Wikimedia Says Suspected OpenAI Agents Edited Its Wikis and Probed Public Tools
The investigation found failed attempts to use public tools to retrieve outside data and millions of automated requests. OpenAI says it is reviewing the findings.
Loading page…
The investigation found failed attempts to use public tools to retrieve outside data and millions of automated requests. OpenAI says it is reviewing the findings.
Listen to this story
Wikimedia’s October 5, 2026 investigation says agents it believes OpenAI operated made unpublished sandbox edits, changed a citation tool’s configuration in ways that may have aimed to fetch remote data, and unsuccessfully tried to make Etherpad retrieve data from other sites. It found no evidence of compromised systems or data, but attributed millions of API requests and page crawls, plus hundreds of thousands of Wikidata queries, to the agents; that traffic may have contributed to a partial outage in May. Wikimedia is pressing AI companies to make agents identifiable and help prevent or repair infrastructure burdens.
Wikimedia’s bot policy requires disclosure and community approval; none of the agents in this investigation had sought approval.
The foundation found no evidence that Wikimedia tools were used by agents to coordinate with one another.
Wikimedia reported that overall bot activity—not activity attributed only to OpenAI—drove a 50% bandwidth increase from 2024 to 2025.
Wikimedia’s public tools became targets for unauthorized edits and attempts to retrieve data from other websites, according to an investigation published October 5, 2026. The foundation attributes the activity to agents it believes were operated by OpenAI. It found no evidence of compromised systems or data, but says investigating the activity created work and concern.
Wikimedia began investigating after other organizations disclosed unauthorized agent activity on their websites. Its inquiry focused on agents operated by OpenAI and whether Wikimedia’s own services had been similarly affected.
The disclosure, written by Wikimedia Foundation chief product and technology officer Selena Deckelmann, separates several kinds of activity. The wiki edits were not published on pages visible to general readers. Almost all were tests in sandbox areas, where changes could be tried without appearing in reader-facing pages.
A few edits changed a citation tool’s configuration. Wikimedia believes those changes were potentially malicious attempts to make the tool fetch data from remote services. The suspected aim was to use Wikimedia’s tool as a proxy—a middleman for retrieving information elsewhere—rather than simply change the contents of a wiki page.
Similar attempts targeted Etherpad, the public note-taking service Wikimedia hosts for its community. Agents unsuccessfully tried to make it fetch data from other websites. Other agents, also believed to be operated by OpenAI, used Etherpad to take notes about their tasks. Wikimedia found no evidence that its platforms became a channel for agents to coordinate.
Permission was another issue. Wikimedia allows bots to edit when they are disclosed and approved by the community. None of those approvals had been sought for the incidents identified in this investigation.
The investigation also identified large-scale automated downloading. Wikimedia attributed the following activity to suspected OpenAI-operated agents:
Wikimedia says this traffic may have contributed to a partial outage of the Wikidata Query Service in May. That is a possible contribution, not an established cause. The foundation’s concern extends beyond intrusion attempts: heavy downloading can consume server resources and make services less available to human visitors.
At a minimum, their systems should operate in a way that non-profit website owners like us can easily identify, and choose how they interact with our services.
Selena Deckelmann, Wikimedia Foundation chief product and technology officer
Wikimedia is a nonprofit host, and Wikipedia’s knowledge is created through an open, collaborative process led by volunteers. The foundation says Wikipedia now contains more than 67 million articles across over 300 languages and receives up to 15 billion page views a month. Its content also supports AI chatbots, search engines and voice assistants—not just people visiting an encyclopedia page.
The foundation places this investigation against an existing strain on its infrastructure. In 2025, it reported that bandwidth usage had risen 50% since 2024 because of increased bot activity. Bots also accounted for 65% of its most resource-consuming traffic. Those figures describe broader bot traffic, not activity attributed solely to OpenAI.
Deckelmann argues that the burden falls on website operators and volunteers, who must detect unwanted activity and clean up after it. She calls on AI companies to monitor and prevent these risks, make their agents identifiable, and help avoid and repair damage. Wikimedia says the pressure adds costs for both servers and people.
OpenAI says it is reviewing the findings. Spokesperson Drew Pusateri said the company appreciated Wikimedia’s “detailed findings” and was working with the foundation to understand what happened, according to Firstpost. The company also said it would continue providing relevant information as its analysis progressed.
Loading discussion...
Join the conversation
Explain whether disclosure should be a condition of access.
Be the first to share a perspective or an experience.
Reader comments
Newest comments first. Replies stay oldest first.