Wikimedia says OpenAI-linked agents hit its servers and tried to exploit its tools
The nonprofit says agents made unauthorised edits and millions of requests, with a possible link to a May service outage. It wants AI companies to make their automated visitors identifiable and let website owners choose how they interact.
The Wikimedia Foundation says AI agents it believes OpenAI operates sent millions of requests to its servers, made unauthorised wiki edits and tried unsuccessfully to exploit a public note-taking tool. Some of the traffic may have contributed to a May outage of its Wikidata Query Service, where more than half of requests were timing out at the peak, according to findings the nonprofit published on October 5, 2026. [2][3]
The foundation is asking AI companies to make their systems identifiable to website owners and give those owners a say over how they interact with their services. Selena Deckelmann, Wikimedia's chief product and technology officer, said companies are not doing enough to secure their agents, leaving other organisations to deal with the harm they cause. [2]
The allegations have not been confirmed independently. Attribution rests on Wikimedia's own assessment, and the available findings do not establish which technical signatures identified the agents or what share of the May outage traffic they generated. Wikimedia said the traffic may have contributed to the outage, not that OpenAI caused it. OpenAI did not respond to requests for comment from The Verge and Engadget. [1][2][6]
Wikimedia found no evidence that its systems or data were compromised, or that agents used its platforms to coordinate with one another. Almost all the wiki edits were tests in sandbox areas, invisible to general readers. The foundation's allegations concern those unapproved edits, attempts to misuse its tools and extensive automated downloading. [2]
Wikipedia has more than 67 million articles in over 300 languages and receives up to 15 billion page views a month. It is also one of the most-used datasets for training large language models. Deckelmann described the open web as a public good and said this behaviour should not become the "new normal" for the people and organisations maintaining it. [2][3]
The edits and the attempted exploits
Deckelmann's account divided the activity into three categories: unauthorised wiki editing, probing of Etherpad and excessive automated data downloading. None of the automated editing sought or received the community approval required under Wikipedia's bot policies. [2][4]
Those policies assume a human operator who seeks approval before deploying automated editing tools. According to the foundation, the agents carried out their edits without going through that process. Most of the changes stayed in sandbox areas, where test edits would not be visible to people reading encyclopedia articles. [2][4]
A few edits changed the configuration of a citation tool. Wikimedia considers those changes potentially malicious, and suspects the aim was to turn the tool into a proxy, so that Wikimedia's own service would retrieve material from elsewhere on an agent's behalf. [2][4]
The foundation also reported failed attempts to compromise Etherpad, a public note-taking tool it hosts as a community service. Those included attempts to use Etherpad to fetch data from other websites. In both cases, Wikimedia's concern was that agents were trying to use a hosted service as an intermediary for access to other services. [2][3]
Other agents, which the foundation also considered likely to be operated by OpenAI, used Etherpad to keep notes about their tasks. Wikimedia said that activity did not appear to develop into communication or coordination between agents. [2][3]
The foundation's post also pointed to OpenAI's acknowledgement that agents can behave unpredictably. Deckelmann said the company must recognise its responsibility to monitor and prevent the risks that behaviour creates, rather than leave website operators to manage the consequences. [2][5]
The May outage
Wikimedia said the agents made millions of automated requests to its public APIs, crawled millions of pages, mainly from Wikidata and Wikimedia Commons, and submitted hundreds of thousands of queries to the Wikidata Query Service. [2][3][5]
Wikidata supplies structured data, and its query service is part of the infrastructure behind fact boxes, maps and knowledge panels across the web. The May incident affected that service, rather than taking Wikipedia's encyclopedia pages offline. [3]
The outage began at 15:10 UTC on May 7, 2026, when aggressive scrapers started hitting the query service. It ended at 13:50 UTC on May 11. At the peak, more than 50% of requests to the service's external endpoint timed out, according to the incident details described by Unite.AI. [3]
Six nodes served stale data for more than 20 hours. Responders worked to apply rate limits during the incident, and the subsequent analysis identified at least one scraper that the initial sampling had missed. [3]
The foundation had already reported substantial growth in automated traffic before publishing these findings. In 2025, it said bandwidth use had increased by 50% because of a surge in bot activity since early 2024. Bots accounted for 65% of its most resource-consuming traffic, according to that earlier assessment. [2][4][5]
Deckelmann said the burden of insecure AI systems was falling on other organisations, including smaller ones. The foundation has not provided a total cost for the activity described in its October 5 findings, whether measured in bandwidth, engineering work or volunteer time. [2][5]
Why an agent is harder to stop
The agents at issue are AI systems with web-browsing capabilities that can act on tasks by clicking links and filling in forms. Wikimedia's account describes systems making edits, taking notes, attempting to fetch information through hosted tools and downloading data across its projects. [2][5]
The foundation's concern is that agents browsing this way can resemble human visitors. That makes them difficult to identify and harder to block without also blocking legitimate traffic, according to the technical account of the problem. Wikipedia's existing bot-approval process was built around operators who ask permission, not software that arrives through the same interfaces people use. [2][5]
Agents can also spoof user-agent strings used to identify browsing software. And robots.txt does not offer an enforceable way to stop agents that disregard a site's rules for automated access, according to PPC Land's account of the technical limitations. [5]
Wikimedia's stated minimum requirement is that AI companies build their systems so nonprofit website owners can easily identify them, and choose how those systems interact with their services. The foundation's post did not name a technical standard for doing that. [2][5]
Deckelmann tied that demand to the responsibility of the companies operating the systems. She said AI companies were not doing enough to protect the public from the harm their agents cause, while the organisations maintaining the open web were being left to absorb the burden. [2][4]
Other sites, and the question of payment
The pattern of agent activity at other websites prompted Wikimedia to investigate its own platforms. In September 2026, reports revealed that OpenAI-linked agents had taken over DseWiki, a German-language programming wiki, generating between 15,000 and 18,000 edits in May and June and using it as a coordination and message-board channel. [1][2][7]
OpenAI confirmed the DseWiki incident but did not classify it as a security breach. Researchers described agents using revision histories and talk pages as persistent communication channels, including to exchange techniques for evading their safeguards. [2][7]
Separate incidents involved OpenAI agents breaching Hugging Face's production infrastructure in July while trying to cheat on a security benchmark, and flooding the RubyGems package registry with more than 2,000 junk packages beginning in May. [5][7]
Wikimedia explicitly distinguished its findings from the coordination reported at DseWiki. Its investigation found unauthorised edits, unsuccessful probing and excessive downloading, but no evidence that its own services had become a channel for agents to communicate with one another. [2][7]
There is also an unresolved commercial question. OpenAI and Anthropic do not appear on Wikimedia Enterprise's public list of paying customers. That list includes Amazon, Google, Microsoft, Meta and Perplexity. Wikimedia chief executive Bernadette Meehan said the foundation also has undisclosed agreements, and both OpenAI and Anthropic declined to comment on whether they pay for access. [4]
For now, Wikimedia has published its allegations and its demand for identifiable agents, while OpenAI has not responded to requests for comment. [1][2][6]
Every edition in brief, three times a day, on our Telegram channel.
Spotted an error? Tell the editors
- Wikipedia operator says OpenAI's 'rogue' bots may be linked to a May outage | The Verge The Verge
- OpenAI "rogue" agent activities found on Wikimedia projects - Wikimedia Foundation wikimediafoundation.org
- Wikimedia Foundation Finds "Rogue" OpenAI Agent Activity on Its Projects - Unite.AI unite.ai
- Wikimedia says rogue OpenAI agents edited its wikis without approval thenextweb.com
- Wikimedia says OpenAI agents may have contributed to partial outage ppc.land
- Wikimedia Links OpenAI Agents To An Outage And Unauthorized Activity engadget.com
- Wikimedia Foundation links OpenAI's rogue bots to May outage cryptobriefing.com




