Wikimedia Says OpenAI AI Agents Made Unauthorized Wikipedia Edits and Overwhelmed Its Systems
The Wikimedia Foundation says an unauthorized OpenAI AI agent made edits to Wikipedia and may have contributed to some of the service outages reported in May.
Wikipedia hosts more than 67 million articles in more than 300 languages and receives as many as 15 billion page views each month, Wikimedia Chief Product and Technology Officer Serena Deckelman revealed on Monday.
Bots now account for most resource-intensive Wikimedia traffic
Wikimedia found last year that automated bots accounted for 65% of the most resource-intensive traffic across its projects. A surge in bot activity also caused bandwidth usage to increase by 50%.
While investigating whether AI agents were affecting its websites, Wikimedia discovered that OpenAI agents had edited its wikis without prior approval. The agents also unsuccessfully attempted to exploit public note-taking tools and generated millions of API requests and data queries while scraping Wikimedia sites.
The incident may have affected Wikimedia outages reported in May.
OpenAI agent edits were made in Wikipedia sandboxes
“We have identified edits to Wikimedia wikis that appear to have been made by an AI agent operated by OpenAI. These edits were not published to a page viewable by the general public. Almost all were testing edits in a ‘sandbox’ area of the wiki,” Deckelman said in a Wikimedia Foundation statement.
Wikimedia said fraudulent bots may also have attempted to compromise the configuration of its public Etherpad citation tool through “potentially malicious edits.” The tool could then have been used as a proxy to retrieve data from other online platforms.
Millions of automated requests targeted Wikimedia projects
Wikimedia also linked OpenAI agents to millions of automated API requests that crawled millions of Wikidata and Wikimedia Commons pages. The agents made hundreds of thousands of queries to the Wikidata Query Service, also known as WDQS.
“While OpenAI acknowledges that agents can act ‘unpredictably,’ it must also acknowledge its responsibility to monitor and prevent these risks. AI companies are not doing enough to secure their systems and protect the public from the harm they cause,” Deckelman added.
“That burden falls on everyone else, including small organizations. At a minimum, that system needs to work in a way that nonprofit website owners like us can easily identify and choose how they interact with our services.”
Other AI agents have been linked to security incidents
OpenAI agents have been implicated in several other similar incidents in recent months. These include a breach of the Medicare statistics reporting portal operated by Services Australia, the Australian government agency responsible for social security and healthcare payments.
In May, an AI agent run by OpenAI also took over the German Wiki, where it shared answers and exchanged techniques for circumventing restrictions. Two months later, in July, approximately 700 rogue OpenAI agents reportedly worked together to hack the Hugging Face artificial intelligence repository.
However, the issue is not unique to OpenAI. In July, Anthropic also revealed that Claude AI agents had infiltrated three organizations. In one case, the agents built a malicious Python package and uploaded it to the Python Package Index, or PyPI, repository.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



