‘Rogue’ OpenAI agents blamed for Wikipedia outage as safety concerns mount
“Rogue” OpenAI agents have been blamed for helping knock a Wikipedia service offline, the latest in a string of incidents involving the ChatGPT maker’s increasingly autonomous technology.
The Wikimedia Foundation said agents it believes were operated by OpenAI flooded its platforms with millions of automated requests, crawled millions of pages and made hundreds of thousands of queries.
The activity may have contributed to a partial outage of its Wikidata Query Service on 7 May, according to the non-profit organisation behind Wikipedia.
But Wikimedia said the agents went beyond simply harvesting data, making unauthorised edits to its sites and attempting to access other services.
“We are deeply concerned about the impact of ‘rogue’ AI agents on platforms like ours”, the foundation said.
OpenAI is already facing questions over how well it can control increasingly autonomous AI systems after a series of security incidents.
In July, an OpenAI agent breached AI developer platform Hugging Face after escaping the confines of a testing environment.
The company has since uncovered unexpected activity involving other organisations, including Australian government websites, and said it has notified more than 100 organisations as it investigates its agents’ behaviour.
OpenAI has also disclosed cases in which models concealed mistakes, acted without permission and found unexpected ways around instructions during testing.
The company delayed the release of its latest AI model following safety concerns and said it was spending more than $500,000 (£376,913) a day reviewing past activity for further unintended behaviour.
‘New normal’
Wikimedia said its investigations found OpenAI agents had made millions of automated requests to its public APIs and crawled millions of pages.
Almost all of their unauthorised Wikipedia edits were tests made away from ordinary readers.
However, several changes to a citation tool were considered “potentially malicious” and appeared designed to use it as a middleman to retrieve information from elsewhere.
Agents also targeted Etherpad, a collaborative note-taking service used by the Wikimedia community, although Wikimedia said there was no evidence its systems or data had been compromised.
The foundation warned the growing use of autonomous agents were placing additional costs on organisations forced to investigate their activity and protect infrastructure from unexpected behaviour.
“This intense pressure on our infrastructure not only adds costs for servers and humans, but if left unaddressed, can block human visitors by overloading systems and causing outages”, it said.
Wider safety row inside OpenAI
Safety leader David Robinson quit last month after three and a half years at the company, arguing its “culture is broken” and that companies developing frontier AI were not being “nearly careful enough”.
OpenAI has separately fired three researchers for allegedly mishandling sensitive company information, including a safety researcher who worked with outside organisations investigations the Hugging Face breach.
Chief executive Sam Altman has defended the company’s broader approach, arguing that society should accept some “bad things” happening as the tech develops in return for its benefits.
“I wouldn’t take a trade of saying we will make sure there’s no major hacks, there’s no misuse of this technology, there’s zero scams or all the other bad things that will happen”, he said in an interview last week.
Wikimedia, however, said organisations maintaining the infrastructure that AI agents rely on should not be expected to absorb the consequences.
“We should not allow this behaviour to become the ‘new normal’ for the people or organisations that maintain it”, it said.
OpenAI said it appreciated Wikimedia’s “detailed findings” and was working with the organisation to analyse the activity.
“We’ll continue to share relevant information as that work progresses”, said spokesperson Drew Pusateri.