Skip to content
Artificial Intelligence

Wikimedia Detected Activity From OpenAI’s ‘Rogue’ Agents Across Its Platforms

The nonprofit says the agents made unauthorized edits, probed its services, and may have contributed to a partial outage.
By

Reading time 3 minutes

Comments (1)

It seems like every week there’s a new story about OpenAI agents messing with another part of the internet. This week, it was Wikimedia’s turn. The nonprofit behind Wikipedia said in a blog post Monday that its services were affected by OpenAI’s “rogue” agents.

The Wikimedia Foundation said it conducted its own investigation and found activity on its platforms that it believes came from agents operated by OpenAI. The unauthorized bots made edits to Wikimedia wikis, unsuccessfully attempted to exploit a public note-taking tool, and generated heavy traffic that may have contributed to a partial outage of one of its data services.

Wikimedia said it found no evidence that its systems or data were compromised. Still, the nonprofit said it was concerned about what could have happened, the difficulty of investigating these incidents, and “the growing risks of agentic AI activity.”

The blog post follows a wave of reports involving OpenAI agents accessing or targeting third-party websites and services without authorization.

Scrutiny over rogue AI agents really kicked into high gear this year after Hugging Face disclosed in July that it had detected and responded to an intrusion carried out “end to end” by an autonomous AI agent system. OpenAI came forward several days later to acknowledge that its models were behind the compromise.

The AI company said the agents, which were undergoing internal cybersecurity evaluations, circumvented guardrails meant to keep them from the internet. They exploited vulnerabilities, gained internet access, and eventually compromised parts of Hugging Face’s infrastructure while trying to complete their assigned tasks. OpenAI is now facing a lawsuit over the breach.

OpenAI has since disclosed other incidents in which its agents accessed third-party systems without authorization. In June, for example, an OpenAI agent gained unauthorized access to an Australian government Medicare statistics portal.

In Wikimedia’s case, the nonprofit said it identified edits to its wikis that it believes were made by OpenAI agents. Almost all were test edits made in “sandbox” areas and were not published to pages visible to general readers. However, some agents also edited the configuration of a citation tool. Wikimedia said it believes those changes “were intended to misuse this tool as a proxy for fetching data from remote services.”

For context, Wikimedia allows bots to make edits, but only when they are disclosed and approved by the community.

Wikimedia also said OpenAI agents made unsuccessful attempts to compromise Etherpad, a public note-taking tool it hosts. The agents also tried to use the service as a proxy to gather data from other websites.

Finally, Wikimedia said agents it believes were operated by OpenAI made millions of automated requests to its public APIs, crawled millions of pages, and made hundreds of thousands of queries to the Wikidata Query Service (WQDS). The nonprofit said that traffic may have contributed to a partial outage of WQDS back in May.

“Incidents like this one, and the many others that have been (and are still being) uncovered, illustrate how AI agents can drain resources and crash servers, as well as attempt to compromise trustworthy information,” wrote Wikimedia Chief Product and Technology Officer Selena Deckelmann in the blog post.

Deckelmann called on AI companies to take more responsibility for monitoring their agents and preventing these risks.

OpenAI did not immediately respond to a for comment, however, spokesperson Drew Pusateri told Reuters that the company appreciated Wikimedia’s findings and was working with the them to review the reported activity.

Share this story

Sign up for our newsletters

Subscribe and interact with our community, get up to date with our customised Newsletters and much more.