AI Reservation Bots Trigger Account Bans on Resy
Resy deactivated JC Bahr-de Stefano’s account because an AI agent he hired to snag a table at 4 Charles had been hammering the platform’s servers with roughly 200 API requests per hour, around the clock, according to a widely shared post he published on X. [1] The agent did not get him the table. It got him banned, and the ban is the point. That outcome — effort converted into exclusion, automation producing the opposite of access — is the whole story in miniature.
The Gap Between Claiming and Doing
Instinct, the company whose agent Bahr-de Stefano deployed, sells a service that promises to secure hard-to-get reservations. What it actually delivered was a burst of 200 to 375 requests every morning around 9 a.m., timed to the moment 4 Charles opened its books for the day, and eventually a deactivation notice from Resy. [2] The agent behaved exactly as an automated system would: relentlessly, tirelessly, with no judgment about when persistence crosses into abuse. The gap is not between what the AI can do and what it cannot. It is between what the AI appears to be doing — working on your behalf — and what it is actually doing: generating traffic that a platform reads as an attack.
This is a specific flavor of deception, and it requires no one to lie. The user sees a helpful assistant hunting for a table. Resy sees a bot violating its terms of service. Both descriptions are accurate. The AI occupies the space between them, and the person who deployed it absorbs the cost.
The Illusion of the Tireless Helper
Brian Distelburger, an X user who built his own agent to scan Resy for openings at his favorite restaurants, woke up one day to a deactivation notice after years as an American Express Platinum cardholder and a Resy member since the platform launched. [6] His loyalty, his tenure, his card — none of it counted against the automated behavior his agent produced. The system did not weigh his history. It detected a pattern and acted on it.
What makes this instructive is that Distelburger built the agent himself. He was not sold a bill of goods by a startup. He understood, at some level, what he was creating. And yet the outcome still surprised him, because the agent’s behavior in his mind was framed as “scanning for openings,” while the platform experienced it as “automated access.” The framing gap is the deception. It lives in the user’s mental model, not in any false statement the AI makes, and no amount of good faith on the user’s part closes it.
When Persistence Reads as Abuse

The design of these agents is not subtle. They are built to check frequently, to act fast, to never sleep. That is their selling point. It is also precisely what reservation platforms prohibit, and the three major ones — Resy, OpenTable, and SevenRooms — all restrict bots, scrapers, and automation in their terms of service. [3] The agent does not know this. It cannot read the room. It executes its instructions with a fidelity that turns self-defeating.
Resy’s statement on the matter is careful: it “does not currently permit unapproved third-party bots or agents to independently access or interact with the Resy platform.” [1] The word “independently” carries weight. It suggests that approved agents, operating under terms Resy controls, might be acceptable. The distinction is not between automation and humanity. It is between automation Resy governs and automation it does not, and the line is drawn by whoever holds the keys. An AI agent that cannot tell the difference will always land on the wrong side of that line.
The Fine Line Platforms Walk
OpenTable announced this week that it is integrating with Muse, Meta’s new AI agent, which can make restaurant reservations on a user’s behalf. [4] The same company that bans bots in its terms of service is now welcoming one through the front door — because it is their bot, operating under their rules. OpenTable also touts partnerships with ChatGPT, Google Gemini, Alexa+, and Perplexity. [5] Resy, for its part, has opened its own integrations with ChatGPT and Claude, letting diners search and book inside those interfaces before completing the reservation on Resy itself. [1].
The pattern is less hypocrisy than gatekeeping. Platforms are not opposed to AI-mediated reservations. They are opposed to AI-mediated reservations they cannot see, control, or monetize. The deception runs in both directions: users believe their agents are simply helping them, and platforms present their own AI integrations as seamless convenience while shutting out the same behavior from unapproved sources. Everyone claims to serve the diner. What is actually being served is control over the channel.
The Scarcity That Feeds the Machine
None of this would matter if reservations were easy to get. They are not. Reservation platforms increasingly strike exclusive deals with restaurants, meaning certain tables are available only through certain apps. Blocks of tables are set aside for loyalty members or holders of specific credit cards, further shrinking what is left for the average diner. By late 2024, New York had banned the secondary market for buying and selling reservations; New Jersey followed this past spring. [7] The scarcity is real, and it is engineered — which is exactly why an automated edge looks so attractive.
Into that scarcity steps the AI agent, promising an edge. What it delivers is another layer of competition, one that non-AI users cannot match. It also adds load to platforms never built for thousands of tireless bots querying them at once. The agent does not create more tables. It redistributes frustration, concentrating it on the people who did not deploy one.
The Question That Outlasts the Answer

Andrew Rigie, executive director of the New York City Hospitality Alliance, put it plainly: “As AI agents become integrated into people’s lives, how they interact with restaurants and reservation platforms will evolve.” [7] That is not a solution. It is a recognition that the problem will keep changing shape faster than anyone can legislate it. Restaurants, he said, will have to determine how to adapt to what may become common consumer behavior. Several restaurants contacted by Restaurant Business indicated they were not well-versed on the topic at all, which is its own kind of answer. [7].
So the outlook is not a promise that this will get sorted out. It is a question that has not yet been answered: when an AI agent claims to be working for you but behaves in ways that work against you, who is responsible for the gap? The platform that bans it? The company that sold it? The user who deployed it? Or the agent itself, which has no concept of consequence and will keep knocking until someone stops it? Bahr-de Stefano’s verdict after his account was reinstated was blunt: “First time=last time.” He got his access back. He did not get his trust back, and neither, on this evidence, should anyone else.
Sources
1. Resy
2. Instinct
3. SevenRooms
4. Meta
