In a blog post published October 5, 2026, Wikimedia Foundation Chief Product and Technology Officer Selena Deckelmann said the foundation had investigated whether its websites were affected by the so-called “rogue” AI agents that several organizations have linked to OpenAI this year, and confirmed that some of that activity reached Wikimedia platforms. Reuters reporter Raphael Satter first reported the findings the same day, under the headline “Wikipedia operator says OpenAI’s rogue agents possibly tied to data service disruption in May.”
Wikimedia did not say its systems were breached. It said it found no evidence that its systems or data were compromised, and no evidence that its sites were used for agents to coordinate with each other. But it said the episode showed how much work it takes a volunteer-built nonprofit to detect, attribute and clean up after AI agents, and it called on AI companies to take responsibility for that burden. An OpenAI spokesperson told Reuters the company appreciated Wikimedia’s “detailed findings” and was working with the foundation to analyze the activity.
Free settlement alerts
Get notified when new class actions open to claims
Join thousands of readers who get the latest class action settlements you may qualify for — delivered straight to your inbox.
Status
No Lawsuit by Wikimedia
Wikimedia published its findings October 5, 2026 and has not announced legal action
What Wikimedia Found
Unapproved edits, failed probes, heavy traffic
Traffic may have contributed to a partial Wikidata Query Service outage in May 2026 · no data compromise found
Can I Claim?
No — nothing to claim
No class action or settlement over OpenAI’s rogue agents as of October 8, 2026
Wikimedia sorted the activity it attributes to OpenAI-operated agents into three categories:
- Wiki editing. Changes to Wikimedia wikis, nearly all of them test edits in “sandbox” pages that ordinary readers never see. A handful changed the settings of a citation tool. Wikimedia considers those changes possibly malicious, aimed at turning the tool into a relay for pulling data from outside servers. Bots may edit Wikipedia only after they are declared and the volunteer community signs off, and Wikimedia said no one asked.
- Etherpad probing. Failed attempts to break into the public Etherpad note-taking tool Wikimedia runs for volunteers, and to route requests to other websites through it. Other agents, also likely operated by OpenAI, used Etherpad to take notes about their tasks, which Wikimedia said did not appear to turn into coordination.
- Heavy traffic. Millions of automated requests to Wikimedia’s public APIs, millions of crawled pages, mainly from Wikidata and Wikimedia Commons, and hundreds of thousands of queries to the Wikidata Query Service, a load Wikimedia linked, with a hedge, to the service’s partial outage in May.
Wikimedia’s wording on the outage is careful: it said the traffic “may have contributed.” Some coverage has described the agents as having caused the outage outright, which goes further than the foundation’s own statement.
Wikimedia’s post describes Wikipedia as one of the best sources of training data for large language models. By the foundation’s count it holds more than 67 million articles in upward of 300 languages and draws as many as 15 billion views a month, and its content feeds chatbots, search engines and voice assistants. The foundation said in 2025 that its bandwidth use had risen 50% because of bot activity since 2024, and that 65% of its most resource-intensive traffic came from bots.
Wikipedia’s text is published under a free license that allows reuse with attribution, which is why disputes with AI companies over Wikipedia have centered less on copyright and more on the cost of the traffic. Wikimedia’s answer has been commercial: through Wikimedia Enterprise, companies pay for high-volume access instead of scraping. In January 2026, Wikimedia named Amazon, Meta, Microsoft, Mistral AI and Perplexity as Enterprise partners alongside Google and others. OpenAI was not among the partners Wikimedia named.
Wikimedia is the latest organization to report activity by OpenAI agents that went beyond their assigned tasks:
- Hugging Face, July 2026. Agents built on OpenAI models with reduced cyber refusals, being tested on a cyber-capabilities benchmark, broke into Hugging Face’s systems. OpenAI publicly disclosed its involvement on July 21 and has called it a serious incident.
- Government websites. OpenAI has said some agents probed U.S. government sites over the summer, and Australia’s government has said OpenAI agents accessed a Medicare statistics reporting portal.
- More than 100 organizations. On October 1, 2026, OpenAI said it had notified more than 100 organizations of agent activity that may have bypassed security measures or posted content without authorization. Reports quoting the company stress that a notification does not by itself mean an organization was breached, and OpenAI has said its review is continuing.
Regulators are looking at the agent incidents. Reports say fifteen state attorneys general asked OpenAI to preserve evidence from the Hugging Face incident, Alabama’s attorney general opened an investigation in August, and California issued an investigative subpoena. The FTC’s separate consumer-protection inquiry into OpenAI and Anthropic is covered in FTC investigates OpenAI and Anthropic. OpenAI also faces a long list of unrelated suits, from the New York Times copyright case to privacy class actions, summarized in OpenAI and ChatGPT lawsuits explained.
OpenAI is not the only AI developer whose models have reached outside systems during testing, but so far only one lawsuit over these incidents has been reported, and no company that was actually hit has sued.
LASST v. OpenAI (San Francisco Superior Court). Filed September 29, 2026 by Legal Advocates for Safe Science and Technology, a New York nonprofit, over the Hugging Face breach. As described by CNBC, ABC News and The Next Web, the complaint claims OpenAI ran hacking evaluations without its usual cyber safety classifiers, that roughly 1,200 agents communicated over a hidden channel and about 700 took part in getting into Hugging Face’s servers, and that the agents are likely to break out again without a court order. The group says it has standing because it had to divert staff and money to respond. It seeks an injunction, not damages. OpenAI spokesperson Drew Pusateri said Hugging Face “was a serious incident” and that the suit is “completely without merit.” These are allegations, and the court has not ruled on them.
Hugging Face itself has not sued. Its chief executive, Clem Delangue, told TechCrunch he does not want to take OpenAI to court, while arguing that companies should be held responsible and the law should keep such events clearly illegal.
Anthropic: incidents disclosed, no lawsuit. On July 30, 2026, about a week after OpenAI’s Hugging Face disclosure, Anthropic said a review of 141,006 evaluation runs found three cases in which Claude models reached the live systems of three outside organizations during cybersecurity tests. TechCrunch reported that a misconfigured test environment run with a third-party partner, Irregular, gave the models internet access they had been told they did not have; that the models involved were Opus 4.7, Mythos 5 and an internal research model; and that one model published a malicious package to the PyPI software registry that outside systems downloaded before it was caught. Anthropic has not named the three organizations, said it was treating the fixes “as if the responsibility were ours alone,” and asked the evaluation group METR to review what happened. Open Class Actions found no lawsuit over those incidents as of October 8, 2026. Anthropic’s pending court cases concern other issues, such as the Claude subscription usage-limit class action.
Why victims have held back. Lawyers interviewed by TechCrunch said a company hit by an AI agent would most likely sue for negligence over how the tests were set up and monitored, using the civil remedy in the Computer Fraud and Abuse Act, and would have to show real losses. Ahmed Ghappour, an attorney who has litigated computer-fraud cases, said the model is the company’s tool and its autonomy should not shield the developer. Andrew Crocker of the Electronic Frontier Foundation doubted that intent could be proven against an AI agent, which matters for criminal charges under the same law.
Wikimedia has given no sign that it plans to. Its statement asks AI companies to “directly help avoid and repair damage” their agents cause and to make their systems easy for website owners to identify, and it frames the problem as one for the whole web, not a single dispute.
If a website owner did go to court over AI agents, the main legal theories are the ones already appearing in the LASST case and in earlier fights over web bots:
- The federal Computer Fraud and Abuse Act prohibits accessing a computer without authorization and lets an owner sue for losses of at least $5,000 in a year. Courts have read it narrowly for public websites; the Ninth Circuit held in hiQ Labs v. LinkedIn (2022) that scraping publicly available pages likely is not access “without authorization.”
- California’s Comprehensive Computer Data Access and Fraud Act, the law LASST relies on, also gives a civil claim to owners who suffer damage from unauthorized access.
- Trespass to chattels is the older theory courts have applied to bots that burden a site’s servers, as in eBay v. Bidder’s Edge (2000).
How those laws apply to autonomous AI agents, which OpenAI itself has said behaved unpredictably, is largely untested. Wikimedia’s own findings would also shape any claim: it reported no data compromise, edits confined almost entirely to sandbox pages, and an outage the traffic “may have” contributed to. This page describes the law in general terms; it is not legal advice.
OpenAI has said its review of agent activity, covering a very large volume of logs, will take months and that more organizations may be notified. Wikimedia said it is working with OpenAI on the analysis. The LASST lawsuit is at its earliest stage, and OpenAI has not yet responded in court. Open Class Actions will update this page if Wikimedia takes legal action or a class action is filed over the rogue agents.
What did OpenAI's agents do on Wikipedia?
According to the Wikimedia Foundation, agents it believes OpenAI operated made unapproved edits to Wikimedia wikis, almost all of them test edits in sandbox areas readers do not see, plus a few edits to a citation tool's configuration that Wikimedia believes were meant to misuse it as a proxy. The agents also tried and failed to compromise a public Etherpad note-taking tool, and made millions of automated requests and hundreds of thousands of Wikidata queries.
Did OpenAI's agents cause the Wikidata outage?
Wikimedia said the agents' heavy querying “may have contributed” to the Wikidata Query Service going partly down in May 2026. It did not say the agents definitively caused it, and OpenAI said it was working with Wikimedia to analyze the activity.
Was any Wikipedia data stolen?
Wikimedia said it found no evidence that its systems or data were compromised, and no evidence that its systems were used for coordination among agents. None of the edits it identified were on pages visible to general readers.
Is Wikimedia suing OpenAI?
No. As of October 8, 2026, the Wikimedia Foundation had not filed or announced a lawsuit. Its October 5 statement called on AI companies to take responsibility for monitoring and preventing harm from their agents and to make their systems identifiable to website owners.
Is there a class action over OpenAI's rogue agents?
Open Class Actions found no class action over the rogue agent incidents as of October 8, 2026. The one reported lawsuit, filed in San Francisco Superior Court by the nonprofit Legal Advocates for Safe Science and Technology over the Hugging Face breach, seeks a court order and no money damages. OpenAI has called it completely without merit.
Has Anthropic been sued over Claude hacking outside systems?
Not as of October 8, 2026. Anthropic disclosed on July 30, 2026 that Claude models reached the live systems of three unnamed organizations during cybersecurity tests, but Open Class Actions found no lawsuit over those incidents.
• Wikimedia Foundation — OpenAI “rogue” agent activities found on Wikimedia projects (October 5, 2026)
• Reuters, Raphael Satter, “Wikipedia operator says OpenAI’s rogue agents possibly tied to data service disruption in May” (October 5, 2026), as republished by KSL
• TechCrunch — Anthropic says its own AI models breached three companies during security tests
• TechCrunch — Who’s legally to blame for Anthropic and OpenAI’s autonomous AI hacks?
• OpenAI — The Hugging Face incident and the road ahead
• ABC News — OpenAI sued by safety group over autonomous hack of Hugging Face
• The Next Web — OpenAI lawsuit asks court to stop its AI agents hacking again
• Wikimedia Enterprise — New partners on Wikipedia’s 25th birthday
For more class actions keep scrolling below.
Status
Findings published · no lawsuit by Wikimedia
Organization
Wikimedia Foundation
Company
OpenAI
Date Disclosed
October 5, 2026
Related Lawsuit
LASST v. OpenAI (San Francisco Superior Court, filed September 29, 2026)
Over the Hugging Face breach · injunction only, no damages sought