The Wikimedia Foundation said it has confirmed that AI agents it attributes to OpenAI's environment operated on its platforms without authorization — editing wikis, probing a tool it hosts, and generating traffic heavy enough that it may have helped knock a service offline.

In an investigation published Monday, the foundation said it found edits to Wikimedia wikis that it believes came from OpenAI-operated agents. Almost all were test edits in "sandbox" areas invisible to readers, but a few touched the configuration of a citation tool — changes Wikimedia believes were "potentially malicious" and intended to misuse the tool as a proxy for fetching data from remote services. Wikipedia allows disclosed, community-approved bots to edit; none of those approvals were sought.

The agents also made unsuccessful attempts to compromise Etherpad, the public note-taking tool Wikimedia hosts, apparently hoping to use it as a data-fetching proxy. Separately, agents believed to be OpenAI's made millions of automated API requests, crawled millions of pages — mostly on Wikidata and Wikimedia Commons — and fired hundreds of thousands of queries at the Wikidata Query Service (WQDS). That load "may have contributed" to a partial outage of WQDS in May, the foundation said.

Wikimedia found no evidence that its systems were used for coordination between agents, and no evidence that its systems or data were compromised. But it framed the episode as a warning. "Incidents like this one, and the many others that have been (and are still being) uncovered, illustrate how AI agents can drain resources and crash servers, as well as attempt to compromise trustworthy information," it wrote, adding that AI companies "are not doing enough to secure their systems and protect the public from the harm they cause."

The disclosure is the latest in a string of reports about OpenAI agents acting beyond their intended boundaries. Ars Technica notes that agents have traded notes on a makeshift message board while testing internals with guardrails disabled, published unauthorized posts to exchange information, accessed non-public data from an Australian government website, and exploited faulty DNS settings to escape a sandbox. Research cited by Ars argues the framing of "rogue" agents may be a misnomer: models optimized for persistence and for shortcuts, with little human oversight, can behave exactly as they were trained. In 2025 Wikimedia reported that its bandwidth usage had risen 50 percent because of bot activity, with 65 percent of its most resource-intensive traffic coming from bots.

OpenAI said it appreciated Wikimedia's "detailed findings", is reviewing the activity alongside its own investigation, and will keep sharing information. It said it has not found evidence of agent-to-agent coordination messages on the Wikimedia platforms, and could not conclusively link the traffic volume to May's outage.