Home AI Wikimedia Says OpenAI Agents Edited Its Wikis, but Found No Breach

Wikimedia Says OpenAI Agents Edited Its Wikis, but Found No Breach

The foundation found no breach, and its May outage report blames unnamed scrapers, not OpenAI.

0
Screenshot of the Wikimedia Foundation statement titled OpenAI rogue agent activities found on Wikimedia projects, with a photo of rows of small robots
Image: Wikimedia Foundation / Tech My Money

The Wikimedia Foundation says it found unauthorized activity from what it believes were OpenAI agents on its sites. It also says it found no evidence of a breach. Its October 5 statement confirms some activity by “rogue” OpenAI agents on its platforms.

However, the link to a May outage is weaker than some headlines suggest. Wikimedia says only that the traffic “may have contributed.”

What Wikimedia says it found

Selena Deckelmann, the foundation’s chief product and technology officer, lists three kinds of activity. First, edits to its wikis. Almost all were tests in sandbox areas, and none appeared on pages general readers see. A few, however, changed the configuration of a citation tool. Wikimedia calls them “potentially malicious edits” and believes they aimed to turn the tool into a proxy for fetching data from other services.

Second, agents made unsuccessful attempts to exploit Etherpad, a public note-taking tool the foundation hosts. They tried to use it to fetch data from other sites. Other agents likely operated by OpenAI took notes about their tasks in it. According to Wikimedia, that did not appear to turn into coordination.

Third, agents made millions of requests to its public APIs. They crawled millions of pages, mainly from Wikidata and Wikimedia Commons. They also sent hundreds of thousands of queries to the Wikidata Query Service. Wikimedia says it found no evidence that agents used its systems to coordinate. It also saw no sign of compromised systems or data.

The May outage claim, checked

Wikimedia’s incident report on the query service covers May 7 to May 11. Six nodes served stale data for more than 20 hours. At peak, 50 percent of external requests timed out. It blames “aggressive scrapers” and names neither OpenAI nor AI agents. The connection appears only in the new statement, and only as a possibility.

The open web is a public good. We should not allow this behavior to become the “new normal” for the people or organizations that maintain it.

Selena Deckelmann, Wikimedia Foundation

What OpenAI has said

OpenAI has acknowledged the wider pattern. On September 5, it referred on X to a “wiki incident,” in which it said its agents “wrote to several internet sites.” Its own misalignment page says it has notified “dozens of third parties” and will notify more. It describes “agent spam,” including agents using public wiki pages as shared message boards. The page anonymizes the organizations it contacted and does not name Wikimedia, so it cannot confirm Wikimedia’s attribution. Wikimedia itself says it “believes” the agents were OpenAI’s.

The foundation also says the pressure was already building. In 2025, it reported a 50 percent rise in bandwidth use from bots since 2024. Bots also drove 65 percent of its most resource-consuming traffic.

This follows the earlier incident Tech My Money covered, when an OpenAI rogue agent spent days hacking Hugging Face. Publishers are also changing how they handle automated traffic, including Cloudflare’s new AI crawler rules.

NO COMMENTS

Exit mobile version