Quick Facts
- OpenClaw Enterprise is MIT-licensed and free to self-host, positioning itself as a governance and security layer for persistent AI agents in multi-user enterprise environments.
- The project originated at OpenAI, was donated to the independent OpenClaw Foundation, and was developed further with contributions from Red Hat and Nvidia.
- The broader OpenClaw framework has 389,000-plus GitHub stars and its npm package logged more than 3.3 million downloads in a single week as of early September 2026.
The OpenClaw Foundation launched OpenClaw Enterprise on Sept. 29, a free, open-source control plane designed to govern persistent AI agents running inside large organizations. The project is MIT-licensed, self-hostable, and backed by engineering contributions from OpenAI, Red Hat, and Nvidia.
The foundation describes it as "Kubernetes for agents" — a management layer that sits above individual agent runtimes and gives IT teams centralized control over what those agents can access and do.
The Governance Problem
Kevin Lin, OpenClaw Enterprise Lead at OpenAI, put the challenge plainly. "The main feedback we hear from organizations is that a stronger common security, safety, and governance standard is needed before agents can be fully adopted," Lin said. "As a consequence, the default stance of IT in most organizations is to ban agentic platforms like OpenClaw altogether."
Lin acknowledged that "actual deployment of persistent agents remains limited" despite the technology's availability. OpenClaw Enterprise is the foundation's answer to that gap.
What the Platform Does
The core of the release is the OpenClaw Control Plane, a deployment and lifecycle management layer for agents. It adds multi-tenancy, hard security boundaries between trusted and untrusted workloads, fine-grained permissions, sandboxing, and tamper-evident audit logging.
An identity and access management layer handles roles and identities. An audit module sanitizes sensitive values. An agent scoping system defaults to deny-by-default tool allowlists, meaning agents can only use tools explicitly permitted by administrators.
Organizations can replace core components — including the model harness, the underlying model, and the sandbox — with their own implementations or third-party solutions. The platform runs locally via Docker Compose and deploys to cloud environments through Kubernetes.
Who Built It and Why
OpenClaw was created by Austrian developer Peter Steinberger, who first released it in November 2025 under the name Warelay. It launched as OpenClaw on Jan. 30, 2026. Within its first week, the project crossed 100,000 GitHub stars and drew 2 million visitors.
On Feb. 15, 2026, OpenAI CEO Sam Altman announced that Steinberger was joining OpenAI to work on personal agents, while confirming OpenClaw would remain open source under independent foundation governance. OpenClaw Enterprise originated at OpenAI and was subsequently donated to the OpenClaw Foundation, a 501(c)(3) nonprofit. The foundation states that donors do not own or direct the project.
Red Hat announced its sponsorship of the foundation alongside the launch. The company is contributing engineering expertise in Linux, Kubernetes, distributed systems, security, and enterprise infrastructure.
Scale and Adoption
The broader OpenClaw project now carries 389,219 GitHub stars and 81,779 forks as of early September 2026. The openclaw npm package recorded 3,328,302 downloads in the week ending Sept. 6, 2026. OpenClaw 2.0, released Aug. 30, drew 933 contributors and more than 16,000 pull requests.
Not all signals are clean. Security researchers have documented more than 135,000 internet-exposed OpenClaw instances across 82 countries. At its peak, the ClawHub marketplace hosted approximately 1,184 malicious skills — a risk that enterprise governance tooling is specifically designed to address.
A Real-World Test Case
OpenAI Member of Technical Staff RJ Marsan described an internal agent called Androidclaw that operates across company context, Git, GitHub, and logging systems. The agent investigates broken builds, identifies relevant pull requests, traces product problems back to incidents, and in some cases prepares and merges fixes. Marsan called its ability to trace issues and publish fixes "kinda game changing" and said the agent has been "well-adopted" internally.
For enterprise technology leaders, the release signals a shift in the agent market. The hard problem is no longer whether an AI model can execute a task. It is whether a company can safely let persistent agents touch production systems, internal repositories, credentials, and enterprise data at scale.
This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.
