Wikimedia: Suspected OpenAI Agents Edited Pages, May Have Caused Outage

Suspected OpenAI agents made millions of unauthorized API requests, strained Wikidata servers, and burdened volunteer editors for weeks

Alex Barrientos Avatar
Alex Barrientos Avatar

By

Image: Deposit Photos

Key Takeaways

Key Takeaways

  • Suspected OpenAI agents made millions of unauthorized requests, potentially causing a multi-day Wikidata outage.
  • Automated agent activity burdened Wikimedia volunteers and staff, reversing edits and managing excess bandwidth.
  • Wikimedia demands AI companies disclose agents, prevent harms, and respect established bot approval policies.

The Wikimedia Foundation published findings that AI agents it believes were operated by OpenAI interacted with its platforms without authorization, generating automated traffic on a scale that strained the nonprofit’s infrastructure and burdened its staff and volunteer community.

Wikipedia and its sister projects depend heavily on employee and volunteer labor, and the foundation says autonomous software agents were quietly making unauthorized edits, probing its tools, and flooding its data services. No publicly visible Wikipedia articles were altered, and Wikimedia found no evidence that its systems or data were compromised. The damage was subtler, and in some ways harder to address.

Autonomous AI agents are software that acts on instructions without direct human oversight at each step. When they operate on third-party infrastructure without disclosure, the costs fall on whoever maintains the servers.

What Wikimedia Found

Wikimedia’s investigation identified three categories of suspected activity it attributes to agents it believes were operated by OpenAI.

Most of the unauthorized edits occurred in sandbox areas, test spaces where changes do not appear on publicly visible pages. The foundation also found several modifications to a citation-tool configuration it considered potentially malicious. Those changes appeared designed to use the tool as a proxy, a relay that routes data requests to other websites, to retrieve information from remote services.

Agents also attempted to exploit Wikimedia’s public Etherpad service, a community note-taking tool, to fetch data from external sites. Those attempts were unsuccessful, according to Wikimedia’s investigation.

Some suspected agents left notes describing their tasks. Wikimedia found no evidence those notes were used to coordinate agent activity across the platform.

Suspected agents made millions of automated requests to Wikimedia’s public APIs, the programming interfaces that allow software to retrieve structured data. They crawled millions of pages across Wikidata and Wikimedia Commons. Hundreds of thousands of queries also hit the Wikidata Query Service.

A Possible Outage and a Real Volunteer Burden

The automated traffic may have contributed to a partial service disruption in May, though Wikimedia stopped short of naming it the definitive cause.

The Wikidata Query Service experienced a partial outage between May 7 and May 11, according to Wikimedia’s incident records as reported by multiple outlets. At peak disruption, roughly half of external query requests timed out, and some nodes served data more than 20 hours behind. Wikimedia said the automated traffic may have contributed to that disruption.

The cost extends beyond server logs. Wikimedia said its employees and volunteer editors now spend significant time reversing unauthorized automated activity and managing bandwidth consumption. For a nonprofit whose projects depend heavily on unpaid community contributors, that is the infrastructure equivalent of receiving a neighbor’s electricity bill with your name on it.

OpenAI said it appreciated Wikimedia’s detailed findings and was working with the foundation to analyze the activity. The reported response did not say which systems generated the actions or describe what safeguards were in place.

What Wikimedia Is Asking For

The foundation is calling on AI companies to take direct responsibility for what their agents do on third-party platforms.

Wikimedia called on AI-powered companies to monitor and prevent harms caused by their agents. It asked that automated systems identify themselves clearly and that nonprofit operators be given meaningful control over how those systems access their services.

Wikimedia noted that its projects maintain bot policies requiring disclosure and community approval before any automated account can edit. The suspected activity identified in the investigation did not receive the required community approval.

If autonomous agents can quietly generate traffic that strains the infrastructure behind free public knowledge, the rules governing how AI systems interact with the open web have not kept pace. Wikimedia’s investigation is a data point, not a verdict, and the pressure on volunteer-supported platforms is unlikely to ease on its own.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →