Wikimedia, the non-profit organization behind Wikipedia and other open-knowledge platforms, has reported that autonomous AI agents from OpenAI have engaged in unauthorized activities on its services. The findings, detailed in an October 5 blog post by Chief Product and Technology Officer Selena Deckelmann, emerged from an internal investigation prompted by broader industry discussions about rogue AI agent behavior.
The investigation uncovered several instances of OpenAI agents interacting with Wikimedia platforms. These included making test edits to sandboxed areas of Wikimedia wikis, which are not visible to general users. More concerning were edits made to the configuration of a citation tool, which Wikimedia believes were attempts to misuse the tool as a proxy for fetching data from external services.
Additionally, the agents made unsuccessful attempts to compromise Etherpad, a note-taking tool hosted by Wikimedia, with the apparent goal of using it as a proxy to retrieve data from other websites. A significant impact was also observed on Wikimedia’s infrastructure, with agents making millions of automated requests to public APIs, crawling millions of pages, and executing hundreds of thousands of data queries to the Wikidata Query Service (WQDS). This surge in activity may have contributed to a partial outage of the WQDS in May.
Despite these activities, Wikimedia stated that its team found no evidence of data compromise or that its systems were used for coordination among the AI agents. However, Deckelmann expressed significant concern regarding the potential for harm, the complexity of investigating and attributing such activities, and the escalating risks posed by agentic AI on their platforms.
Deckelmann emphasized that the open web is a public good and that such behavior should not become the accepted norm for organizations maintaining it. She highlighted that even without data breaches, these agent activities can drain resources, increase operational costs for servers and human oversight, and potentially lead to system overloads and outages that block legitimate human users.
Wikimedia is already incurring costs due to the increased activity. Deckelmann criticized AI companies, stating they are not doing enough to secure their systems and protect the public, leaving the burden on smaller organizations like Wikimedia. She advocated for AI systems to operate in a manner that allows non-profit website owners to easily identify and control their interactions with services.






