Rogue OpenAI agents made unauthorized Wikipedia edits and millions of requests to Wikimedia
Rogue OpenAI agents made unauthorized edits on Wikimedia wikis and sent millions of automated requests to Wikimedia’s public APIs, traffic that may have contributed to a partial outage of the Wikidata Query Service in May, the Wikimedia Foundation said on Monday.

“The Wikimedia Foundation conducted its own investigation to see whether Wikimedia websites had been similarly affected by AI agents, focusing on those operated by OpenAI,” wrote Selena Deckelmann, Wikimedia Chief Product and Technology Officer.
“We can confirm that we have discovered some activity by these ‘rogue’ OpenAI agents on Wikimedia platforms,” added Deckelmann.
According to Deckelmann, Wikipedia hosts 67 million articles in more than 300 languages, and up to 15 billion page views per month.
Sandbox edits and a citation tool
Wikimedia identified edits to its wikis that it believes came from OpenAI agents. The edits did not appear on pages general readers see, and almost all of them were test edits in “sandbox” areas of the wikis.
“While Wikipedia policies allow bots to edit when they are disclosed and approved by the community, none of those approvals were sought in these incidents.”
A few of the edits targeted the configuration of a citation tool. Wikimedia described them as “potentially malicious edits” and believes they were meant to misuse the tool as a proxy for fetching data from remote services.
Agents tried, without success, to use Etherpad, a public note-taking tool Wikimedia hosts, as a proxy to fetch data from other websites. Other agents likely run by OpenAI used it to take notes about their tasks.
Wikimedia found no evidence that its systems were used for coordination among agents, and no evidence that its systems or data were compromised.
Millions of requests and a May outage
Wikimedia said OpenAI agents made millions of automated requests to its public APIs and crawled millions of pages, mostly on Wikidata and Wikimedia Commons.
They also sent hundreds of thousands of queries to the Wikidata Query Service, traffic that may have contributed to a partial outage of the service in May 2026.
Concerns for open knowledge sites
Deckelmann is “deeply concerned” about the effects rogue AI agents could have on open knowledge platforms.
“Wikipedia was designed for humans – and agentic behavior clearly poses challenges that no one has solutions for,” she noted.
“This intense pressure on our infrastructure not only adds costs for servers and humans, but if left unaddressed, can block human visitors by overloading systems and causing outages. We are already paying for costs that come with the increased activity.”
Wikimedia remains concerned about what could have happened here and about the effort it took to investigate and attribute the activity. It warned of growing risks from AI agent activity on its platforms.
“The open web is a public good. We should not allow this behavior to become the ‘new normal’ for the people or organizations that maintain it,” Deckelmann warned.
She added that while OpenAI admits its agents behaved unpredictably, the company must also take responsibility for monitoring and preventing these risks, and that AI companies are not doing enough to secure their systems and protect the public from the harm they cause.
“That burden is falling onto everyone else, including smaller organizations. At a minimum, their systems should operate in a way that non-profit website owners like us can easily identify, and choose how they interact with our services,” concluded Deckelmann.