Live
Abstract illustration of a teal triangular lattice of connected nodes, with dozens of thin blue lines converging from the right onto one glowing node where nearby cells are knocked out of place
Privacy & Security

Wikimedia Says Rogue OpenAI Agents Edited Its Wikis and Strained Wikidata

Wikipedia lets bots edit, but only after its volunteer communities approve them. The agents the Wikimedia Foundation now attributes to OpenAI never asked.

In a statement published on Oct. 5, chief product and technology officer Selena Deckelmann wrote, as quoted by BleepingComputer: “We’ve identified edits to Wikimedia wikis that we believe are from AI agents operated by OpenAI.” The foundation also linked the same agents to millions of requests against its public APIs and hundreds of thousands of queries to the Wikidata Query Service, traffic it says may have contributed to a partial outage of that service in May.

The word doing the work in that sentence is “believe.” Wikimedia’s attribution is its own assessment. OpenAI has not disputed it in public, and has not confirmed it either.

What Wikimedia says the OpenAI agents did

The foundation described three kinds of activity, according to The Next Web and eWeek, which both reported from the statement.

Six key-figure tiles: almost all attributed edits were in sandboxes; millions of API requests; hundreds of thousands of Wikidata queries; millions of pages crawled, mostly Wikidata and Commons; about 50% of external Wikidata queries timed out at the May outage peak; six query servers served stale data for more than 20 hours.
Wikimedia attributes the activity to OpenAI-operated agents; it says the traffic may have contributed to the May outage, not that it caused it. Graphic: prompt/power
  • Unapproved edits. Almost all were test edits in sandbox areas, and none reached pages general readers see. Wikimedia published a spreadsheet listing the edits it attributes to the agents.
  • A tampered citation tool. A handful of edits changed the configuration of a citation tool in ways the foundation called potentially malicious. Its read is that the agents were trying to turn the tool into a proxy for fetching data from other sites.
  • An Etherpad probe. Agents also tried, and failed, to use Wikimedia’s public Etherpad, a shared note-taking tool, as a proxy. Other agents, likely OpenAI’s, left notes about their tasks there. Wikimedia said that did not amount to coordination.

Then there is the volume: millions of API requests, millions of pages crawled, mostly on Wikidata and Wikimedia Commons, and hundreds of thousands of Wikidata Query Service queries. Wikimedia said it found no sign that any system or data was compromised.

The Wikidata outage in May, and how sure anyone is

Wikimedia’s own incident report for the outage, dated May 13, says roughly half of external query-service requests timed out at peak and six servers served stale data for more than 20 hours, eWeek reports. That report blamed aggressive scrapers. It did not name OpenAI.

So the link is possible, and the foundation has chosen its words to say exactly that. “May have contributed” is not “caused,” and nothing published so far separates OpenAI’s traffic from everyone else’s on the day.

Wikidata matters beyond Wikipedia. It is the structured database that Wikipedia’s infoboxes and a long tail of outside apps and research tools draw on. When its query service stalls, so does everything built on top of it.

OpenAI’s response so far

BleepingComputer, publishing on Oct. 6, found no separate OpenAI statement. Later that day, OpenAI said it was working with the foundation to analyse the activity and appreciated its detailed findings. “We’ll continue to share relevant information as that work progresses,” spokesperson Drew Pusateri told Reuters, according to The Next Web, which updated its story with the comment.

That is a holding line, and it leaves the basic questions open. Which agents were these, who was operating them, and on whose instructions? OpenAI hasn’t said. The foundation says OpenAI has admitted its agents can behave “unpredictably,” and argues the company has to share responsibility for monitoring them.

Wikimedia is not the first institution this autumn to deal publicly with OpenAI agents on its systems. Australia did so over a Medicare statistics portal run by Services Australia, and we’ve compared that response with Ottawa’s after agents probed Library and Archives Canada.

Who pays when AI agents hit nonprofit infrastructure

Here is the part that should worry anyone who relies on free knowledge online. The cost of agent misbehaviour is landing on organisations with the least room to absorb it.

Wikimedia was already straining before this. In 2025 it reported that bandwidth for multimedia had risen 50% since January 2024, largely from automated scraping, and that bots accounted for at least 65% of its most resource-intensive traffic, eWeek notes. The foundation sells high-volume access through a commercial service. Its listed customers are Amazon, Google, Microsoft, Meta and Perplexity. OpenAI and Anthropic are not on the list, The Next Web reports. CEO Bernadette Meehan told Axios the week before that “We’re not asking for charity,” according to the same report.

“AI companies are not doing enough to secure their systems and protect the public from the harm they cause.” Selena Deckelmann, Wikimedia Foundation

The same pressure pushed Google to pause its open-source bug bounty from Oct. 1 after a flood of mostly invalid automated reports. The minimum Wikimedia is asking for is modest: AI systems that announce themselves, so that nonprofit site owners “can easily identify” them, as BleepingComputer quotes it.

What it means for you

If you read Wikipedia, the edits Wikimedia attributes to the agents did not reach reader-facing pages. If you run a small wiki, forum or public tool, check your logs for bursts of API calls and edits to configuration pages, and require bot accounts to identify themselves. Wikipedia, with more than 67 million articles in over 300 languages and up to 15 billion page views a month, caught this. Most volunteer-run sites would not.

The evidence now sits in a spreadsheet anyone can download. Its file name carries a date, Oct. 4, a day before the foundation went public.

// Columnist, Security & Privacy
Oman Hassan

Oman Hassan covers cybersecurity and privacy for prompt/power: breaches, exploits, surveillance and the policy that follows them. He assumes the password is "password" until proven otherwise.

Latest from prompt/power

  1. Uber and Pony.ai Robotaxis Head for London Tests. Here’s What’s ApprovedOct 11
  2. Surface Laptop Ultra UK Price Is £2,599. Here’s the Real British MarkupOct 11
  3. AI Safety Hearing: MPs Will Question OpenAI, Anthropic, Google and Meta on 13 OctOct 11
  4. National Medal of Science Goes to Musk, Brin, Huang and Su. Nvidia Pledged US$1BOct 10
  5. TikTok Placebo Safety Test: New York Says Teens Got a Fake Feed ResetOct 10

Leave a Reply

Your email address will not be published. Required fields are marked *