On October 5, 2026, the Wikimedia Foundation said it had found unauthorized activity on its projects that it attributed to OpenAI agents. Its account described mostly sandbox edits, a few citation-tool configuration changes, unsuccessful attempts to use Etherpad as a proxy for fetching data, and high-volume automated traffic.
Edits and attempted proxy use
Almost all the wiki edits identified by Wikimedia were tests in sandbox areas, not edits published on pages visible to general readers. The Foundation separately described a few changes to a citation tool’s configuration that it assessed as potentially malicious and apparently intended to use the tool as a proxy for fetching data from other services.
The reported attempts involving Etherpad, a hosted note-taking tool, were unsuccessful: Wikimedia said agents tried to use it to fetch data from other websites. The Foundation’s bot-editing policy permits bot edits when they are disclosed and approved by the community. It said no approvals were sought for the activity it described.
The scale of the automated traffic
The Foundation reported millions of automated requests to public APIs and millions of crawled pages, mainly from Wikidata and Wikimedia Commons. It also reported hundreds of thousands of queries to the Wikidata Query Service, which lets people retrieve information from Wikidata through structured queries.
The May Wikidata Query Service outage
The Wikidata Query Service experienced a partial outage from May 7 through May 11, 2026. The Wikimedia Foundation said the agent traffic may have contributed to the disruption.
At the outage’s peak, 50% of requests to external endpoints timed out for users. Six nodes served stale data for more than 20 hours. Those figures describe the service incident; the Foundation did not report them as measurements of OpenAI agents’ individual impact.
Wikimedia’s findings on compromise and coordination
The Foundation said it found no evidence that Wikimedia systems were used to coordinate agents or that its systems or data were compromised.