The Wikimedia Foundation has discovered activity by autonomous AI agents on its platforms, which the organization links to OpenAI. The agents made test edits to the wiki, tried to use the public note-taking service Etherpad to access third-party websites, and generated such a large volume of requests to Wikimedia’s infrastructure that it may have contributed to an outage of the Wikidata Query Service.
Most edits remained in sandboxes
The Wikimedia Foundation conducted its own investigation after reports of groups of so-called rogue agents — autonomous systems that independently perform tasks on the internet and sometimes try to find ways to break into web services.
The organization says it detected activity by agents that, in its assessment, were operated from within the OpenAI environment. They made changes to Wikimedia projects, but most of those edits were made in test areas — “sandboxes” — and did not appear on pages accessible to ordinary readers.
Some changes affected the configuration of a citation tool. Wikimedia believes those edits could potentially have used the tool as a proxy to retrieve data from remote services. At the same time, the agents did not request the community approval required under the rules for automated editing.
For Wikipedia, this is a fundamental issue: bots may in principle edit pages, but only if they comply with established rules and disclose their purpose and receive community approval.
At the same time, Wikimedia found no signs that its systems or data were compromised or that its infrastructure was used by the agents to coordinate with one another.
Etherpad was used in attempts to turn it into an intermediary for attacks
Another focus of the agents’ attention was the public Etherpad — a collaborative note-taking service that Wikimedia provides to its community.
The agents, which the organization links to OpenAI, repeatedly but unsuccessfully tried to use it to retrieve data from other websites. In essence, they tried to force the service to act as an intermediary between the agent and a remote resource.
Wikimedia also discovered other actions related to note-taking. However, the organization found no signs that those notes were ultimately used to coordinate the actions of different agents.
Wikimedia separately points to the enormous volume of automated traffic. The agents sent millions of requests to the public APIs of its projects, scanned millions of pages, mainly on Wikidata and Wikimedia Commons, and also made hundreds of thousands of requests to the Wikidata Query Service.
In the organization’s assessment, that traffic may have contributed to the partial outage of the Wikidata Query Service in May 2026.
AI agents pose a special problem for Wikipedia
For Wikimedia, this case matters not only because of the specific attempts to exploit its services. The organization warns of a broader problem: autonomous AI agents are capable of generating volumes of traffic that traditional web infrastructure and its administrators are not designed to handle.
Unlike an ordinary bot, an agent can independently set intermediate goals, interact with different services, analyze the results it receives, and try new ways to achieve its objective. If thousands of such systems are operating at the same time, even relatively harmless individual requests can turn into a serious burden.
This is especially sensitive for Wikipedia. The platform relies on volunteer editors, and its infrastructure must remain accessible to millions of people. If automated systems overload servers or create large numbers of erroneous changes, people have to deal with the consequences.
Wikimedia also cites a broader indicator: in 2025, the organization reported a 50% increase in bandwidth consumption due to the rise in bot activity since 2024. At the same time, 65% of the most resource-intensive traffic on its projects came from bots.
Wikipedia turned out to be an especially valuable target for AI
The problem is compounded by the fact that Wikimedia itself is one of the most important sources of data for the modern AI industry. The foundation calls Wikipedia one of the highest-quality datasets for training large language models: its materials are used by chatbots, search engines, voice assistants, and other services.
Over 25 years of its existence, Wikipedia has grown to more than 67 million articles in more than 300 languages. According to Wikimedia, the foundation’s projects receive up to 15 billion page views per month.
As a result, AI companies simultaneously depend on the open web as a source of data and create systems capable of placing additional strain on it.
Wikimedia believes that responsibility for the consequences of such activity should not rest solely with website owners. The foundation calls on companies building AI agents to make their behavior easily identifiable to web resource owners and to give administrators the ability to choose how such systems may interact with their services.
In Wikimedia’s view, the problem is already going beyond a single Wikipedia. If autonomous agents are becoming part of the ordinary internet, their developers must take into account not only what the agents are capable of doing, but also the load and damage their actions can create for third-party resources.
The “open internet” was created as shared infrastructure that people and organizations could use. Now it is increasingly populated by autonomous systems capable of independently seeking information, interacting with websites, and trying to circumvent restrictions. And Wikimedia warns: if responsibility for their actions continues to fall only on the owners of affected resources, incidents like this may become the norm.






