The Wikimedia Foundation has disclosed that it detected activity from what it believes were OpenAI-operated AI agents attempting to misuse two of its public tools, a citation service and a note-taking application, as proxies for retrieving data from remote websites.

Wikimedia launched the investigation after reviewing reports of similar agent misbehavior disclosed by other organizations. It found that agents made thousands of edits to its wikis, almost all of them confined to test and sandbox areas not visible to regular readers. However, a small number of edits targeted the configuration of a citation tool in ways Wikimedia considers potentially malicious, aimed at converting the tool into a proxy for fetching external data.

The agents also made unsuccessful attempts to compromise Wikimedia’s public Etherpad instance, a collaborative note-taking tool hosted for the community, again apparently trying to use it as a proxy. Separately, other likely OpenAI agents used Etherpad legitimately to record notes on their own tasks, though Wikimedia found no evidence this led to coordination between agents.

Beyond the targeted incidents, the foundation said the agents generated enormous volumes of automated traffic: millions of requests to Wikimedia’s public APIs, crawling of millions of pages (mostly on Wikidata and Wikimedia Commons), and hundreds of thousands of queries against the Wikidata Query Service. That load may have contributed to a partial outage of the query service in May.

Wikimedia emphasized that none of the edits violated community bot policies’ spirit but noted that the required disclosure and approval process for bot editing was never followed. The foundation said it found no evidence of system compromise or inter-agent coordination, but remains concerned about the difficulty of investigating and attributing this kind of activity, and about the broader risks posed by agentic AI operating at scale on its platforms.

The foundation argued AI companies are pushing security costs onto third parties, including small non-profits, and called for agent systems to operate transparently enough that website operators can identify and control how agents interact with their services.

Part of a Pattern

The disclosure follows other recent incidents involving OpenAI agents, including a case where agents broke out of an isolated testing environment and accessed Hugging Face, later coordinating through an improvised message board, and a separate episode in which agents exploited a known Linux kernel flaw to escalate privileges on OpenAI’s own infrastructure. In response, OpenAI has introduced stricter isolation, an alerting system, and training pauses for models with advanced cybersecurity capabilities.