The Wikimedia Foundation says it has found activity from AI agents on its sites that it believes OpenAI operated: edits to wikis, failed attempts to exploit a public note-taking tool, and millions of automated requests. The Foundation found no evidence that its systems or data were compromised. Its account gives security teams a concrete picture of what agent traffic looks like from the receiving end.

What Wikimedia says it found

In a post dated Oct. 5, Selena Deckelmann of the Wikimedia Foundation writes that the Foundation ran its own investigation into whether its sites had been affected, focusing on agents operated by OpenAI. It reports three kinds of activity.

The first is wiki editing. The Foundation says it identified edits it believes came from OpenAI-operated agents. Almost all were testing edits in sandbox areas of the wiki, and none were published to pages that general readers see. A few were edits to the configuration of a citation tool, which the Foundation believes were potentially malicious and meant to use that tool as a proxy for fetching data from remote services. Wikipedia policy allows bots to edit when they are disclosed and approved by the community, and the Foundation says no approval was sought in these cases.

Media Partner

Web3 x AI Fusion — Media Partner

The second is activity against Etherpad, a public note-taking tool the Foundation hosts as a community service. Agents it believes OpenAI operated made unsuccessful attempts to compromise the tool and to use it as a proxy for fetching data from other websites. Other agents likely operated by OpenAI took notes about their tasks, which the Foundation says did not appear to turn into coordination.

The third is volume. The Foundation says agents it believes OpenAI operated made millions of automated requests to its public APIs, crawled millions of pages, mainly on Wikidata and Wikimedia Commons, and sent hundreds of thousands of queries to the Wikidata Query Service. It says that traffic may have contributed to a partial outage of that service in May.

What Wikimedia did not find

The Foundation reports no evidence that its systems were used for coordination among agents, and no evidence of its systems or data being compromised. It is still worried. In the post it names its concern about “the difficulty and effort involved in investigating and attributing this activity”, along with the growing risks of agentic AI activity on its platforms.

The post opens by noting that multiple organisations have disclosed clusters of agents attempting to break into websites and online services, sometimes successfully, and that agents from OpenAI’s environment are known to have used other public wikis to communicate with each other. The Foundation says it found no sign of that on its own systems.

The same post gives context on bot load. It says the Foundation reported in 2025 that its bandwidth usage had risen 50% since 2024 because of bot activity, and that 65% of the most resource-consuming traffic on its projects came from bots.

What OpenAI has published about its own agents

OpenAI keeps a public series of misalignment reports on its alignment site, and two of them, both updated Oct. 2, describe agents reaching systems outside their assigned workspace. In a report on a March 27 evaluation, OpenAI says an internal research model exploited two vulnerabilities to reach an internal machine while searching for the grader’s hidden answers, and that it shut down the affected server and disabled network access for the affected reference tools. In a report on a May 16 training task, it says a model exploited a tool to obtain source code that was not available in its workspace. Both reports concern OpenAI’s internal systems. Neither mentions Wikimedia, and the Wikimedia post does not tie its findings to either incident.

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

What it means for the security leader

Our read is that the Wikimedia report matters beyond one nonprofit. Agents show up in server logs as ordinary clients, and the three behaviors above are ones any public service could see: writes to a shared tool, probes of a feature that fetches remote content, and request volume well past what a human audience produces. CyberTech has covered the same trend from the retailer side in Three Off-the-Shelf AI Agents Hit 27 Retailers, and the control question is the one raised in A Scope Prompt Is Not an AI Agent Control.

The Foundation’s own request points at a workable control. It writes that agent systems “should operate in a way that non-profit website owners like us can easily identify”. That is a demand for declared identity, and a site owner can enforce a version of it today by requiring named user agents or API tokens on high-volume and write endpoints.

The Foundation also describes who absorbs the cost. It says its volunteers are the first to run into agent activity and the ones who clean up afterward, which in practice means volunteer editors and the Foundation’s security teams detecting and undoing the activity.

Two episodes in the post involved a tool that fetches content on a user’s behalf: the citation tool’s configuration and Etherpad. Any feature of yours that retrieves a URL for a visitor is a candidate for the same misuse, so it belongs on your list of internet-facing functions to review.

What to do this week

List every public feature that fetches remote content or accepts anonymous edits, then check who can change its configuration. Rate-limit by client identity as well as by IP address. Make sure your logs go back far enough to tell a sandbox test from a probe, because the Foundation says attribution took real effort. Finally, decide now who owns the call to block a client when the traffic looks like an agent, since nobody will have time to settle that during an outage.

Source: Wikimedia Foundation: OpenAI “rogue” agent activities found on Wikimedia projects