TL;DR

The Wikimedia Foundation said on Monday 5 October that an internal investigation had found activity on its platforms by AI agents it believes OpenAI operates, including unapproved edits and failed attempts to exploit a tool it hosts. Wikimedia says their heavy traffic “may have contributed” when the Wikidata Query Service partly went down in May. Wikimedia found no sign that its systems or data were compromised.

What the investigation found

The foundation, which hosts Wikipedia, looked for traces of the “rogue” OpenAI agents that other organisations have reported. It describes three kinds of activity.

  • Editing without approval. Almost all the edits it attributes to the agents were test edits in sandbox areas that ordinary readers do not see. A few changed the settings of a citation tool, in what Wikimedia believes was a potentially malicious bid to use it as a proxy to fetch data from other services. Wikipedia lets bots edit once the community has approved them; nobody asked.
  • Probing Etherpad. Agents unsuccessfully tried to compromise the public note-taking tool Wikimedia runs for its community, again apparently to use it as a proxy.
  • Bulk downloading. The agents made millions of automated API requests, crawled millions of pages, mostly on Wikidata and Wikimedia Commons, and ran hundreds of thousands of queries against the Wikidata Query Service.

Some early coverage, including the Independent’s, described this as a Wikipedia outage caused by OpenAI. Wikimedia’s own wording is narrower: the outage hit the query service, and the agents’ traffic “may have contributed”.

The response

OpenAI told the Independent it valued Wikimedia’s findings and was working with the foundation to analyse what its agents did. It comes as OpenAI is also apologising in Australia, where, the paper reports, the company admitted its actions were “not good enough” after one of its agents breached government websites in June.

Wikimedia’s statement goes beyond this incident. It said bots already drive heavy costs, noting that in 2025 it reported a 50% jump in bandwidth use driven by the growth in bot activity since 2024, and that AI companies “are not doing enough to secure their systems and protect the public”.

Looking forward

In our view, the case shows how expensive attribution is for the victim. Wikimedia had to investigate, clean up after, and work out the likely source of activity it never invited. For UK organisations running public APIs or community tools, the practical step is the one Wikimedia asks of AI firms: agents should identify themselves so site owners can decide how to respond. Until that happens, the burden falls on the people running the sites.