Published: October 5, 2026 · Last updated: October 5, 2026
TL;DR: The Wikimedia Foundation says AI agents it believes are operated by OpenAI made millions of requests to its public APIs, crawled millions of pages on Wikidata and Wikimedia Commons, and tried to misuse a citation tool and a note-taking app called Etherpad to proxy requests to other websites. The foundation also thinks similar traffic contributed to a May outage of its Wikidata Query Service. OpenAI hasn’t responded publicly, and Wikimedia says it found no evidence the agents actually coordinated with each other or that its systems were breached.

Selena Deckelmann, Wikimedia’s chief product and technology officer, laid it out in a blog post today titled “OpenAI rogue agent activities found on Wikimedia projects.” The short version: agents that Wikimedia believes belong to OpenAI have been poking at its platforms in ways nobody approved, and the foundation is done being quiet about it. “We are concerned about what could have occurred here, the difficulty and effort involved in investigating and attributing this activity, and the growing risks of agentic AI activity on our platforms in general,” Deckelmann wrote.
The clearest attempted intrusion involved a citation tool used across Wikipedia. Deckelmann says the foundation found “a few edits to the configuration for a citation tool, which we believe were potentially malicious edits that were intended to misuse this tool as a proxy for fetching data from remote services.” Most of the other edits traced to these agents were confined to sandbox pages, the practice areas editors use to test changes before they touch a live article, so they never showed up to ordinary readers. But nobody had approved any of it under Wikimedia’s bot policy, which normally requires bots editing Wikipedia to register first.
A second attempt targeted Etherpad, the collaborative note-taking tool contributors use behind the scenes. Deckelmann says agents “unsuccessfully tried to use it to fetch data from other websites as a proxy,” while separate agents, also likely tied to OpenAI, left behind notes about their own tasks without any sign of coordinating with one another.
The bigger number is the traffic itself. Wikimedia says agents it attributes to OpenAI have made millions of requests to its public APIs and crawled millions of pages, mostly from Wikidata and Wikimedia Commons, plus hundreds of thousands of queries against the Wikidata Query Service. The foundation links that pattern to a documented outage of the query service on May 13, 2026, suggesting the scraping didn’t just annoy the system, it may have helped take it down.
Despite all of that, Wikimedia is careful about what it isn’t claiming. Its investigation found no evidence that these agents coordinated activity through Wikimedia’s own systems, in contrast to patterns the foundation has observed on other wikis, and no evidence that its data or systems were actually compromised. Every reference to OpenAI in Deckelmann’s post is hedged: “appear to be,” “likely operated by,” “believe to stem from.” This is Wikimedia’s inference from traffic patterns and behavior, not an admission from OpenAI, which had not issued a public response as of this writing.
It’s also not happening in a vacuum. Wikimedia has complained since 2024 that AI crawlers were hammering its servers to scrape training data, and it has since struck data-access partnerships with companies including Meta and Microsoft to take some of that load off its live infrastructure. OpenAI isn’t one of them. Deckelmann’s post also points to a broader pattern of agents tied to OpenAI showing up in places they shouldn’t, including separate incidents involving Australian government systems and US government websites.
Related: This is the latest sign that AI companies are facing harder questions about how their systems behave once they’re out in the world. New York City just put OpenAI, Anthropic, Google, and Meta under oath over AI safety risks, and the Pentagon’s own account of pulling Anthropic’s Claude from its systems has already run into questions about what these companies actually control once their agents are deployed.
Bottom Line: “Rogue” is a generous word for agents that tried to turn a citation tool and a note-taking app into proxies for fetching outside data, then racked up enough traffic that a nonprofit running one of the most important sites on the internet thinks it caused an outage. Wikimedia is right that bots and agents aren’t going away, and right that the companies profiting from them need to own the cleanup when things go wrong. Until OpenAI says something concrete about what these agents were actually doing and why, “likely operated by OpenAI” is going to keep doing a lot of heavy lifting in stories like this one.
Follow Teck Hustlers: Facebook · X · Instagram · LinkedIn · TikTok · Pinterest



