{"slug": "wikimedia-foundation-openai-agents-tried-to-edit-pages-and-compromise-notes-tool", "title": "Wikimedia Foundation: OpenAI agents tried to edit pages and compromise notes tool", "summary": "The Wikimedia Foundation published an investigative report on October 5, 2026 finding that OpenAI agents made unpublished edits to Wikipedia pages, attempted \"potentially malicious edits\" to misuse a citation tool as a data-fetching proxy, and unsuccessfully tried to compromise the community-hosted note-taking tool Etherpad. Wikimedia also attributed millions of automated requests, millions of crawled pages and hundreds of thousands of data queries from OpenAI agents to a partial outage of a Wikimedia service in May 2026, and said it found no evidence the agents used its sites to coordinate or steal information. OpenAI did not respond to requests for comment, and the report follows a Senate hearing at which members of both parties floated holding AI companies liable for damage caused by their agents.", "body_md": "# Wikimedia Foundation: OpenAI agents tried to edit pages and compromise notes tool\n\nOpenAI agents tried to compromise a public note-taking tool, attempted to edit Wikipedia pages and possibly contributed to site disruptions earlier this year, according to a new statement from the Wikimedia Foundation.\n\n The nonprofit [released](https://wikimediafoundation.org/news/2026/10/05/openai-rogue-agent-activities-found-on-wikimedia-projects/) a detailed investigative report about a series of incidents involving OpenAI agents that repeatedly abused the site’s rules and took several unauthorized actions.  \n\nThe California-based foundation is best known for hosting and running Wikipedia — which has more than 67 million articles across 300 languages. It has become one of the most popular sources of information over the last decade, allowing people to make verified edits to pages.\n\n The organization’s investigation found [edits](https://security.wikimedia.org/data/openai-wikimedia-edits-2026-10-04.csv) made to Wikipedia pages by OpenAI agents that were not published. The agents also made “potentially malicious edits” that were intended to misuse a citation tool “as a proxy for fetching data from remote services.” \n\nWikipedia does allow bots to make edits to pages when they are disclosed and approved by community editors, but those rules weren’t followed in this incident.\n\nWikimedia also found two other issues tied to OpenAI agents, including unsuccessful attempts to compromise Etherpad — a note-taking tool the organization hosts as a community service.\n\n “Agents unsuccessfully tried to use it to fetch data from other websites as a proxy. Other agents also likely operated by OpenAI took notes about their tasks, though this did not appear to turn into coordination,” Wikimedia said. The foundation noted that OpenAI’s agents have been seen compromising [public platforms](https://fortune.com/2026/09/07/openai-ai-agents-german-wiki-ran-their-own-message-board/) to communicate with one another. \n\n Wikimedia added that agents operated by OpenAI also made millions of automated requests to access the knowledge on Wikimedia projects, crawled millions of pages and made hundreds of thousands of data queries to the site — potentially contributing to a [partial outage](https://wikitech.wikimedia.org/wiki/Incidents/2026-05-13_wdqs) of a Wikimedia service in May.  \n\nOpenAI did not respond to requests for comment. Wikimedia said it began the investigation after recent reports found allegedly “rogue” AI agents tried to break into websites and other online services to use them for unrelated tasks.\n\n New reports continue to emerge weekly detailing the ways AI agents [misuse platforms](https://therecord.media/openai-cyberattack-hugging-face), [breach government systems](https://therecord.media/openai-apologizes-australia-medicare-breach) and [access sensitive data](https://therecord.media/openai-australia-health-breach). \n\nAt a Senate hearing last week, multiple members from both parties floated the idea that AI companies should be liable for the damage their agents cause.\n\n## Drain on resources\n\nWikimedia said that the activity it observed could be tough for many web platforms to confront, given that they may not have the staff or funding to afford investigations or recovery efforts.\n\n“For a site like Wikipedia, agents might find and use security vulnerabilities or make misleading edits at scale. Wikipedia’s volunteer editors and the Wikimedia Foundation’s security teams have to detect and undo that activity,” the nonprofit said.\n\nWikimedia’s investigation found no evidence that OpenAI agents used its sites to coordinate or steal information from the organization.\n\nBut Wikimedia said it is concerned by what the investigation did find and expressed concern about the amount of effort it took to uncover the activity.\n\nThe nonprofit said its employees have increasingly had to “clean up the mess left behind by AI agents” and now sees large bandwidth usage increases due to bot activity.\n\n Last week, researchers [said OpenAI agents scraped data](https://therecord.media/openai-software-attempted-to-secretly-scrape-data-from-dozens-of-websites) from more than 50 private and public sector organizations’ websites over a six-month period earlier this year. \n\nWikimedia said OpenAI needs to “acknowledge their responsibility to monitor and prevent these risks.”\n\n“AI companies are not doing enough to secure their systems and protect the public from the harm they cause. That burden is falling onto everyone else, including smaller organizations,” Wikimedia said. “At a minimum, their systems should operate in a way that non-profit website owners like us can easily identify, and choose how they interact with our services.”\n\n In an interview on Monday, OpenAI CEO Sam Altman [told](https://x.com/politico/status/2106851857423282648) Politico that the world “should accept some bad things happening for the benefits of this technology.” \n\nJonathan Greig\n\nis a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.", "url": "https://wpnews.pro/news/wikimedia-foundation-openai-agents-tried-to-edit-pages-and-compromise-notes-tool", "canonical_source": "https://therecord.media/wikimedia-foundation-openai-agents-report", "published_at": "2026-10-05 21:26:00+00:00", "updated_at": "2026-10-05 21:48:46.754432+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "ai-crawlers", "artificial-intelligence"], "entities": ["Wikimedia Foundation", "OpenAI", "Wikipedia", "Etherpad", "United States Senate"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/wikimedia-foundation-openai-agents-tried-to-edit-pages-and-compromise-notes-tool", "markdown": "https://wpnews.pro/news/wikimedia-foundation-openai-agents-tried-to-edit-pages-and-compromise-notes-tool.md", "text": "https://wpnews.pro/news/wikimedia-foundation-openai-agents-tried-to-edit-pages-and-compromise-notes-tool.txt", "jsonld": "https://wpnews.pro/news/wikimedia-foundation-openai-agents-tried-to-edit-pages-and-compromise-notes-tool.jsonld"}}