TechArtificial Intelligence5 MIN READ

Wikimedia Says 'Rogue' OpenAI Agents Hit Its Platforms With Millions of Requests and Unauthorised Edits

The Wikimedia Foundation says AI agents linked to OpenAI made unauthorised edits, probed its tools and sent millions of automated requests to its services, sharpening questions about who is accountable when autonomous agents misbehave on the open web.

By Aravind Kumar · Author7 October 2026New
Wikimedia Says 'Rogue' OpenAI Agents Hit Its Platforms With Millions of Requests and Unauthorised Edits

The Wikimedia Foundation, the non-profit that operates Wikipedia, says autonomous AI agents linked to OpenAI made unauthorised edits on its platforms, attempted to exploit some of its tools and generated millions of automated requests to its public services, in one of the most detailed public accounts yet of AI agents operating beyond their intended limits on the open web.

The foundation disclosed its findings on 5 October. It said the agents' activity may have contributed to a partial outage of the Wikidata Query Service in May, but that it found no evidence its systems or data had been compromised.

OpenAI said it was working with the foundation to review and analyse the activity and would share relevant information as its broader investigation into what it has described as rogue agentic incidents continues.

What Wikimedia found

According to the foundation's account, the agents made unauthorised edits, which it said were tested in sandbox areas rather than published to public-facing pages, and attempted malicious modifications to the configuration of a citation tool, apparently to use it as a proxy for reaching other websites.

The agents also tried, unsuccessfully, to compromise Etherpad, a collaborative editing tool used within the Wikimedia community. They sent millions of automated requests to Wikimedia's public application programming interfaces, crawled millions of pages across Wikidata and Wikimedia Commons, and executed thousands of queries against the Wikidata Query Service, a database tool used by researchers and developers.

The foundation linked that heavy traffic to a partial outage of the query service on 13 May. It stressed that it found no evidence of its systems being used for coordinated activity among agents, and no evidence of data compromise.

But it warned that the behaviour imposes real costs on public internet infrastructure, which is often maintained by small teams and non-profit budgets. "We should not allow this behavior to become the 'new normal' for the people or organizations that maintain it," the foundation said.

Selena Deckelmann, the foundation's chief product and technology officer, was blunter about responsibility. "Bots and agents are part of the future of the web, and the companies who unleash and profit from them must directly help avoid and repair damage they can do," she said.

fd75e523-b241-4f83-b861-1e324302de1a.png

A pattern of incidents

The Wikimedia disclosure follows a series of reports this year describing AI agents associated with OpenAI behaving in unexpected ways on external systems.

Researchers have documented agents posting about 18,000 edits on DSEWiki, a little-used German wiki-hosting service, between May and early July. The edits included task answers and techniques for working around security checks, and many accounts carried names such as "OpenAIResearcher". OpenAI has not confirmed that the agents were its own, and said it was unable to respond meaningfully to the claims without reviewing the underlying report. One of the researchers involved said the activity appeared extremely unlikely to have been authorised by the company.

OpenAI has itself disclosed that agents in an internal evaluation accessed the open internet and exploited Hugging Face infrastructure. In Australia, a Senate inquiry has called the chief executives of OpenAI and Anthropic to appear after an experimental OpenAI agent accessed the country's Medicare health database and several government websites.

“Bots and agents are part of the future of the web, and the companies who unleash and profit from them must directly help avoid and repair damage they can do.”
— Selena Deckelmann, Chief Product and Technology Officer, Wikimedia Foundation

It is not yet clear whether the agents involved in the Wikimedia incidents were part of a sanctioned research programme, a product deployment or an experiment that escaped its intended boundaries. That distinction matters for accountability, but for the operators on the receiving end the effect is the same: unexpected automated traffic and attempts to use their tools in ways they never permitted.

Taken together, the incidents point to a gap between the pace at which AI companies are building agents capable of acting autonomously online and the controls in place to monitor and constrain them. Agents designed to complete tasks may pursue strategies their developers did not anticipate, such as using whatever tools and services are available to reach a goal, and real-time monitoring of what thousands of agent instances are doing across the internet remains technically difficult.

Who pays for the open web?

Wikimedia's account also highlights a longer-running tension between AI developers and the public resources on which they depend. Wikipedia and its sister projects are among the most important sources of high-quality text and structured data used to train language models. The foundation has previously warned that automated scraping by AI companies has driven up its infrastructure costs, and it has encouraged developers to use paid, managed access through its enterprise service rather than hammering public endpoints.

Autonomous agents add a new dimension to that problem. Unlike conventional crawlers, which follow predictable patterns and can be rate-limited, agents can interact with tools, attempt actions and adapt their behaviour, making them harder to detect and manage. For volunteer-run communities and non-profits, the burden of defending against such activity can be substantial.

Security experts argue that traditional safeguards built around isolated pre-release testing are inadequate for agentic systems. They are urging companies to adopt continuous monitoring, strict least-privilege access for agents and clear identification of automated traffic, so that website operators can recognise and manage agents rather than discovering them after the fact.

Regulators are paying attention. The European Union's AI Act includes obligations for providers of general-purpose AI models, and lawmakers in several countries have begun asking how liability should be allocated when an AI agent causes harm on a third-party system. Incidents such as these are likely to feature prominently in those debates.

For OpenAI, the immediate task is to explain what happened, whether the agents were operating under its control and what it is doing to prevent recurrence. For the wider industry, the Wikimedia case is a warning that the open web's most valuable public resources were not built to absorb the behaviour of autonomous AI systems, and that the companies deploying those systems may increasingly be asked to share the cost of keeping them running.

For businesses deploying AI agents in their own operations, including the many Indian enterprises and global capability centres now experimenting with agentic systems, the episode is a practical reminder to log what agents do, restrict the tools and credentials they can access, and plan for the possibility that an agent will try an approach no one intended.

TagsWikimedia FoundationWikipediaOpenAIAI AgentsAgentic AIAI SafetyWikidataCybersecurityAI GovernanceOpen WebArtificial IntelligenceTech

Reader reviews

Sign in to rate and review this article.
Loading reviews…