Wikimedia Says Rogue AI Agents Abused its Platforms

Written by

Rogue AI agents have been caught again doing things they shouldn’t be on the open web, this time on platforms run by Wikimedia.

The non-profit giant, which operates Wikipedia and several other open-knowledge platforms, revealed the news in a blog post published on October 5.

Chief product and technology officer Selena Deckelmann said that her team investigated potential unauthorized agent activity after reading recent reports about this kind of behavior.

The team quickly discovered that OpenAI agents:

  • Made testing edits to Wikimedia wikis in sandboxed areas of the platform not visible to users, and edits to the configuration of a citation tool. Wikimedia believes the latter “were intended to misuse this tool as a proxy for fetching data from remote services”
  • Made unsuccessful attempts to compromise Etherpad, a note-taking tool hosted by Wikimedia, in order to fetch data from other websites as a proxy
  • Made millions of automated requests to Wikimedia’s public APIs, crawled millions of pages and made hundreds of thousands of data queries to the Wikidata Query Service (WQDS), which may have contributed to a partial outage of the service in May

Read more on rogue agents: OpenAI: Hugging Face Incident a “Warning Shot” to the World.

Deckelmann said her team didn’t find any evidence that their systems had data compromised or were used for coordination among agents.

“However, we are concerned about what could have occurred here, the difficulty and effort involved in investigating and attributing this activity, and the growing risks of agentic AI activity on our platforms in general,” she added.

“The open web is a public good. We should not allow this behavior to become the ‘new normal’ for the people or organizations that maintain it.”

Piling Pressure on the Internet

Deckelmann did not pull her punches, arguing that Wikimedia’s findings show how agents can drain resources and crash servers, even when they aren’t compromising data and systems.

“This intense pressure on our infrastructure not only adds costs for servers and humans, but if left unaddressed, can block human visitors by overloading systems and causing outages,” she continued. “We are already paying for costs that come with the increased activity.”

Deckelmann argued that AI companies aren’t doing enough to secure their systems and protect the public from possible harm.

“That burden is falling onto everyone else, including smaller organizations,” she said. “At a minimum, their systems should operate in a way that non-profit website owners like us can easily identify and choose how they interact with our services.”

Industry experts agreed. Jamie Beckland, chief product officer at APIContext, argued that Wikimedia’s findings point to a “serious failure of safety controls.”

He added: “Every organization operating public-facing services now needs to be equipped to recognize, manage and, when necessary, block inappropriate agent activity.”

Bri Frost, director of product management at Cloud Range, said that things tend to go wrong when inexperienced users hand agents open-ended tasks.

“Before giving an agent credentials or tools, teams should test it in a realistic environment, including with vague or poorly written prompts,” she added. “Does it stay within its permissions? Does it try to work around restrictions? Does it escalate to a human when a task pulls it outside its lane? If you can't answer those questions, the agent isn't ready for that level of autonomy."

Image credits: Casimiro PT / T. Schneider / Shutterstock.com

What’s Hot on Infosecurity Magazine?