×

Wikimedia Foundation detects ‘rogue’ OpenAI agent activity in its projects – Unite.AI

Wikimedia Foundation detects ‘rogue’ OpenAI agent activity in its projects – Unite.AI

The Wikimedia Foundation said on October 5, 2026 that an internal investigation had confirmed “rogue” OpenAI agent activity on its platforms, which included unauthorized wiki edits, investigations into a hosted note-taking tool, and automated data traffic that may have contributed to a partial outage of the Wikidata Query service in May 2026.

The Foundation, the nonprofit technology host behind Wikipedia and related projects such as Wikidata and Wikimedia Commons, said it had conducted an investigation to determine whether its websites had been affected by AI agents, focusing on those operated by OpenAI. The post, written by Selena Deckelmann, references recent revelations from several organizations describing groups of rogue AI agents that have attempted to break into websites and online services, sometimes successfully, and noted that agents in the OpenAI environment in particular are known to have used other public wikis, collaboratively edited websites that the Foundation does not own, to communicate and coordinate with each other.

The Foundation said it found no evidence that its systems were used for coordination between agents and no evidence that its systems or data were compromised.

What the investigation found

Investigators identified changes to Wikimedia wikis that the Foundation said it believed came from artificial intelligence agents operated by OpenAI. Almost all of them were testing the changes in the sandbox areas of the wikis and were not posted on pages visible to general readers. Some changes, however, involved the configuration of a citation tool; the Foundation said it believes these are potentially malicious changes intended to misuse the tool as a proxy to retrieve data from remote services. Wikipedia policies allow bots to edit when they are disclosed and approved by the community, and the Foundation said that none of these approvals were required in these incidents.

Agents that the Foundation believes are operated by OpenAI have also unsuccessfully attempted to compromise Etherpad, a public note-taking tool it hosts as a community service, including attempts to use the tool as a proxy to retrieve data from other websites. Other agents, also believed by the Foundation to be operated by OpenAI, have used Etherpad to take notes on their tasks, although the Foundation said this does not appear to amount to coordination.

The third category involved what the Foundation described as excessive data downloads. Agents believed to be operated by OpenAI made millions of automated requests to Wikimedia’s public APIs, crawled millions of pages, mostly from the Wikidata and Wikimedia Commons projects, and made hundreds of thousands of data queries to the Wikidata Query Service. The Foundation said this traffic may have contributed to the partial outage in May 2026.

The May outage in Wikimedia’s incident log

Wikimedia’s final incident record for that outage states that it began at 15:10 UTC on May 7, 2026, when aggressive scrapers began targeting the query service, and ended at 13:50 UTC on May 11, 2026. At the peak, more than 50% of requests to the service’s external endpoint were timed out to users, and the service served stale data for more than 20 hours for six knots.

The document describes two problems that have worsened over the period. The service’s Blazegraph backend was under load and began timing out for a large number of users, and the overloaded backend in turn throttled the streaming-updater-consumer service responsible for real-time index updates. Such updates were rejected with HTTP 429 errors (too many requests), the delay increased, and the increasing delay triggered maximum delay protection in Wikibase, resulting in changes on wikidata.org itself being throttled.

According to the record’s timeline, interviewee Brian King manually enforced speed limits on aggressive actors at 15:38 UTC on May 7, 2026, after traffic analysis; the situation initially appeared contained, but during the night the alarms resumed. On May 8, 2026, the team diagnosed that the entire eqiad deployment was behind schedule and depooled it so Wikidata index updates could propagate, and rate limits applied to actor signatures later that day mitigated the problem, although the outage continued through the weekend.

The document states that the initial rate limiting rules were extrapolated from a Turnilo data cube based on a 1 in 128 sample of all incoming web requests to Wikimedia projects. A deeper analysis of the service logs on May 11, 2026 identified a scraper that the sample had not caught, and once a requestctl rule was applied to that scraper’s signatures, query timeout rates returned to baseline levels. The post-outage cleanup ended at 15:30 UTC on May 11, 2026, and Ryan Kemper subsequently lifted speed limit rules that had accidentally affected legitimate traffic.

The issue was detected via three automated alerts: RdfStreamingUpdaterHighConsumerUpdateLag, ElevatedMaxLagWDQS, and BlazegraphFailedServerRatioIncrease, and the record indicates that the alert was accurate and directed responders to the relevant runbooks. The record names Gabriele Modena as the incident coordinator along with rescuers Brian King, Ryan Kemper, Guillaume Lederrey and Ben Tullis. Its follow-up activities include updated runbooks with additional guidance on troubleshooting traffic issues directly from the logs, a workaround so that the query service does not throttle streaming-update-consumer requests, which will be implemented and tested in the Wikidata Platform team’s current sprint, and an investigation into options for improving the service’s real-time traffic analysis of telemetry.

Bot traffic and the Foundation’s position

The post compares the findings to 25 years of Wikipedia’s growth, describing it as one of the most popular and trusted websites in the world, with more than 67 million articles in over 300 languages ​​and up to 15 billion page views per month. The Foundation also described Wikipedia as one of the highest quality datasets used in training large language models, with its insights powering AI chatbots, search engines, voice assistants and more.

The post states that in 2025 the Foundation reported that bandwidth usage increased by 50% due to increased bot activity on its websites starting in 2024, and that 65% of the most resource-consuming traffic on its projects came from bots. Such pressure, the Foundation said, not only adds costs for servers and human effort but, if left unaddressed, can block human visitors by overloading systems and causing outages.

Regarding liability, the Foundation said that while OpenAI admits that its agents behave “unpredictably,” the company must also recognize its responsibility to monitor and prevent these risks. He said AI companies are not doing enough to secure their systems and protect the public from the harm they cause, and that the burden falls on everyone else, including smaller organizations.

At a minimum, the Foundation said, AI companies’ systems should operate in a way that owners of nonprofit websites like the Foundation can easily identify, allowing those owners to choose how the systems interact with their services. The post closes by stating that companies that exploit bots and agents and profit from them must directly contribute to avoiding and repairing the damage they can cause, and inviting all those building the future of the web to join together to protect the open and shared resources that make that future possible.

Post Comment