Wikimedia says rogue OpenAI agents edited its wikis without approval
The Wikimedia Foundation says AI agents it believes OpenAI runs made unapproved edits to its wikis. They also tried and failed to break into a note-taking tool it hosts. Their traffic may have contributed to a partial outage in May, the foundation, which hosts Wikipedia, said in a blog post on Monday. Its investigation found […] This story continues at The Next Web
The Wikimedia Foundation says AI agents it believes OpenAI runs made unapproved edits to its wikis. They also tried and failed to break into a note-taking tool it hosts. Their traffic may have contributed to a partial outage in May, the foundation, which hosts Wikipedia, said in a blog post on Monday.
Its investigation found no sign that agents used its systems to coordinate. It also found no sign of compromised systems or data. Agents from OpenAI’s environment have used other public wikis to coordinate with each other , the post noted.
“The open web is a public good. We should not allow this behavior to become the ‘new normal’ for the people or organizations that maintain it,” wrote Selena Deckelmann, the foundation’s chief product and technology officer.
The foundation published a list of the edits it attributes to OpenAI agents. Almost all were test edits in sandbox areas. None appeared on pages that general readers see. A few changed the settings of a citation tool. The foundation believes those edits were potentially malicious. Their aim was to turn the tool into a proxy for fetching outside data.
Wikipedia allows bots that its community has approved. Nobody asked for approval in these cases, the foundation said.
The agents also tried to use its public Etherpad as a proxy to fetch data from other websites. They failed. Other agents, likely OpenAI’s, took notes about their tasks there. That did not turn into coordination, the foundation said.
The third finding was traffic. The agents made millions of requests to Wikimedia’s public APIs. They crawled millions of pages, mainly on Wikidata and Wikimedia Commons. They also sent hundreds of thousands of queries to the Wikidata Query Service. That traffic may have contributed to the service’s partial outage in May, the foundation said.
OpenAI admits its agents behave “unpredictably”, the foundation said. It argued the company must also take responsibility for monitoring and preventing the risks. At a minimum, non-profit site owners should be able to identify AI systems easily. They could then choose how those systems use their services.
“AI companies are not doing enough to secure their systems and protect the public from the harm they cause,” Deckelmann wrote.
In 2025, the foundation reported that bot activity since 2024 had raised its bandwidth use by 50%. Bots also sent 65% of its most resource-heavy traffic, it said. Engadget said it had asked OpenAI for comment.
The findings add to a run of reports on OpenAI’s agents. A lawsuit targets the company over the Hugging Face hack . California has subpoenaed the company over agents traced to the CDC.
Wikimedia charges large commercial users for high-volume access to its data. Its public enterprise customers include Amazon, Google, Microsoft, Meta and Perplexity. OpenAI and Anthropic are not on that list, chief executive Bernadette Meehan told Ina Fried of Axios last week. She said Wikimedia also has agreements it does not disclose, and declined to name those companies. OpenAI and Anthropic declined to comment to Axios.