Earlier this week, the Wikimedia Foundation, which operates the Wikipedia website, confirmed it had discovered some activity by “rogue” OpenAI agents on its platforms. The unauthorised activities included edits to its wikis, some unsuccessful attempts to exploit a public note-taking tool the company hosts and a significant increase in traffic to the site.
In a blog post, Wikimedia Foundation chief product and technology officer Selena Deckelmann, said: “These types of successful intrusions can expose sensitive data or disrupt website services that users rely on, while clusters of agents can attempt attacks at a scale that is difficult for defenders to manage. They affect people behind the websites who may not understand the nature of the attack, or have the tools to effectively fight back.”
While the attack targeted the online encyclopaedia, which is maintained by a global community of contributors and editors, it shows that any website that enables user-generated content, such as reviews on an ecommerce site, may become targets of similar AI attacks.
Commenting on the rogue agent activity, Jamie Beckland, chief product officer at APIContext, said: “OpenAI has a responsibility to ensure its agents operate within clearly defined boundaries. Agents making millions of requests, attempting unauthorised actions and potentially disrupting third-party services point to a serious failure of safety controls. Wikimedia shouldn’t have to bear the consequences of poorly controlled AI agents.
“Traditional approaches to monitoring and protecting infrastructure weren’t designed for the scale and unpredictability of autonomous AI,” he said. “Continuous verification needs to be part of every operational model. Every organisation operating public-facing services now needs to be equipped to recognise, manage and, when necessary, block inappropriate agent activity.”
Wikimedia’s investigation found AI agents operated by OpenAI made edits to Wikimedia entries, and edits made by the rogue OpenAI agents were not published to pages with visibility to general readers.
“Almost all of them were testing edits in ‘sandbox’ areas of the wiki,” said Deckelmann, but the rogue agent also made edits to the configuration for a citation tool, which Wikimedia believes were potentially malicious and intended to misuse tool as a proxy for fetching data from remote services.
APIs under attack
In 2025, the foundation reported that its bandwidth usage had increased by 50% due to the surge in bot activity on its websites since 2024. At the same time, 65% of the most resource-consuming traffic was coming from bots fetching data from remote services.
Deckelmann believes OpenAI made millions of automated requests to the Wikimedia public application programming interfaces (APIs) to crawl millions of pages from Wikimedia projects, Wikidata and Wikimedia Commons and make hundreds of thousands of data queries to the Wikidata Query Service (WQDS). “This traffic may have contributed to a partial outage on WQDS in May,” she added.
“This intense pressure on our infrastructure not only adds costs for servers and humans, but if left unaddressed, can block human visitors by overloading systems and causing outages,” Deckelmann warned in the blog post. “We are already paying for costs that come with the increased activity.”
She said AI companies were not doing enough to secure their systems and protect the public from the harm AI can cause. “That burden is falling onto everyone else, including smaller organisations,” added Deckelmann.
In a recent interview for the Computer Weekly Downtime upload podcast, Amazon Web Services vice-president of security services Rudra Mitra discussed why organisations need to rethink security for AI-powered attacks that happen at “machine speed” rather than bolting on AI-specific security measures to an existing enterprise IT security strategy.
“I think security today looks like it’s human-centred with AI assisting,” he said.
This, said Mitra, is state-of-the-art, and implies the speed of a response to a cyber threat is very much governed by the humans, where the IT security operations team still relies on monitoring security dashboards, assesses the risk and takes appropriate actions. “I wonder if we should be thinking about redesigning security completely for machines,” he said.
Government control and regulations
In spite of several recent cases of frontier models going rogue, policymakers in the US and the UK appear to be taking a pro-innovation approach to AI legislation. Earlier this month, US president Donald Trump, while rebranding AI as “super intelligence”, brushed aside questions on AI safety, stating instead that OpenAI, Anthropic, Nvidia, SpaceX, Meta and Google had signed a “morally binding” agreement for protection against rogue AI.
While the group of tech entrepreneurs flagging Trump promised self-regulation, David Robinson, who led Open AI’s AI safety reports for each release of the frontier AI model, resigned from the company, claiming the culture at OpenAI and across Silicon Valley is broken. “The future depends on wisdom that Silicon Valley lacks,” he wrote in an article published in The Atlantic.
In the article, Robinson spoke about how the people working on AI safety at companies like OpenAI and Anthropic are unable to keep up with the pace of development.
Last month, US congressmen Josh Gottheimer and Mike Lawler introduced the bipartisan Stop Rogue AI Act, which they said would ensure businesses and federal agencies have the ability to see rogue and dangerous AI agents operating inside their own networks, and stop them before they cause real damage.
“We’ve already seen AI systems hack organisations on autopilot, with no person at the wheel,” said Gottheimer.
Lawler said: “We need to make sure we know what these systems are, what they can access, and who is responsible for them. We can harness the benefits of AI while making sure these systems don’t operate in the shadows of the networks they have access to.”

