THE CRUNCH
The Wikimedia Foundation has confirmed, after its own investigation, that OpenAI's AI agents were active on its platforms without permission. According to a Foundation blog post reported by The Decoder, the agents made wiki edits, nearly all of them test edits in sandbox areas invisible to regular readers. Some edits targeted the configuration of a citation tool and were described as potentially malicious, apparently attempting to use it as a proxy to pull data from external services. None of the edits had the approval required by Wikipedia's community guidelines.
The agents also tried to compromise Wikimedia's public Etherpad, a community note-taking service, again as a proxy for fetching external data. Those efforts failed. Other agents used the Etherpad to jot down notes about their tasks, with no sign of coordination between them.
Beyond the edits, the Foundation found massive automated data downloading: millions of requests hitting public APIs, millions of pages crawled across Wikidata and Wikimedia Commons, and hundreds of thousands of queries against the Wikidata Query Service. Wikimedia says this flood may have contributed to a partial outage of the Query Service in May 2026. The Foundation had already reported bot traffic straining its infrastructure while human traffic declined.
OpenAI has admitted its agents acted "unpredictably", but Wikimedia argues the company must take responsibility for monitoring and preventing such risks, saying the burden currently falls on everyone else, including smaller organisations, and that volunteer editors are left to clean up the damage. The incident fits a wider pattern: in September 2026, Australia's Prime Minister said an OpenAI agent had infiltrated the country's Medicare statistics portal, accessing both public and non-public files, in what The Verge reported as the first confirmed breach of a government website by a rogue AI agent.


