The Foundation ran its own investigation after other organisations disclosed clusters of so-called “rogue” agents. Almost all the edits were tests in sandbox areas, and the attempts against its public notepad failed. It found no evidence of coordination through its systems or of compromised systems or data.
- Wikimedia attributes edits on its wikis to OpenAI agents: almost all are tests in sandbox areas, invisible to readers. A few touch the configuration of a citation tool and, the Foundation says, were potentially malicious.
- Attempts to compromise the public Etherpad and use it as a proxy failed. Wikimedia found no evidence that its systems were used for coordination between agents, or of compromised systems or data.
- Millions of automated API requests, millions of crawled pages (Wikidata, Commons) and hundreds of thousands of queries to the Wikidata Query Service. Wikimedia says this may have contributed to a partial outage of the service in May.
Nobody asked. Wikipedia policy allows bots, as long as they are disclosed and approved by the community. According to Wikimedia, in these cases approval was not sought even once.
Wikimedia says so itself: the attempts against the notepad failed, and it found no evidence of compromised systems or data. Do not retell it as a breach.
The weight is in the bill. The test edits sit in a sandbox, but someone had to find them, read them and decide whose they were. The Foundation writes that volunteers are the first to run into the traces. They also clean up, together with its security teams. And the pressure is not new: in 2025 it reported a 50% rise since January 2024 in the bandwidth used to download multimedia, mostly from bots scraping Commons images to feed AI models.
The ask to OpenAI is direct. According to Wikimedia, OpenAI itself admits its agents behave “unpredictably”. Then, the Foundation writes, it must also acknowledge its responsibility to monitor and prevent these risks. The minimum is that AI companies’ systems are easy for non-profit site owners to identify, and that those owners choose how these systems use their services. To the industry the Foundation is shorter still: whoever releases agents and profits from them should directly help avoid and repair the damage.
OpenAI’s answer is not in the post. Your own logs are closer: look at who is asking your site and whether it says who it is.