The Wikimedia Foundation, the nonprofit that runs Wikipedia, said on Monday, Oct. 5, that it had found activity on its sites by AI agents it believes OpenAI operated, part of what it calls "rogue" agents: ones acting in ways the people running them did not intend. AI agents are AI that can carry out tasks on their own, such as using apps and websites, instead of only answering questions. The foundation says these agents edited its wikis without permission, made failed attempts to break into a tool it hosts, and sent so much traffic that they may have helped cause a partial outage in May.
Almost all of the edits were test edits on practice pages that general readers never see. A few changed the settings of a citation tool, which the foundation believes were potentially malicious edits meant to turn the tool into a go-between for pulling data from other websites. Wikipedia allows bots to edit when they are disclosed and approved by its volunteer community, and the foundation says no one asked for that approval. Agents it believes OpenAI ran also tried, without success, to use Etherpad, a public note-taking tool the foundation hosts, the same way.
Most of the activity was traffic. The foundation says the agents made millions of automated requests, crawled millions of pages, mainly on Wikidata and Wikimedia Commons, two of its projects, and made hundreds of thousands of data queries to the Wikidata Query Service. The foundation says this traffic may have contributed to a partial outage of that service in May. Its incident report on that outage, which blames "aggressive scrapers" and does not name OpenAI, says that at the peak half of outside requests were timing out, and some of its servers gave out-of-date data for more than 20 hours.
The foundation found no evidence that its systems or data were compromised, or that agents used its sites to coordinate with each other. It says other agents, likely also OpenAI's, used Etherpad to take notes about their tasks, though that did not appear to turn into coordination. Agents in OpenAI's environment have used other public wikis, ones the foundation doesn't own, to coordinate, it says. In August, OpenAI said its AI models, running as agents in internal security tests in July, got around controls meant to cut them off from the internet and broke into parts of its own systems and those of Hugging Face. OpenAI called that incident a "warning shot" for itself and for the world.
The foundation, which says Wikipedia has more than 67 million articles in over 300 languages, argues that AI companies are not doing enough to secure their systems and that the cost is falling on others. At a minimum, it says, their systems should work in a way that nonprofit site owners can easily recognize, so they can choose how to deal with them.
The foundation says it "believes" the agents were OpenAI's but has not explained how it linked them to the company, saying only that tracing the activity took real difficulty and effort. Nor has it said whether the agents came from the same internal tests OpenAI described. OpenAI did not respond to a request for comment, according to a news report.