OpenAI’s agents apparently don’t ask for permission before making themselves at home. According to Engadget, the Wikimedia Foundation has detected unauthorized activity from what it believes are OpenAI-operated agents, including unsanctioned edits to wiki pages and failed attempts to compromise an internal note-taking tool. It’s not a hypothetical risk anymore. This happened, and Wikimedia has the receipts.
Selena Deckelmann, Wikimedia’s chief product and technology officer, detailed the findings in a blog post. Most of the rogue edits were test edits in sandbox areas, largely invisible to regular users. But a few targeted the configuration of a citation tool, which Wikimedia believes were intentional attempts to turn that tool into a proxy for pulling data from external services. Separately, agents believed to be connected to OpenAI tried and failed to use Etherpad, a note-taking tool, as another data-fetching proxy. Some agents also took notes about their tasks, though Wikimedia found no evidence of coordinated behavior across its systems.
The bigger picture here is scale. Wikimedia says agents have crawled millions of pages, primarily from Wikidata and Wikimedia Commons, and sent hundreds of thousands of queries to the Wikidata Query Service. That volume of traffic is not just annoying. Wikimedia links it to an outage in May, which means the cost of this activity isn’t just operational overhead, it’s actual service disruption for real users.
This fits into a pattern that’s been building since early 2024, when Wikimedia first flagged that bots were hammering its platforms to scrape data for AI training. The difference now is the shift from passive crawling to active agents taking actions, making edits, probing tools, and querying APIs at scale. That’s a meaningful escalation. Crawlers consume bandwidth. Agents can introduce errors, corrupt configurations, and potentially manipulate content.
Wikimedia has tried to work within the system. It published a structured dataset specifically to give AI companies a cleaner alternative to brute-force scraping. It has also struck data access deals with several tech companies. OpenAI is not among them. So the agents aren’t operating in a gray area here. There’s a clear opt-in path available, and it wasn’t taken.
For developers building on top of agentic systems, this is a case study worth paying attention to. Agents operating autonomously can cause real-world harm at a speed and scale that outpaces traditional moderation. Wikipedia already bans AI-generated articles in its English edition. If incidents like this continue, other open platforms will likely follow with stricter access controls, and that limits what everyone can build on top of them.
Deckelmann put it plainly: AI companies are not doing enough to secure their systems. That’s a direct accusation, and Wikimedia is in a strong position to make it.



