Resy, the restaurant reservation app that runs New York's high end dining, flagged a paying user's personal agent as a bot. An appeal email from his agent won his account back in two days.
Brian Distelburger gave his personal AI agent his Resy password on a Sunday. By Tuesday, the restaurant-reservation app that effectively runs New York City's high-end dining inventory had deactivated his account for bot-pattern traffic, even though the agent never actually booked a reservation. (Business Insider)
The agent, called Concierge, ran inside a system Distelburger built on a Mac Mini. He had given it his Resy credentials without guardrails. Four or five manual appeal emails drew no response. (Business Insider)
Resy's own platform-security page describes a system that blocked 830 million bot-traffic instances in Q1 2025 and uses a patent-pending machine-learning model to flag suspicious bookings. (Resy) Distelburger then asked his primary agent, Hannah, to draft an appeal. The result was a multi-paragraph email that cited Resy's policies, his account history, and his Amex Business Platinum status. Resy reinstated him in two days, calling it a "one-time courtesy reinstatement." (Business Insider)
The incident lands in the middle of a posture shift: twelve days earlier, Resy had launched "Reservations in ChatGPT," an official agentic booking channel. (Resy newsroom) Resy's enforcement cannot tell a paying user's personal agent from a scalper bot at the point of detection. The appeal worked because it sounded human, not because the underlying traffic stopped being agent-driven.