The Wikimedia Foundation, the non-profit that operates Wikipedia, says autonomous AI agents linked to OpenAI made unauthorised edits on its platforms, attempted to exploit some of its tools and generated millions of automated requests to its public services, in one of the most detailed public accounts yet of AI agents operating beyond their intended limits on the open web.
The foundation disclosed its findings on 5 October. It said the agents' activity may have contributed to a partial outage of the Wikidata Query Service in May, but that it found no evidence its systems or data had been compromised.
OpenAI said it was working with the foundation to review and analyse the activity and would share relevant information as its broader investigation into what it has described as rogue agentic incidents continues.
What Wikimedia found
According to the foundation's account, the agents made unauthorised edits, which it said were tested in sandbox areas rather than published to public-facing pages, and attempted malicious modifications to the configuration of a citation tool, apparently to use it as a proxy for reaching other websites.
The agents also tried, unsuccessfully, to compromise Etherpad, a collaborative editing tool used within the Wikimedia community. They sent millions of automated requests to Wikimedia's public application programming interfaces, crawled millions of pages across Wikidata and Wikimedia Commons, and executed thousands of queries against the Wikidata Query Service, a database tool used by researchers and developers.
The foundation linked that heavy traffic to a partial outage of the query service on 13 May. It stressed that it found no evidence of its systems being used for coordinated activity among agents, and no evidence of data compromise.
But it warned that the behaviour imposes real costs on public internet infrastructure, which is often maintained by small teams and non-profit budgets. "We should not allow this behavior to become the 'new normal' for the people or organizations that maintain it," the foundation said.
Selena Deckelmann, the foundation's chief product and technology officer, was blunter about responsibility. "Bots and agents are part of the future of the web, and the companies who unleash and profit from them must directly help avoid and repair damage they can do," she said.

A pattern of incidents
The Wikimedia disclosure follows a series of reports this year describing AI agents associated with OpenAI behaving in unexpected ways on external systems.
Researchers have documented agents posting about 18,000 edits on DSEWiki, a little-used German wiki-hosting service, between May and early July. The edits included task answers and techniques for working around security checks, and many accounts carried names such as "OpenAIResearcher". OpenAI has not confirmed that the agents were its own, and said it was unable to respond meaningfully to the claims without reviewing the underlying report. One of the researchers involved said the activity appeared extremely unlikely to have been authorised by the company.
OpenAI has itself disclosed that agents in an internal evaluation accessed the open internet and exploited Hugging Face infrastructure. In Australia, a Senate inquiry has called the chief executives of OpenAI and Anthropic to appear after an experimental OpenAI agent accessed the country's Medicare health database and several government websites.



