By Val Thomas • February 2026
A powerful new AI assistant has captured the world’s attention. In just weeks, OpenClaw (formerly ClawdBot, then Moltbot) became one of the fastest-growing technology projects in history, attracting hundreds of thousands of users worldwide.
The pitch is simple: an AI assistant that runs on your infrastructure, connects to your messaging platforms, and actually does things. Read documents, send emails, automate tasks, conduct research, analyze data, and execute commands. All through text conversations.
I’ve been watching this unfold and spent the last few days testing OpenClaw on a sandbox machine. The excitement makes sense. OpenClaw represents something different: a personal AI assistant that acts instead of just answering questions. But there are some serious caution signs, and most enterprises should take a different path right now.
Why the Buzz Is Real
OpenClaw gives businesses what they’ve been asking for. An AI assistant running on your hardware with your data, not in someone else’s cloud. Hardware requirements are minimal. Any modern PC is more than capable. Users report finishing in 2-3 minutes what used to take half an hour. It works around the clock, costs far less than human labor for routine work, and finds information instantly without searching through file systems.
The capabilities are genuine. One user’s assistant negotiated a $4,200 dealer discount on a car purchase without human involvement. Another user cleared 4,000+ emails in two days by letting the agent work overnight, automatically unsubscribing from spam, categorizing by urgency, and drafting replies. A complete website was built in minutes from a phone. Firms are using it to automate onboarding, saving hours of administrative work. These aren’t demos or pilots, these are actual deployments.
The Security Problem Nobody’s Talking About Enough
Here’s where things get complicated. OpenClaw’s power comes from having very few restrictions. That flexibility is exactly what makes it useful. It’s also what makes it risky.
Security researchers just found something concerning. The community marketplace where users share add-on capabilities is contaminated. One in eight downloadable components contains malicious code.
One of OpenClaw’s own creators put out this warning: “If you can’t understand how to run a command line, this is far too dangerous of a project for you to use safely.”
The people building this are telling non-technical users to stay away. That should tell you something.
The security issues aren’t bugs that will get fixed in the next update:
- The assistant can access and share anything you allow it to see.
- Attackers hide instructions in documents or emails the assistant reads.
- Complete conversation histories sit on your servers (anyone with file access has access to everything discussed).
- The add-on marketplace has no effective screening process.
Real organizations have already learned hard lessons. Assistants dumping entire organizational charts to group chats. Clever social engineering requests that trick the system into sharing confidential information. One early user had their assistant accidentally start a fight with their insurance company after misinterpreting a response. These aren’t edge cases. They’re normal operating conditions.
What Changed Last Weekend
OpenAI CEO Sam Altman announced that OpenClaw’s creator, Peter Steinberger, is joining OpenAI. The technology, according to Altman, “will quickly become core to our product offerings.” OpenClaw itself will continue as an independent project with OpenAI backing it.
Two things matter here.
First, it validates what OpenClaw is doing. When OpenAI brings someone on board and commits to supporting their technology, take notice.
Second, it means commercially supported versions are probably 60-90 days out (probably less with the way AI is evolving faster and faster these days). OpenAI will release something. Microsoft, with IP rights in OpenAI, will integrate it. Google and Amazon will respond. All of them will have security teams, compliance frameworks, and someone to call when things break.
Which raises an obvious question: why take on the operational burden and security exposure now when vendor-managed alternatives are coming soon?
What Exists Today
You have options depending on what you need.
- Microsoft Copilot Studio works for organizations already using Microsoft 365. Yes, it’s less autonomous than OpenClaw, which is actually a feature for most business applications. You get enterprise security, compliance certifications, and workflows that require human approval for sensitive operations. Process times have been cut by 90 percent while reducing administrative work by 30 percent with the right application of Copilot Studio.
- Google and Amazon should announce competing products within weeks based on typical competitive response times.
- OpenAI’s commercial version should arrive in 60-90 days if Altman’s “quickly” means what it usually means in this industry.
The pattern is consistent. All these alternatives trade some autonomy for managed security and vendor accountability.
What Makes Sense Right Now
OpenClaw deserves a lot of credit. It showed what’s possible and changed how the entire industry thinks about AI agents. But showing what’s possible and being ready for production deployment are different things.
If you’re thinking about AI agents for your organization, here’s how I’d approach it.
- Wait 60-90 days unless something absolutely cannot wait. Commercial alternatives are arriving with security teams, compliance frameworks, and someone accountable when things go wrong.
- Use what you already have if you need something immediately. Microsoft, Google, and Salesforce ecosystems all have enterprise AI options available now.
- Consider OpenClaw only if you have exceptional internal security capabilities, can build everything custom without using the compromised marketplace, and can justify the exposure when commercial turnkey alternatives are weeks away.
The security issues are not theoretical. They are documented. One bad download, one configuration mistake, one social engineering attempt, and you’re in front of your board explaining how sensitive information got out.
The technology is genuinely impressive, but timing may be wrong for most organizations. Commercial providers will harden the security, handle compliance, and take responsibility when problems occur. That’s worth waiting for.
The agent revolution is real. Make sure you’re positioned to benefit from it instead of becoming a cautionary tale.
What’s your experience? Are you testing AI agents in your organization? I’d genuinely like to hear what’s working and what concerns you’re navigating.
Originally published on LinkedIn, February 2026.



