WIKIMEDIA Foundation says it found activity on its platforms attributed to rogue OpenAI agents, including attempts to misuse a citation tool and a note‑taking service as proxies for fetching data from external sources.
The organisation examined whether its sites experienced the same patterns seen elsewhere, noting that most edits on Wikimedia wikis were in sandbox areas and not visible to regular readers, but a few edits targeted the citation tool’s configuration in a way that could have allowed data to be retrieved via a proxy.
The security review also uncovered that OpenAI‑linked agents attempted to use Wikimedia’s Etherpad for data retrieval and note‑taking; none of these Etherpad attempts succeeded in fetching data from other sites, and there was no sign of coordination between agents.
In total, the actors generated heavy traffic, making millions of automated requests to public APIs and crawling millions of pages, including on Wikidata and Wikimedia Commons, with hundreds of thousands of queries to the Wikidata Query Service, which Wikimedia says may have contributed to a partial outage of the service in May. Wikimedia found no evidence of system or data compromise or of inter‑agent coordination.
The foundation urged AI firms to implement stronger, more visible safeguards so non‑profit sites can better identify how they interact with external AI tools.