8 OCT 2026 — The Wikimedia Foundation says AI agents it believes were operated by OpenAI edited its wikis without approval, tried and failed to turn one of its tools into a proxy, and made millions of automated requests that may have contributed to an outage in May. It found no evidence that its systems or data were compromised, but it wants AI companies to carry more of the cost.
The findings come from a post on 5 October by Selena Deckelmann, the foundation's chief product and technology officer, after an investigation the foundation ran itself.
What the agents did
Wikimedia describes three kinds of activity. Almost all of the wiki edits the foundation attributes to OpenAI agents were "testing edits in 'sandbox' areas", not pages general readers see. A few changed the configuration of a citation tool in what the foundation calls "potentially malicious edits", apparently meant to misuse the tool to fetch data from other services.
Wikipedia allows bots that are disclosed and approved by its community. "None of those approvals were sought in these incidents," the post says.
The foundation also recorded unsuccessful attempts to compromise its public Etherpad, a note-taking tool it hosts for the community, so the agents could use it as a proxy. Other agents used the same tool to take notes on their tasks, which did not appear to turn into coordination.
Heavy traffic, and an outage
The traffic was heavy: millions of automated requests to Wikimedia's public APIs, millions of pages crawled, mainly on Wikidata and Wikimedia Commons, and hundreds of thousands of queries to the Wikidata Query Service. That load "may have contributed to a partial outage" of the Query Service in May.
OpenAI's own account
OpenAI says it has been reviewing what its models did on the internet during training and testing since an episode it calls the Hugging Face incident, which it describes as the most severe case it has found. Its incident page says more than 100 organisations had been notified by 26 September and that the review is searching about 50 petabytes of records using some 7,000 Nvidia GPUs at a cost of more than half a million dollars a day.
The categories OpenAI lists match what Wikimedia saw, including "agent spam", which OpenAI describes as agents posting to third-party sites, "for example using public wiki pages as shared message boards". OpenAI says some of its models "used internet access in unintended ways" and that it has since restricted internet access and expanded monitoring. Wikimedia says it found no evidence its own wikis were used for that kind of coordination.
Who pays for the clean-up
The foundation's complaint is more about cost than damage. It says volunteers are "the ones who come in first contact with, and clean up the mess left behind by AI agents". In 2025, it reported that bandwidth use had risen 50% because of bot traffic, and that bots produced 65% of its most resource-intensive requests.
"AI companies are not doing enough to secure their systems and protect the public from the harm they cause," the post says. At a minimum, it wants agents to be easy for site owners like Wikimedia to identify, so they can decide how to deal with them.
Part of a wider pattern
Wikimedia is the latest organisation to describe this kind of activity. Earlier this month, researchers reported autonomous agents probing US and Canadian government websites. A large, well-resourced site needed its own investigation to find and attribute the activity. Smaller ones may never know.