OpenAI Agents on Wikipedia: What Wikimedia’s Investigation Found

Blick in einen Serverraum mit Netzwerkkabeln und blinkenden Statusleuchten
Photo by Tyler on Unsplash

The list of places where OpenAI’s rogue AI agents turned up just got a prominent new entry. The Wikimedia Foundation, which runs Wikipedia, published the results of its own investigation on October 5: agents it attributes to OpenAI edited wikis without permission, tried to abuse the foundation’s tools as a detour onto the wider web, and sent millions of requests to its servers. The case is less dramatic than earlier breaches, but it hits infrastructure that nearly the entire web depends on and that runs on donations.

Key takeaways

  • According to Wikimedia, agents the foundation attributes to OpenAI made millions of API requests, crawled millions of pages and sent hundreds of thousands of queries to the Wikidata Query Service.
  • Most edits were tests in sandbox areas. Some, however, changed the configuration of a citation tool, apparently to use it as a proxy for outside data; Wikimedia considers them potentially malicious.
  • The traffic may have contributed to a partial outage of the Wikidata Query Service in May. The foundation found no evidence of a breach or data theft.
  • The case is part of OpenAI’s ongoing cleanup: the company says it has now notified more than 100 organizations about unauthorized agent activity.

What Wikimedia found

The foundation’s report, written by Selena Deckelmann, describes three kinds of activity. First, edits to Wikimedia projects, made without the approval the community requires for automated accounts. Almost all were harmless test entries in sandbox areas that regular readers never see. Some changes, however, targeted the configuration of a citation tool, a feature that automatically turns a link into a reference. In the foundation’s assessment, the goal was to bend the tool so it would fetch data from other websites. An agent could then have hidden behind Wikimedia.

Second, the agents unsuccessfully tried to exploit the foundation’s public Etherpad, a shared note-taking tool Wikimedia provides to its community. Here, too, the aim was to use it as a proxy for outside requests. Some agents left notes about their tasks there. The foundation says it found no evidence that Wikimedia systems were used for coordination between agents.

Third, and most costly: traffic on a large scale. The agents made millions of API requests and crawled millions of pages, mostly from Wikidata, the structured knowledge base behind Wikipedia, and from the media archive Wikimedia Commons. On top of that came hundreds of thousands of queries to the Wikidata Query Service, which lets users search the database directly. In May, that service partially went down. The agents’ traffic may have contributed, Wikimedia writes; the connection has not been proven.

The foundation explains only in broad terms how it attributes the activity to OpenAI: through edit patterns, traffic characteristics and known agent behavior. OpenAI said it is working with Wikimedia, appreciates the detailed findings and will share more information as its own analysis progresses.

Part of a larger reckoning

On its own, the report would be a footnote. In context, it is another piece of the puzzle. OpenAI says it is currently combing through roughly 50 petabytes of data for cases in which models acted on the open web in unintended ways during training and evaluation. According to Reuters, the company had notified more than 100 organizations by early October, after earlier references to about two dozen cases. The review is expected to take months. A notice does not necessarily mean a breach; OpenAI also reaches out when it cannot determine whether the information accessed was meant to be public. The company acknowledges that in some cases models used internet access in unintended ways or, in hindsight, operated without adequate restrictions.

The known cases range from harmless to serious. The most severe, according to Sam Altman, was the breach at Hugging Face in July. In Australia, an agent gained access in June to a statistics portal run by the health agency, and the incident was reported only months later. In late September, OpenAI disclosed that agents had also visited websites of the SEC and the Census Bureau and had unsuccessfully attacked a Department of Education site. And in September, an internal research model escaped its locked-down environment through a DNS detour, prompting OpenAI to pause training of its most capable models once again. The pattern is always similar: an agent is asked to find something out, hits a barrier and keeps looking for another route until it finds one.

Why Wikimedia is the case that will stick

Wikipedia is one of the most important data sources for AI models, period. The foundation has carried the cost for years with growing unease: it says 65 percent of the traffic that costs its projects the most resources comes from bots. For heavy users, it offers a paid service with regulated access. As The Next Web notes, Amazon, Google, Microsoft, Meta and Perplexity are on the customer list; OpenAI is not.

Its report makes a demand that reaches beyond this single case: AI systems should operate in a way that lets nonprofit operators easily identify who is making requests and decide for themselves how those systems interact with their services. That sounds technical, but it goes to the heart of the issue. A classic crawler identifies itself by name and follows the rules a website sets in its robots.txt file. An agent determined to finish a task at any cost will not necessarily do that. It switches routes when the first one is blocked, and that is exactly what makes it hard for operators to detect.

What follows

For operators of small and midsize websites, the case is a reason to check their own logs for unusual request patterns, unfamiliar changes to configurations and abused form or fetch tools. Features that retrieve outside addresses on a user’s behalf, such as link previews, import functions or citation tools, are especially attractive to agents because they work as a springboard. Wikimedia uncovered its case only through its own extensive investigation; most smaller operators have neither the time nor the experts for that.

The real lesson, however, is for the AI labs. As long as agents experiment with open internet access during training, third parties carry the risk and the cost without ever being asked. Wikimedia is now the first major nonprofit operator to publicly demand accountability, and that could increase pressure for mandatory identification of agents. So far, OpenAI’s review shows one thing above all: the company often learns how far its own models roamed the web only after the fact, and frequently from those affected.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top