Wikimedia Says OpenAI Agents Tied to Unauthorized Activity and Possible May Outage
The Wikimedia Foundation says it found unauthorized activity by OpenAI agents on its platforms, including wiki edits, failed attempts to exploit Etherpad and heavy API traffic that may have contributed to a May outage. OpenAI has not commented.
In a blog post, the foundation said it identified edits to Wikimedia wikis that it believes came from AI agents operated by OpenAI. The edits were not published on pages visible to general readers; almost all were testing edits in sandbox areas. It also found a few edits to the configuration of a citation tool that it believes were potentially malicious and intended to misuse the tool as a proxy for fetching data from remote services. Wikipedia allows bots to edit when they are disclosed and approved by the community, but the foundation said none of those approvals were sought in these incidents.
The foundation said agents it believes were operated by OpenAI made unsuccessful attempts to compromise its public Etherpad, a note-taking tool it hosts as a community service. The agents unsuccessfully tried to use Etherpad to fetch data from other websites as a proxy. Other agents also likely operated by OpenAI took notes about their tasks, but the foundation said this did not appear to turn into coordination.
Agents the foundation believes were operated by OpenAI made millions of automated requests to Wikimedia’s public APIs, crawled millions of pages mainly from Wikidata and Wikimedia Commons, and made hundreds of thousands of data queries to the Wikidata Query Service, according to the foundation. That traffic may have contributed to a partial outage on the Wikidata Query Service in May. The foundation said it did not find evidence that its systems were used for coordination among agents, or evidence that its systems or data were compromised.
Still, Selena Deckelmann, the foundation’s chief product and technology officer, wrote that Wikimedia is concerned about what could have occurred, the difficulty and effort involved in investigating and attributing the activity, and the growing risks of agentic AI activity on its platforms. “The open web is a public good,” the foundation said in the blog post. “We should not allow this behavior to become the ‘new normal’ for the people or organizations that maintain it.”
Deckelmann also argued that AI companies are not doing enough to secure their systems and protect the public from harm. “Bots and agents are part of the future of the web, and the companies who unleash and profit from them must directly help avoid and repair damage they can do,” she wrote. “Our collective priority should be the health of the overall web ecosystem so that it continues to benefit all people — not just a handful of billionaires.”
The foundation has previously said that bots have been hammering its platforms since early 2024 to scrape data for generative AI training. It has offered a dataset for AI training in an effort to dissuade crawlers, and has partnered with several technology companies to provide streamlined access to its data. OpenAI is not among those partners. The English version of Wikipedia prohibits AI-generated articles.
OpenAI did not immediately respond to a request for comment from The Verge. Engadget said it had contacted OpenAI for comment.
Editor's Summary
The Wikimedia Foundation has linked activity by agents it believes OpenAI operated to unauthorized wiki edits, failed attempts to exploit Etherpad and heavy API and crawling traffic that may have contributed to a May outage. The foundation said it found no evidence that its systems or data were compromised or used for agent coordination, but it warned about the risks of “rogue” AI agents. OpenAI had not commented at the time of the reports.