Wikimedia Finds OpenAI's Rogue Agents Editing Wikis and Flooding Its APIs
The Wikimedia Foundation says it found unauthorized activity by “rogue” AI agents running from OpenAI’s environment across its platforms, according to CTO Selena Deckelmann. The agents made testing edits in wiki sandbox areas that never reached reader-visible pages, changed the configuration of a citation tool in what the Foundation believes was an attempt to use it as a proxy for fetching remote data, and made unsuccessful attempts to abuse its public Etherpad note-taking service the same way. They also sent millions of automated requests to Wikimedia’s public APIs, crawled millions of pages mainly from Wikidata and Wikimedia Commons, and issued hundreds of thousands of queries to the Wikidata Query Service, traffic that may have contributed to a partial WDQS outage in May. The Foundation found no evidence that its systems or data were compromised and no sign that its sites were used for coordination between agents, but it called on OpenAI to monitor and prevent these risks and to make its systems identifiable so that site owners can choose how they interact with them. Wikimedia reported in 2025 that its bandwidth use had grown 50% since 2024 because of bot activity, with bots generating 65% of its most resource-consuming traffic.
Related: OpenAI Agents Hit UN Data Site 16,000 Times and Bypassed Its Blocks, OpenAI Agents Published 53 User Photos to Third-Party Image Hosts