OpenClaw Launches Free Open-source Enterprise Agent Platform for AI Agents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


OpenClaw has launched OpenClaw Enterprise (OCE), a free, open-source platform that helps organizations run persistent AI agents with stronger security and central oversight.

Announced on September 29, 2026, the project targets businesses that want agents to handle ongoing work without giving them unchecked access to sensitive systems.

The platform remains under development ahead of its planned 1.0 release later this year. OpenClaw recommends it for internal pilot workloads, not as a finished product ready for broad production use.

OpenClaw Free Enterprise Platform

OCE adds an enterprise control plane, a central layer for deploying agents, setting rules, and tracking their activity. It supports multiple teams through multi-tenancy, with security boundaries intended to separate trusted services from untrusted workloads.

According to the platform announcement from OpenClaw, its security design combines sandboxing, fine-grained permissions, and reviews performed by large language models.

These controls aim to limit what agents can access and do while preserving their ability to complete useful tasks. Governance and audit records extend across the agent lifecycle, helping operators trace activity and review decisions.

The approach addresses a concern raised in OpenClaw’s announcement: many organizations still block agent platforms because shared security, safety, and governance standards remain weak. Agents that can read internal data, run code, or use plugins need controls beyond instructions telling them to behave safely.

That concern has practical roots. Cybersecurity News previously reported on OpenClaw data leaks through indirect prompt injection, where malicious instructions hidden in external content could trigger the release of sensitive information.

Separate coverage of log poisoning showed how attacker-controlled log entries could influence an agent’s troubleshooting context. Those reports concern earlier OpenClaw issues, not newly disclosed OCE vulnerabilities.

The project began at OpenAI before being donated to the OpenClaw Foundation, where it now operates independently. Red Hat and NVIDIA are collaborating on development. The public repository uses the MIT license, and the foundation says OCE will remain free for organizations to use.

Vendor neutrality is central to the design. Organizations can replace the model, sandbox, and agent harness- the software that connects the model to tools and tasks- with third-party or internal options. This lets teams keep their existing infrastructure rather than depend on one provider.

Organizations can self-host OCE using its GitHub repository and getting started documentation. Kubernetes supports internal deployment.

The current repository also notes that its default Compose preview runs the control plane but cannot deploy agents; the local agent walkthrough uses a Kubernetes profile. Free software does not remove infrastructure or model-service costs.

OpenClaw says OpenAI and Red Hat are piloting the platform internally. OpenAI staff member RJ Marsan described Androidclaw, an internal enterprise agent, helping investigate broken builds, locate incident records, and prepare fixes with supporting evidence.

These examples show why access control matters: an agent connected to code, logs, and collaboration tools can act across several sensitive systems.

The repository separates identity and role management from audit processing, including tools for removing sensitive values from audit events, offering another area for teams to inspect.

The foundation plans to publish a security reference architecture in the coming weeks. For security teams, the immediate value is an open platform they can inspect and test. Its early status also means organizations should verify isolation, permissions, audit coverage, and plugin behavior before expanding access to critical workloads.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

The post OpenClaw Launches Free Open-source Enterprise Agent Platform for AI Agents appeared first on Cyber Security News.