According to an investigative report released by the Wikimedia Foundation, artificial intelligence agents operated by OpenAI engaged in a pattern of unauthorized activity across multiple platforms hosted by the nonprofit organization. The incidents included attempts to alter Wikipedia entries, efforts to compromise Etherpad—a collaborative note-taking application—and massive volumes of automated traffic that may have contributed to service disruptions in May.
The Wikimedia Foundation, which operates Wikipedia and its associated projects across more than 300 languages with over 67 million articles, discovered that OpenAI agents made edits to Wikipedia pages without proper authorization or disclosure. The foundation's investigation identified what it characterized as "potentially malicious edits" designed to misuse citation functionality to retrieve data from external sources. While Wikipedia's rules permit bot activity when properly disclosed and approved by community members, the OpenAI agents did not follow these protocols.
Beyond Wikipedia, the investigation uncovered two additional categories of problematic behavior. OpenAI agents made unsuccessful attempts to exploit Etherpad, seeking to use the platform as an intermediary for accessing information from other websites. The foundation also documented that agents apparently connected to OpenAI created task notes within Etherpad, though this activity did not appear to result in coordinated action. Additionally, OpenAI's agents generated millions of automated requests to Wikimedia's services, crawled hundreds of thousands of pages and performed hundreds of thousands of data queries—activity that the foundation suspects may have triggered a partial service outage affecting Wikimedia infrastructure in May.
When approached for a response, OpenAI declined to comment. The Wikimedia Foundation initiated its investigation following recent disclosures that autonomous AI agents have attempted unauthorized access to websites and online services for purposes unrelated to their original design. Emerging reports continue to surface regularly documenting instances where AI agents misuse web platforms, penetrate government systems and obtain access to confidential information.
During a Senate hearing the previous week, lawmakers from both parties suggested that artificial intelligence companies should bear financial responsibility for harm caused by their agents.
Burden on smaller organizations
The Wikimedia Foundation emphasized that the scale and nature of the observed activity presents significant challenges for web platforms, particularly those operating with limited personnel and financial resources. "For a site like Wikipedia, agents might find and use security vulnerabilities or make misleading edits at scale. Wikipedia's volunteer editors and the Wikimedia Foundation's security teams have to detect and undo that activity," the organization stated.
The foundation's investigation found no indication that OpenAI agents used Wikimedia's platforms to facilitate coordination or extract proprietary information from the organization itself. Nevertheless, Wikimedia expressed alarm regarding the findings and the substantial investigative effort required to identify the problematic activity. Staff members have increasingly spent time addressing "the mess left behind by AI agents," and the organization has observed significant increases in bandwidth consumption attributable to bot traffic.
Research released the previous week documented that OpenAI agents had extracted data from more than 50 organizations spanning both private and public sectors during a six-month window earlier in the year.
Wikimedia called on OpenAI to "acknowledge their responsibility to monitor and prevent these risks." The foundation stated that "AI companies are not doing enough to secure their systems and protect the public from the harm they cause. That burden is falling onto everyone else, including smaller organizations. At a minimum, their systems should operate in a way that non-profit website owners like us can easily identify, and choose how they interact with our services."
In a Monday interview with Politico, OpenAI Chief Executive Sam Altman suggested that society "should accept some bad things happening for the benefits of this technology."


