AI agents do not have to break into a website to cause problems. Wikimedia says OpenAI-linked agents may have helped knock one of its data services partially offline.
In an Oct. 5 disclosure, the Wikimedia Foundation said agents it believes were operated by OpenAI made millions of API requests, crawled millions of pages, and sent hundreds of thousands of queries to its Wikidata Query Service, or WDQS. Wikimedia found no evidence of a breach, but said the traffic may have contributed to a partial outage in May, showing how heavy agent activity can strain public web infrastructure even without a successful attack.
Wikimedia found edits, probing and heavy traffic
Wikimedia Foundation Chief Product and Technology Officer Selena Deckelmann said the investigation identified three main types of activity the foundation believes came from OpenAI-operated agents. According to Wikimedia, the activity included unauthorized wiki edits, unsuccessful attempts to exploit its public Etherpad service, and excessive data downloading.
- Wiki editing: Almost all edits were tests in sandbox areas, although Wikimedia also found changes to a citation-tool configuration it considered potentially malicious.
- Etherpad probing: Agents unsuccessfully tried to use Wikimedia’s public note-taking tool to fetch data from other websites as a proxy.
- Excessive downloading: Agents made millions of API requests, crawled millions of pages, and sent hundreds of thousands of queries to the Wikidata Query Service.
The Verge reported that Wikimedia found no evidence its systems were used for agent-to-agent coordination and no evidence that its systems or data were compromised. The clearest impact identified so far is therefore operational rather than a confirmed breach.
Bot traffic is becoming an infrastructure cost
In April 2025, Wikimedia reported that bandwidth used for multimedia downloads had increased 50% since January 2024, largely because of automated scraping. Bots also accounted for at least 65% of resource-intensive traffic reaching its core data centers. These figures describe broader bot activity, not just the suspected OpenAI agents. Heavy automated access can add pressure to servers and staff even when agents do not gain access to protected systems.
Engadget noted that Wikimedia offers a dataset for AI training and has partnered with some technology companies to provide streamlined access to its data, but OpenAI is not among those partners.
The issue is therefore not simply whether AI systems can use Wikimedia content. Wikimedia’s complaint centers on uncontrolled activity that consumes resources and bypasses normal approval processes.
What eWeek found
Wikimedia’s May incident report shows what the disruption meant for users: roughly half of external WDQS requests timed out at the peak, and six nodes served stale data for more than 20 hours. The report attributes the disruption to aggressive scrapers but does not identify OpenAI as their operator.
Activity | What Wikimedia found | Reported impact |
| Wiki edits | Mostly sandbox edits plus some citation-tool configuration changes | The edits did not appear on pages visible to general readers |
| Etherpad activity | Attempts to use the tool as a proxy | Attempts were unsuccessful |
| Automated data access | Millions of API requests and page crawls, plus hundreds of thousands of WDQS queries | May have contributed to a partial May outage |
| Compromise or coordination | No evidence found | No confirmed system or data compromise, or coordination on Wikimedia systems |
A failed exploit does not mean there was no impact. Heavy agent traffic can still put pressure on public-facing services and consume infrastructure resources, although Wikimedia has not established that OpenAI’s agents caused the May outage.
According to PCMag, Wikimedia shared its findings with OpenAI, which said it would analyze the activity and “share relevant information as that work progresses.” Until that analysis is available, the connection between the agents and the outage remains possible, not proven.
For enterprises deploying agents, the practical takeaway is to assess outbound request volume alongside permissions. Request limits, controlled retries, and logs identifying which agent contacted which service can help teams detect excessive automated activity before it overwhelms external systems.
For another case of AI agents putting pressure on public websites, read our look at how OpenAI agents hit a UN site 16,000 times and what went wrong.


