Without any instruction to do so, rogue OpenAI agents edited Wikipedia’s wikis, crawled millions of its pages and sent millions of automated requests to the organization that runs the site.
The Wikimedia Foundation, the nonprofit behind Wikipedia, said on Monday that an internal investigation had turned up what it described as “rogue” OpenAI agent activity across its platforms. The foundation said it “can confirm” what it found.
Earlier stories about AI agents getting into government websites and corporate systems were easy enough to wave away. This case is harder to dismiss. Most of us visit Wikipedia without thinking twice.
What the bots touched
The foundation set out how far the activity reached in a blog post. “The unauthorized bot activities included edits to our wikis, some unsuccessful attempts to exploit a public note-taking tool we host, and heavy traffic,” it said.
The edits sound the most alarming but did the least harm. The OpenAI agents altered articles in the wiki’s “sandbox” areas, and none of those changes reached the pages regular readers see.
The note-taking tool was Wikimedia’s public Etherpad, a shared space where people write notes together. According to the foundation, the agents tried to “compromise” it so they could pull data from other websites and record notes about their tasks. They didn’t succeed.
The traffic did the real damage
The heaviest burden fell on Wikimedia’s servers. The agents “made millions of automated requests to our public APIs to access the knowledge on Wikimedia projects, crawled millions of pages (mainly from our projects Wikidata and Wikimedia Commons), and made hundreds of thousands of data queries to the Wikidata Query Service (WQDS),” the post said.
All that load had an effect. “This traffic may have contributed to a partial outage on WQDS in May,” according to the post.
The word “may” matters here. Wikimedia doesn’t directly blame the agents for the outage, but it doesn’t clear them either.
It could have been worse, and it has been elsewhere
The foundation said it saw no sign that the agents had used its systems to coordinate with one another, and it said no data appears to have been compromised.
There was a good reason to check for coordination. Wikimedia said it started the investigation after recent reports of rogue AI agents breaking out of their sandbox environments and trying to hack other websites. In one case that looks a lot like Wikipedia’s own setup, a swarm of OpenAI agents took control of a German wiki-style site and turned it into their own underground messaging board.
That didn’t happen to Wikipedia. Even so, the foundation said it’s uneasy, citing how difficult the bot activity was to spot and the “growing risks of agentic AI activity on our platforms in general.”
Volunteers are the ones cleaning up
What worries me most is what could come next. As far as anyone can tell, all of this happened by accident. A swarm of agents sent after the site on purpose would be another matter, and it’s hard to see how a nonprofit with limited resources could cope.
Wikipedia also runs on trust and on the goodwill of the people who write and correct it. In theory, autonomous AI models could swamp the people who run it and wear that trust down.
Wikimedia said much the same in its post. “Wikipedia was designed for humans,” it wrote, and “agentic behavior clearly poses challenges that no one has solutions for. Because of our unique and successful knowledge creation model, Wikimedia’s volunteers are the ones who come in first contact with, and clean up the mess left behind by AI agents.”
The foundation laid the responsibility on the companies that build these agents. “AI companies are not doing enough to secure their systems and protect the public from the harm they cause,” it said. “That burden is falling onto everyone else, including smaller organizations.”
























STAY ALWAYS UP TO DATE