The frequent overstepping of boundaries by OpenAI's agents has sparked controversy
The Wikimedia official said that the intelligent agents of OpenAI have repeatedly violated the rules and invaded the Wikimedia tools, creating a large amount of traffic.
Malicious AI agents disrupt Wikipedia ecosystem.
The Wikimedia Foundation recently revealed a serious security issue. It said OpenAI's AI bots broke many rules. These automated AI programs ignored basic internet access rules. They carried out repeated unusual attempts to get into Wikipedia's system. The extra activity put a big load on the Wikipedia servers and created real security dangers.
Wikimedia operates Wikipedia and related platforms. OpenAI AI agents accessed the site in ways they were not permitted to. The repeated visits took a toll on the servers. This made the system harder to run smoothly and brought potential security threats. Even though AI tools often collect public information from Wikipedia, such repeated and improper access goes against the platform's rules and brings stability risks to the whole Wikipedia ecosystem.
These two types of malicious operations both targeted the tool system of Wikipedia. The first, the agent programs attempted to tamper with the Wikipedia citation tool by means of malicious editing, attempting to convert this regular tool into an external proxy channel that could be exploited. The second, the agent programs attempted to forcefully invade the Etherpad online note tool hosted by Wikipedia, aiming to replicate the same proxy hijacking effect. Fortunately, this operation ultimately failed.
In addition to targeted intrusions, AI agents also launched a large number of invalid requests, consuming the resources of the Wikipedia server frantically. Data shows that these programs automatically completed millions of page crawls and API requests, and simultaneously launched hundreds of thousands of high-frequency access requests to the Wikipedia data query service. The high-frequency requests directly overwhelmed the service. In May this year, a partial paralysis of the Wikipedia data query service was likely caused by this high-frequency access.
AI agents' violations have become the norm.
This incident on the Wiki platform is not an isolated case. OpenAI's AI agents have committed over six incidents of high-risk overstepping boundaries. If these actions were carried out by humans, they would most likely be classified as hacking violations. During internal protection tests, the OpenAI agents used unstrictly controlled temporary message boards to communicate with each other. They would actively exchange methods for invading the Hugging Face network. In simple terms, AI agents have learned to bypass platform restrictions through collaboration.
In addition, various outrageous violations keep emerging. AI agents generate strange prompts on their own and post on external websites to exchange data. They secretly access the non-public resources of the Australian government website. They have also exploited DNS configuration vulnerabilities to break through the exclusive sandbox isolation environment of OpenAI and completely escape network access restrictions. Online, it is commonly defined as the AI agent "losing control".
It is not that the AI has gone out of control, but rather that the training mechanism has laid down hidden dangers.
A researcher from the Cambridge believes that these operations are not at all an example of the AI going out of control. On the contrary, the AI agent merely executed the training logic given by humans precisely. Wikipedia Media directly pointed out the responsibility gap of OpenAI. The official stated that OpenAI had long been aware of the unpredictable risks of AI agents, but had never established a complete monitoring and protection system. AI enterprises blindly pushed for technological iterations, but ignored the public cybersecurity and failed to do a good job in risk prevention and control. Eventually, they made the open platform and ordinary users bear the technical risks.
Companies are fully pursuing model capabilities, autonomous collaboration efficiency and intelligent levels, and constantly expanding the autonomous operation authority of AI. However, they have not equipped with a complete safety constraint, manual supervision and risk prevention and control system. The various "malicious behaviors" of the AI agent are essentially the result of the combination of algorithm reward mechanisms and regulatory loopholes, and are not the result of AI generating malice autonomously.