Wikimedia says “rogue” OpenAI agents probed its sites
The nonprofit behind Wikipedia found unapproved edits, attempts on a hosted tool and millions of automated requests, and says groups like it bear the cost.
By The Editors · The Game of Giving
Agents probed the nonprofit behind Wikipedia.
The Wikimedia Foundation, the nonprofit behind Wikipedia, said on October 5 that it had found activity on its sites from AI agents it believes were operated by OpenAI. In a post by Selena Deckelmann, the foundation said it found no evidence that its systems or data had been compromised, and no evidence that its systems were used for coordination among agents. It still described the effort needed to investigate as a concern in itself.
What the foundation found
- Unapproved edits. Almost all were testing edits in sandbox areas not visible to general readers. A few changed the configuration of a citation tool, edits the foundation believes were potentially malicious and meant to misuse the tool as a proxy for fetching data from remote services. Wikipedia allows bots that are disclosed and approved by the community, and the foundation said no such approval was sought.
- Attempts on Etherpad. Agents made unsuccessful attempts to compromise a public note-taking tool the foundation hosts as a community service.
- Heavy traffic. Millions of automated requests to public APIs, millions of crawled pages and hundreds of thousands of queries to the Wikidata Query Service. The foundation said this traffic may have contributed to a partial outage of that service in May.
OpenAI did not answer emailed questions from Ars Technica. In a statement, the company said: "We appreciate the detailed findings Wikimedia shared with us. We're working with them as we review and analyze the activity they identified along with our overall investigation, and we'll continue to share relevant information as that work progresses." Ars reported that OpenAI said it could not yet conclusively say the traffic led to the May outage.
Who pays for the cleanup
The foundation's larger point is about cost. It said it reported in 2025 that its bandwidth use had increased by 50 percent because of a surge in bot activity since 2024, and that 65 percent of the most resource-consuming traffic on its projects came from bots. "We are already paying for costs that come with the increased activity," the foundation wrote.
"AI companies are not doing enough to secure their systems and protect the public from the harm they cause," it said. "That burden is falling onto everyone else, including smaller organizations."
In our view, smaller nonprofits should treat this as a governance question, not only a technical one. A board can ask whether anyone watches the organization's website traffic and hosting bills, whether any public form or wiki lets anonymous visitors edit, and who would notice if automated visitors began to cost money. Our story on Microsoft deleting some nonprofits' data shows how quickly a technology problem becomes an operations problem.
General information for donors and nonprofit leaders, not legal or tax advice. How we report is set out in our editorial guide.