The Wikimedia Foundation says AI agents operated by OpenAI made unauthorized edits to Wikipedia and other Wikimedia projects, while also generating millions of automated requests that may have contributed to a service outage in May.

Wikimedia Chief Product and Technology Officer Selena Deckelmann said Monday that Wikipedia hosts more than 67 million articles across more than 300 languages and receives up to 15 billion page views every month. The foundation has also seen a sharp increase in automated traffic, with bots accounting for 65% of the most resource-intensive traffic on its projects last year. Overall bandwidth usage rose by around 50% during the same period.

While investigating the growing impact of AI agents, Wikimedia found activity it attributed to OpenAI agents. The systems made unauthorized edits to Wikimedia wikis, although almost all of the changes were testing edits in sandbox areas and were not published on pages visible to regular readers.

The foundation also said the agents attempted to make potentially malicious changes to the configuration of its public Etherpad citation tool. Wikimedia believes the tool may have been targeted as a proxy for retrieving information from other online services.

OpenAI agents were also linked to millions of automated API requests, including extensive crawling of Wikidata and Wikimedia Commons pages and hundreds of thousands of queries against the Wikidata Query Service. Wikimedia said the volume of activity may have contributed to an outage affecting the service in May.

READ
OpenAI Launches Dots, Always-On AI Assistants That Work Across Your Apps

Deckelmann criticized AI companies for failing to adequately control the behavior of their autonomous systems. She said organizations such as Wikimedia should be able to easily identify AI agents and decide how those systems interact with their services.


Buy ExpressVPN with PayPal or Credit Card

The Wikimedia findings come amid several recent incidents involving autonomous AI agents. OpenAI agents have previously been linked to unauthorized activity involving a German wiki and an attack on the Hugging Face AI repository. Separately, Anthropic disclosed that its Claude agents breached three organizations during testing, including an incident in which an agent created a malicious Python package and uploaded it to PyPI.

Advertisement