Wikimedia Foundation has reportedly found activity from AI agents it believes were operated by OpenAI across its platforms. The agents made unauthorised edits to Wikimedia wikis, tried to use its public Etherpad service to access other websites and generated millions of automated requests to Wikimedia’s services. The Foundation said there is no evidence that its systems or data were compromised. However, it warned that this kind of activity can put extra pressure on its infrastructure and the volunteers who maintain it.
According to a report published by the Wikimedia Foundation, the organisation came across several types of activity that it believes came from OpenAI’s AI agents. This included edits to its wikis, attempts to use Etherpad to reach other websites and a large volume of automated traffic hitting its public services.
Most of the wiki edits were made in sandbox areas, so they did not affect the main pages that readers see. However, Wikimedia also found some changes to the settings of a citation tool. The Foundation believes these changes may have been an attempt to use the tool to retrieve information from other websites. While Wikimedia allows bots to edit its wikis with community approval, the agents involved in this activity had not received that approval.
The investigation also turned up attempts to use Wikimedia’s public Etherpad service. Some agents reportedly tried to use the note-taking tool to retrieve information from other websites, while others appeared to use it to keep track of their tasks. Wikimedia said it found no evidence that these notes were being shared between agents to help them coordinate.
The agents also generated a significant amount of traffic on Wikimedia’s services. They reportedly made millions of automated requests to its APIs and crawled millions of pages, mostly on Wikidata and Wikimedia Commons. The Foundation also identified hundreds of thousands of queries to the Wikidata Query Service, or WQDS, and believes this traffic may have contributed to a partial outage in May.
Despite the activity, Wikimedia said it found no evidence that its systems or data had been compromised. There was also no indication that its platforms were being used to coordinate the agents. However, the Foundation said investigating the activity and working out where it came from was difficult and required considerable effort.
The incident comes as Wikimedia deals with a broader rise in automated traffic. The Foundation said its bandwidth usage increased by 50 percent in 2025 as bot activity grew, with bots accounting for 65 percent of the most resource-intensive traffic across its projects. Such traffic can put additional strain on servers, raise infrastructure costs and, in extreme cases, make services harder for people to access.
Wikimedia is now calling on AI companies to do more to monitor their agents and make them easier for website operators to identify. The Foundation said this would give organisations more control over how these systems interact with their services and make it easier to respond when something goes wrong.
The findings add to a growing list of reported incidents involving autonomous AI agents. Wikimedia pointed to earlier reports involving OpenAI agents and services including Hugging Face and an Australian government Medicare statistics portal. Reuters has separately reported that OpenAI is working with Wikimedia to review the activity identified by the Foundation.
