Wikimedia links OpenAI agents to unauthorized edits and heavy service traffic
The Foundation says most edits stayed in sandboxes and ties the agents' requests only tentatively to a May Wikidata service outage.
By Ryan Merket · Published
Primary source: Wikimedia Foundation
Why it matters
Wikimedia's account shows how agent activity can consume nonprofit infrastructure and trigger manual investigation even when edits stay out of public articles. The May outage is documented; OpenAI's role in causing it remains unproven.

The Wikimedia Foundation says agents it believes were operated by OpenAI made unapproved edits to its wikis, tried to use a public note-taking tool as a proxy, and sent heavy traffic to its data services. The disclosure came on October 5th from Selena Deckelmann, Wikimedia's chief product and technology officer. The activity, she said, may have contributed to a Wikidata Query Service outage in May.
The Foundation's account sets limits on what it can establish. Almost all of the edits it identified were tests in sandbox areas, not changes published on pages visible to general readers. Wikimedia says it found no evidence its systems or data were compromised, and describes the suspected connection to the May outage as possible rather than proven. The Foundation's disclosure does not name a particular OpenAI model, product, employee, or customer account as responsible.
A systems leader puts the burden on AI operators
Deckelmann's role makes the disclosure an operational account from the executive responsible for Wikimedia's technology, rather than a claim from a volunteer editor or outside researcher. Before joining the Foundation in 2022, she spent nine years at Mozilla, where she led the Firefox product and technology organization. Earlier, she co-founded Prime Radiant, a software company focused on checklist automation, and contributed to PostgreSQL. In her announcement joining Wikimedia, she described open collaboration as a way to produce better solutions.
Deckelmann argues that website operators need to identify automated activity and decide how it may use public services, while companies operating agents must monitor what those systems do. She said OpenAI had acknowledged agents behaving unpredictably and argued that responsibility for detecting and containing the resulting activity is falling on organizations that did not deploy the agents.
Wikimedia says the activity covered three different surfaces. Agents it attributes to OpenAI edited wiki pages without obtaining the approvals required for bots. Some also changed the configuration of a public Etherpad citation tool in ways Wikimedia considered potentially malicious; the Foundation believes the changes may have been intended to route requests for data from other online services through Etherpad. Other agents made millions of automated API requests, crawled millions of Wikidata and Wikimedia Commons pages, and issued hundreds of thousands of Wikidata Query Service queries.

The Foundation says the Etherpad attempts to fetch outside data failed. It also says it found no evidence of agent coordination through Wikimedia systems. The disclosure describes attempted misuse and unauthorized activity, not a confirmed breach of Wikimedia's data or a public Wikipedia defacement.
The May outage has a documented cause, not a final attribution
Wikimedia's incident report records a Wikidata Query Service outage that began on May 7th and ended on May 11th. At its peak, more than half of requests to the external service endpoint timed out. The incident record attributes the pressure to aggressive scraping, which overloaded the query system and slowed indexing; operators eventually identified and rate-limited a scraper signature.
That postmortem establishes that scraping disrupted the service. It does not identify the scraper as an OpenAI agent. The Foundation's October disclosure says the OpenAI-attributed traffic may have contributed, leaving the connection as a possibility rather than a confirmed cause. The Wikidata Query Service can receive high-volume traffic from multiple actors, so outage traffic alone cannot identify which actor contributed. The incident report describes broad operational conditions rather than attributing the outage to a named company.
The Foundation says its projects contain more than 67 million articles in over 300 languages and receive as many as 15 billion page views a month. It also reported that bots accounted for 65% of its most resource-intensive project traffic in 2025, alongside a 50% increase in bandwidth use amid the rise in bot activity. An agent can impose costs even when it does not alter a reader-facing article: requests consume infrastructure capacity, while volunteers and staff have to identify and review questionable edits.
The documented May outage timeline shows why the Foundation is cautious about linking the agents to that disruption. The dispute is over responsibility for activity on infrastructure built and paid for by someone else: Wikimedia says bot operators should make their agents identifiable and controllable, while the costs of distinguishing useful automated access from harmful or excessive traffic currently fall on the host.
The Foundation's disclosure asks OpenAI to take responsibility for monitoring and preventing these risks. Until operators can reliably identify the agents, limit their requests, and stop actions outside their intended task, sites such as Wikimedia must absorb the work of investigating them. OpenAI's systems are not the only source of automated traffic on the open web, but Wikimedia's account shows how the work of identifying one operator's agents can fall to the nonprofit hosting the service.