OpenClaw launched OpenClaw Enterprise (OCE), an open-source, vendor-neutral platform for centrally deploying and managing persistent AI agents in enterprise environments. Its OpenClaw Control Plane (OCC) is designed as a Kubernetes-like management layer that runs on an organization’s own Kubernetes infrastructure and governs agent deployment, isolation, permissions, credentials, configuration, and change records. Nvidia and Red Hat are among the companies supporting the enterprise push.
OCE remains pre-1.0 and is intended only for internal pilots while authentication and other security-relevant capabilities are completed. OpenClaw’s proposed security model combines workload isolation, sandboxing, granular permissions, and LLM-assisted review; CISOs evaluating the platform should treat it as an early-stage agent-management control plane and validate identity, credential handling, tenancy isolation, auditability, and policy enforcement before production deployment.

Track how attackers are adapting to this technology.
7 events from the most recent confirmed update back to the earliest known activity.
Austrian developer Peter Steinberger created OpenClaw, which later grew rapidly.
Snyk research reported that more than 280 OpenClaw and ClawHub skills exposed API keys and personally identifiable information, identifying a credential- and data-leakage risk in the skills ecosystem.
OpenAI, which initially housed the OpenClaw Enterprise effort, transferred the project to the independent OpenClaw Foundation. Red Hat and Nvidia contributed to its development, while OpenAI and Red Hat began internal testing.
OpenClaw introduced OpenClaw Enterprise, an open-source, vendor-neutral platform centered on the OpenClaw Control Plane for governing and managing persistent enterprise AI agents.
Zenity researchers demonstrated that indirect prompt injection in content processed by OpenClaw could induce it to create an attacker-controlled Telegram integration, creating a persistent external control channel. The proof of concept further used SOUL.md modification and a recurring Windows scheduled task for persistence, and showed escalation to execution of a Sliver C2 beacon on the host.
The original OpenClaw was reportedly susceptible to indirect prompt injection that could give attackers persistent control. Its central agent-customization hub had also reportedly hosted malicious payloads, prompting security concerns ahead of OpenClaw Enterprise.
OpenAI hired OpenClaw creator Peter Steinberger following the project's rapid growth.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
5 references tracked. Mallory keeps watching after this page renders.
thenewstack.io
Open sourceopenclaw.ai
Open sourcesnyk.io
Open sourcelabs.zenity.io
Open sourcesdxcentral.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.