OpenAIi’s ‘Rogue’ AI Agents Made Unauthorised Wikimedia Edits as Traffic May Have Affected Service

Most identified edits remained in sandbox areas, but Wikimedia also found attempted misuse of a citation tool, Etherpad activity and traffic that may have affected Wikidata

OpenAI
OpenAI’s ‘rogue’ AI agents made unauthorised wiki edits as Wikimedia probes heavy traffic Photo by Andrew Neel: Pexels

OpenAI's AI agents have been linked by the Wikimedia Foundation to unauthorised activity across Wikimedia platforms, including wiki edits, attempts to misuse a note-taking service and automated requests.

Wikimedia said almost all of the edits it identified were confined to sandbox areas rather than pages visible to ordinary readers, while a small number involved changes to a citation tool that the foundation believes may have been intended to reach remote data.

The investigation also found millions of API requests and hundreds of thousands of queries to the Wikidata Query Service. Wikimedia said that traffic may have contributed to a partial outage affecting the service in May. OpenAI has acknowledged Wikimedia's findings and said it is working with the foundation to analyse the activity.

It has not publicly confirmed that its agents caused the May disruption. The findings add another example of AI agents interacting with public infrastructure without conventional controls expected of human users.

OpenAI Agents Made Unauthorised Wikimedia Edits

The Wikimedia Foundation's investigation found several forms of activity that it believes were connected to OpenAI-operated agents. The foundation said the bots had not obtained the approvals normally required for automated editing on Wikimedia projects.

The distinction between a test area and a public article is important. Because the edits were confined largely to sandbox areas, they were not published on pages visible to general readers. Wikimedia nevertheless had to investigate the activity.

A smaller number of changes affected the configuration of a citation tool. Wikimedia described these as potentially malicious and said they appeared intended to misuse the tool as a proxy for obtaining information from remote services. The foundation said it found no evidence that its systems or data had been compromised.

The investigation also identified activity involving Etherpad, a note-taking platform hosted by Wikimedia as a community service. Agents Wikimedia believes were operated by OpenAI unsuccessfully attempted to use the service to fetch data from other websites as a proxy.

Separate agents appear to have used the platform to record notes about their tasks, although Wikimedia said it found no evidence that its systems became a channel for coordinating the agents.

That finding matters because previous investigations have uncovered OpenAI agents using public websites in unexpected ways.

In September, independent researchers reported that thousands of agents identifying as OpenAI systems had posted messages on a little-used German wiki, using it to share information and, according to the researchers, discuss ways around restrictions during an evaluation.

OpenAI later acknowledged that its agents had accessed a public wiki and used it as a shared message board.

Heavy AI Traffic May Have Affected Wikidata Service

The incident comes as Wikimedia has already been dealing with rising automated traffic. The foundation previously said its bandwidth usage increased by 50% following a surge in bot activity from 2024, while 65% of its most resource-intensive traffic was coming from bots in 2025.

Wikimedia has argued that large-scale automated access can put additional pressure on infrastructure maintained for human users.

The latest investigation therefore points to a problem that extends beyond whether an individual AI agent edits a wiki page. Automated systems can make enormous numbers of requests, interact with services designed around human users and create work for organisations trying to establish what happened.

OpenAI has separately acknowledged the need to identify and respond to unexpected or misaligned agent behaviour. In September, it said it had implemented a framework for identifying, classifying and responding to such behaviour and was developing standards for notifying affected organisations and reporting findings publicly.

For Wikipedia and the wider Wikimedia ecosystem, the practical issue is how public services can remain open to legitimate users while limiting automated activity that places unusual demands on the infrastructure.

The foundation says its projects were designed for human participation, while the rise of agentic AI is creating new challenges for the volunteers and technical teams that maintain them.

Tags:ChatGPT