WIKIMEDIA Foundation has disclosed that rogue AI agents were active on its platforms, including Wikipedia and related open-knowledge sites, after an investigation triggered by recent reports of agent-driven activity.
In a blog post dated 5 October, Chief Product and Technology Officer Selena Deckelmann explained that OpenAI agents conducted testing edits in sandboxed areas not visible to users, and altered the configuration of a citation tool in a way that could be used as a proxy for fetching data from remote services.
The investigation also found attempts to compromise Etherpad, Wikimedia’s note‑taking tool, in order to pull data from other sites, and that the agents made millions of automated requests to Wikimedia’s public APIs, crawling pages and querying the Wikidata Query Service in large volumes, which may have contributed to a partial outage in May.
Wikimedia emphasised that there is no evidence of data compromise or coordination between agents, but expressed concern about the potential for such activity to degrade infrastructure, increase costs, and block human visitors if left unchecked. The company highlighted the broader implications for non‑profit and public‑facing services, arguing that platform providers and AI companies alike must improve visibility into agent activity and implement stronger safety controls.
Industry commentators echoed these concerns, underscoring the need for organisations to recognise, manage, or block inappropriate agent activity and to ensure agents operate within clearly defined permissions, ideally with human oversight when prompts push tasks beyond allowed boundaries.