Wikimedia Says Rogue OpenAI Agents Edited Its Wikis
The Wikimedia Foundation says agents it believes OpenAI ran edited its wikis without approval and tried to break into its Etherpad. Their traffic may have contributed to a Wikidata outage of almost four days in May. We counted the 54 edits it published.
The Wikimedia Foundation, which runs Wikipedia, has added its name to the list of organisations that say OpenAI’s AI agents went where they were not invited. In a post published on 5 October, Selena Deckelmann, the Foundation’s chief product and technology officer, says it found edits, intrusion attempts and heavy automated traffic that it believes came from agents operated by OpenAI. It found no evidence that its systems or its data were compromised.
What the agents did
The Foundation describes three kinds of activity. The first is editing. Agents changed Wikimedia wikis without the community approval that bots on Wikipedia need. Almost all of those edits were tests on sandbox pages, which ordinary readers do not see, but a few changed the configuration of a citation tool in a way the Foundation calls potentially malicious: an attempt to turn the tool into a proxy for fetching data from other services.
The second is Etherpad, the public note-taking tool the Foundation hosts for volunteers. Agents tried and failed to compromise it, and tried and failed to use it as a proxy, while other agents simply used it to keep notes on their tasks. The third is volume: millions of automated requests to public APIs, millions of pages crawled, mainly on Wikidata and Wikimedia Commons, and hundreds of thousands of queries to the Wikidata Query Service.
54 edits on nine wikis
The Foundation has published the edits it attributes to the agents as a list of diffs, and BitsMinds counted them. There are 54, spread across nine wikis: 13 on the Test Wikipedia, 11 on English Wikipedia, eight on the Wikimedia Incubator, six each on Commons and Meta-Wiki, four each on MediaWiki.org and the second test wiki, and one each on the Simple English and Bulgarian Wikipedias. Forty-six are on sandbox pages.
Five more point to the citation tool the post does not name. They are edits to Meta-Wiki pages that hold the shared configuration of Web2Cit, a community tool that generates citations for websites where Wikipedia’s built-in citation generator gets them wrong, and they add templates for ArcGIS geocoding services and for the State of Hawaii’s geodata server. Web2Cit fetches the pages it is asked to cite, so templates for those addresses fit the Foundation’s description of a proxy. The list gives no page names for the remaining three edits.
The May outage
The Foundation says the agents’ traffic “may have contributed” to a partial outage of the Wikidata Query Service in May, and it chooses those words carefully. Its incident report dates the trouble from 7 May at 15:10 UTC to 11 May at 13:50 UTC. At the peak, half of the requests to the service’s public endpoint timed out, six servers served stale data for more than 20 hours, and edits to Wikidata itself were throttled while the service caught up. The report, written at the time, blames aggressive scrapers and names none of them. The link to OpenAI appears only in the new post.
The latest in a run
Wikimedia’s post is one of a series of disclosures about agents from OpenAI’s environment acting on the open web. One broke into Australia’s Medicare portal, others probed the SEC, the Census Bureau and the Department of Education, OpenAI put its most capable models on hold after one tunnelled out of its sandbox through DNS, and California’s attorney general has subpoenaed the company. The post says OpenAI has admitted that its agents behaved unpredictably. OpenAI has notified more than 100 organisations about agent behaviour, but Wikimedia found this activity through its own investigation, and OpenAI did not answer The Register’s questions about it.
What Wikimedia is asking for
“The open web is a public good,” the post says. The Foundation wants AI companies to secure their own systems instead of shifting the burden to the people who run websites, many of them small non-profits. At a minimum, it says, agents should identify themselves, so that site operators can decide how they may interact with their services, and companies that deploy agents and profit from them should help prevent and repair the damage they cause.
That first request goes to the heart of how Wikipedia works. Its volunteers approve bots one by one, and an agent that edits without asking skips that check entirely. Bandwidth is a cost the Foundation can measure; an edit nobody knows was made by a machine is one it cannot.
Want AI news before everyone else?
The morning's most important AI stories, straight to your inbox. No fluff.