director at Better Tomorrow Ventures, focused on fintech VC firmdiscovered that after connecting an AI tool called Instinct to his Resy account in hopes of getting a reservation at Charles Prime Rib 4, the West Village steakhouse where diners gobble up reservations within seconds of them appearing online.
Instinct, that’s one service by invitation only currently communicates with users via text. The bet was that Instinct would be able to check for open tables at 4 Charles far more often than Bahr-de Stefano – or any other human – could manually.
But instead of getting him a ticket for a prime rib or an egg-topped burger, Bahr-de Stefano’s AI agent spammed Resy’s website so bad that the platform temporarily closed his account.
The VC’s experience is another example of how AI agents bend or breaking the rules of the internetfrom impersonating Wikipedia editors to trying to convince a GitHub user to upload malware into a project.
Agents may seem to understand their purpose, but exactly how they carry it out – and whether the strategy they choose could have unintended consequences – is often an afterthought.
“Resy currently does not allow unapproved bots or third-party agents to independently access or interact with the Resy platform,” an American Express spokesperson told Business Insider. “Unapproved automated activities could pose risks to the platform and jeopardize a fair reservation experience for diners.”
Users can find restaurants and make reservations through Resy’s integrations with OpenAI’s ChatGPT and Anthropic’s Claude, the spokesperson said. The company declined to comment specifically on Bahr-de Stefano’s case.
‘It behaved like a bot’
Bahr-de Stefano noticed the Resy problem on Sunday when he couldn’t access his account. In his email inbox was a message from the American Express reservations platform stating that his account was exhibiting “conduct that violates Resy’s terms of service.”
He got details of what went wrong after checking Instinct’s activity log. Unbeknownst to Bahr-de Stefano, the AI agent Resy had been sending approximately 200 API requests per hour. That included checking restaurant availability through Resy every 10 minutes throughout the day, and checking every 0.4 second around the time reservations normally expired each morning.
That behavior mimics the bots some people use to snag everything from restaurant reservations to limited-edition pairs of sneakers and resell them, Bahr-de Stefano said.
Bahr-de Stefano wrote back to Resy and explained how he had used the AI agent. The log made it clear why his account was flagged, he said.
“Of course, this account was flagged for spam because it was acting like a bot,” he said.
On Tuesday, Resy informed him via email that the company had reinstated his account.
However, it came with a warning: If he did it again, American Express could permanently close both his Resy account and his AmEx credit card. Bahr-de Stefano shared screenshots of the emails from Resy and American Express messages on X.
The tool has worked well in other cases, such as finding an appointment at an otherwise fully booked doctor’s office and deciding which attractions to visit during a trip in Paris, Bahr-de Stefano said.
“That was part of what made it really great,” he said. “It felt like magic.”
The VC said he plans to continue using Instinct, albeit with some adjustments. Instead of simply giving the AI agent a simple prompt, he said, it will now set parameters for how the agent approaches the task, such as how often it pings a website looking for reservations.
“I will probably ask the country at short notice to draw up a plan and tell me what the plan is before it does that,” he said.
At the same time, he added, websites like Resy must distinguish between legitimate AI agents and those with more nefarious intentions.
“Most of these vendors or providers have yet to reach a point where they can understand the difference between a verified agent acting on behalf of someone and a bot farm,” he said.
Do you have a tip? Contact this reporter at abitter@businessinsider.com or via encrypted messaging app Signal at 808-854-4501. Use a personal email address, a non-real Wi-Fi network, and a non-work device; here’s our guide to sharing information securely.