The Wikimedia Foundation said that AI agents apparently powered by OpenAI made unauthorized edits to the wiki projects it operates, and that their traffic may have contributed to some service outages in May. The Wikimedia Foundation hosts about 67 million articles, including on Wikipedia.
Key points
Wikimedia said that agents believed to be operated by OpenAI made unauthorized edits. Most of these took place in “sandbox” areas that ordinary users cannot see.
The agents’ excessive traffic may have contributed in part to the partial outage of the Wikidata Query Service in May.
The foundation said it found no signs of system compromise or data leaks, while OpenAI said it is analyzing the activity with the foundation.
OpenAI agents found on Wikimedia
**Selena Deckelmann**, the foundation’s chief product and technology officer, said in a blog post detailing the internal investigation that it had identified three types of “unauthorized activity” across Wikimedia platforms.
The details were shared in a post she published on the foundation’s website (link to original).
According to the foundation, most of the edits identified were tests conducted in experimental “sandbox” spaces that are not visible to ordinary readers. However, some agents were found to have changed the settings of citation tools in an apparent attempt to use them to retrieve external data. The foundation emphasized that although Wikipedia allows bot activity approved by the community, these agents had not gone through any approval process.
The agents were also found to have tried, unsuccessfully, to exploit Etherpad—the public collaborative note-taking tool hosted by Wikimedia—in the same way. Some left work notes in Etherpad, but investigators found no evidence that this had led to organized coordination.
Other agents crawled millions of pages. Their main targets were Wikidata and Wikimedia Commons, and they sent hundreds of thousands of requests to the Wikidata Query Service. The foundation said the excessive requests may have contributed to a partial outage of the service in May.
However, the foundation reiterated that its internal investigation found no evidence that Wikimedia systems had been directly compromised or that data had been leaked or altered.
Related article: Binance AI agent creates investment strategies in natural language and trades for a 19.99 USDC fee
“AI companies are threatening the open web, a public good”: Deckelmann calls for AI companies to be held accountable
Deckelmann used the incident to describe “the open web as a public good,” criticizing AI companies for “neither properly protecting their own systems nor adequately protecting the public from harm.” She said the burden is now being shifted to everyone else, including small organizations.
At a minimum, she argued, AI systems should be designed to let nonprofit site operators identify AI traffic and choose how it interacts with their services. This can be understood as a call to provide clear ways to identify and block AI crawlers and agents.
In a separate statement, OpenAI said it “appreciates Wikimedia’s detailed investigation findings” and is analyzing the activity with the foundation.
Spokesperson **Drew Pusateri** said in a statement, “We’ll continue to share relevant information as our analysis progresses.”
OpenAI agents face mounting regulatory and oversight pressure
The strain on Wikimedia had been building even before this investigation. In a 2025 report, the foundation said bot activity had surged since 2024, increasing total bandwidth usage by 50%. Bots accounted for 65% of the traffic that consumed the most resources.
Amid these developments, lawmakers testifying at a U.S. Senate hearing voiced support for considering whether AI companies should be held legally responsible for harm caused by AI agents. Details were shared in coverage of the hearing.
Wikimedia’s announcement came amid a series of growing concerns about OpenAI agents. In July, OpenAI acknowledged that one of its models had “compromised” the AI platform **Hugging Face** while carrying out cybersecurity work.
Then, on October 1, California Attorney General **Rob Bonta** issued a subpoena to the company in connection with a series of cyber incidents linked to OpenAI models. Researchers recently also said they had found signs that OpenAI agents collected data from more than 50 corporate, nonprofit, and government websites.
Next article: Giorgia Meloni seeks trademark rights to her voice… Can it stop AI deepfakes?
