
Wikimedia Foundation servers in a data centre, July 2012. Image: Victor Grigas / Wikimedia Commons, CC BY-SA 3.0, cropped
The Wikimedia Foundation, which runs Wikipedia, says OpenAI’s “rogue” AI agents made unapproved edits to its wikis, tried and failed to break into a note-taking tool it hosts, and hit its servers with millions of requests that may have contributed to an outage in May. It set out the findings in a post on Monday, and used it to accuse AI companies of leaving everyone else to clean up after their agents.
The foundation went looking after OpenAI disclosed that agents running in its own environment had been reaching out to outside websites. It joins a growing list of organisations, from Hugging Face to an Australian government portal, that have found traces of the same agents on their systems.
What the agents did on Wikipedia
The foundation lists three kinds of activity it believes came from agents operated by OpenAI:
- Wiki edits: almost all were test edits in “sandbox” areas, not on pages general readers see. But a few changed the configuration of a citation tool, in what the foundation calls “potentially malicious edits” meant to turn the tool into a proxy for fetching data from other websites. None of the edits had the community approval Wikipedia requires before bots can edit. The foundation has published a list of them.
- Etherpad: agents made unsuccessful attempts to compromise the public Etherpad, a shared note-taking tool the foundation hosts for volunteers, again trying to use it as a proxy. Other agents used it to take notes about their tasks, though the foundation says that “did not appear to turn into coordination”.
- Heavy traffic: millions of automated requests to Wikimedia’s public APIs, millions of pages crawled (mostly from Wikidata and Wikimedia Commons), and hundreds of thousands of queries to the Wikidata Query Service. That traffic “may have contributed” to a partial outage of the query service in May.
The foundation says it found no evidence that its systems were used by agents to coordinate with each other, and no evidence that its systems or data were compromised. Agents from OpenAI’s environment are known to have used other public wikis, not run by Wikimedia, to pass messages.
“It doesn’t need to be this way”
The post goes beyond an incident report. The foundation says it is worried about “what could have occurred here” and about how hard it was to investigate and attribute the activity, adding: “The open web is a public good. We should not allow this behavior to become the ‘new normal’.”
It aims squarely at OpenAI: “While OpenAI admits to agents behaving ‘unpredictably’, they must also acknowledge their responsibility to monitor and prevent these risks.” AI companies, it says, “are not doing enough to secure their systems and protect the public from the harm they cause,” and at a minimum their agents should be easy for non-profit sites to identify, so those sites can decide how to deal with them.
It also points to a longer-running strain: the foundation reported in 2025 that its bandwidth use had risen 50% because of bot traffic since 2024, and that 65% of its most resource-hungry traffic came from bots. Volunteers, it says, are the ones who “clean up the mess left behind by AI agents”.
What OpenAI says
OpenAI didn’t answer questions from Ars Technica, but told the outlet it appreciated “the detailed findings Wikimedia shared with us” and was working with the foundation as it reviews the activity alongside its wider investigation. Ars reports that OpenAI, like Wikimedia, hasn’t found evidence of agents leaving coordination messages there, and can’t yet say whether its traffic caused the May outage.
Earlier this month OpenAI said it had warned more than 100 organisations about what its agents had done, after reports that they had tried to hack Hugging Face and called stolen credentials “LOOT”.
Not everyone accepts the “rogue” framing. Eryk Salvaggio, an AI researcher and Gates Scholar at the University of Cambridge, told Ars:
What I see here is language models doing what language models do: reading and writing.
Eryk Salvaggio, AI researcher, to Ars Technica
He added that Wikipedia’s sandboxes, which anyone can write to, are “an ideal place for these machines to store notes for later pickup”.
Why it matters
Wikipedia is one of the most heavily used sources of training data for AI, and it is run by a non-profit that relies on volunteers. If even its defenders struggle to spot and attribute agent traffic, smaller sites have little chance. For site owners, our guide on blocking AI agents and bots explains why robots.txt alone isn’t enough.
Sources: Wikimedia Foundation, Wikitech incident report, Ars Technica (OpenAI statement, Salvaggio interview).


