OpenClaw is an open-source AI agent that runs on your local machine and takes actions on your behalf. It can execute terminal commands, edit files, drive your browser, and call APIs. In principle, it is what most people mean when they talk about "an AI that actually does things." In practice, it is the case study for why the current agent ecosystem is not yet safe to point at your business.

This is a different call than the Claude Cowork playbook posted earlier this month. Cowork is imperfect but built by a single company that owns both the product and the safety posture. OpenClaw is an open-source project with a community skills ecosystem that inherits your credentials and permissions. That difference is the whole article.

The receipts

What has actually happened in the wild in the last six months.

None of this means OpenClaw is unusable forever. It means OpenClaw is unusable on the machine that has your customer database, your accounting login, and your production credentials on it.

Why the risk model is different from Claude Cowork

Cowork inherits the same underlying risks that any agent inherits: prompt injection, over-broad permissions, the classic "agent does thing you did not ask for" pattern. The Cowork playbook (sandbox folder, "Act without asking" off, activity log review) applies just as much to any other agent, including OpenClaw.

But Cowork has three structural advantages OpenClaw does not.

  1. A single vendor owns both the product and the safety infrastructure. When Anthropic ships an update to the content classifier that catches 99 percent of prompt injection attempts, every Cowork user gets it. There is one place to file a security report and one place to patch.
  2. There is no plugin ecosystem in the same sense. Cowork's tools are curated. OpenClaw's skills marketplace is open, which is the whole point of an open-source project, and also the reason malware slips through.
  3. Cowork does not run as a background service that other software can talk to over the network. OpenClaw does. That is why 30,000 instances turned up on the public internet with weak authentication.

None of these are moral failings on OpenClaw's part. They are the trade-offs of open-source software vs. a commercial product. But if you are a business owner and someone on your team wants to install a personal AI agent, this is the trade-off you should understand before you say yes.

Should you run it at all?

Yes, actually. But not on the machine that touches anything sensitive.

The pattern for exploring OpenClaw today is the same one that used to apply to bleeding-edge software before enterprise trust could develop.

If that sounds like a lot of overhead just to try a piece of software, it is. That overhead is the tax the current agent ecosystem is charging for the privilege of running something that can do real work autonomously on your machine.

What to run instead if you want to actually get work done today

Each of those has an accountable vendor, a published security posture, and a support channel. That is what you want on the machine you actually work on.

What OpenClaw is actually good for right now

It is a live demonstration of how autonomous local agents are going to work when the safety infrastructure catches up. Every attack researchers document against OpenClaw is one that will hit whatever commercial product does the same job in eighteen months. If you run OpenClaw in a sandbox and follow the security research, you are getting a preview of the risks your organization will inherit when a mainstream vendor ships the equivalent.

That is worth doing. It is not worth doing on your production machine.

Bottom line

OpenClaw is an important project. It is also a security surface with more than 30,000 exposed instances, an 84.6 percent system-prompt extraction rate, real observed autonomous actions gone wrong, and a plugin ecosystem researchers have documented as an active malware vector.

If a team member asks to install OpenClaw on their work laptop, the answer is no. If they want to run it in a virtual machine as a personal learning tool, that is a different conversation. If they want to deploy it against your customer data, that is a no.

For an accountable alternative that does most of what an agent should do without the current safety debt, start with Cowork. When the OpenClaw ecosystem matures, and it will, the calculation will change. For the broader executive framework on evaluating AI tools before you commit, see The AI Owner's Manual.