TechForge

March 12, 2026

  • Agentic AI security concerns mount in respond to OpenClaw.
  • China stops state agencies running the software.
  • Meta threatens to fire staff who install it.

An open-source AI agent that books your flights, clears your inbox, and drafts your reports sounds like a useful tool. OpenClaw, which has undergone three name changes in as many months due to trademark disputes, does all of that and apparently a great deal more than its users intended. The tool has become the fastest test case for a question the enterprise technology world has been quietly dreading: what happens when an AI system that can act autonomously meets corporate infrastructure?

The answer, so far, has been messy.

One user reported the agent “went rogue” and spammed hundreds of messages after gaining access to iMessage. The response from governments and companies has been swift. Chinese authorities moved to restrict state-run enterprises and government agencies, including the largest banks, from running OpenClaw on office devices, citing potential security risks.

SecurityScorecard’s STRIKE team found over 135,000 OpenClaw instances exposed to the public internet in 82 countries, with more than 15,000 directly vulnerable to remote code execution. A separate analysis found that roughly 12% of the entire ClawHub skills registry – OpenClaw’s public marketplace for plugins – had been compromised with malicious code, including tools that installed keyloggers on Windows or Atomic Stealer malware on macOS.

China’s CNCERT, the country’s primary cybersecurity technical body, issued a second warning this week as major cloud providers Alibaba, Tencent, and ByteDance were actively promoting OpenClaw deployment, according to a South China Morning Post report. The gap between adoption enthusiasm and security caution has rarely been this visible.

Meta has warned employees that installing OpenClaw on work devices is strictly prohibited, with those who do so reportedly facing termination. Microsoft’s Defender Security Research Team put it bluntly: “OpenClaw should be treated as untrusted code execution with persistent credentials. It is not appropriate to run on a standard personal or enterprise workstation.”

The agentic AI security problem is structural

The risks here are not the product of sloppy coding that patches will eventually fix. They are intrinsic to what agentic AI is designed to do. Researchers describe a “lethal trifecta”: AI agents with access to private data, the ability to communicate externally, and the ability to ingest untrusted content.

OpenClaw, by design, ticks all three boxes. “The more access you give them, the more fun and interesting they’re going to be – but also the more dangerous,” said Colin Shea-Blymyer, a research fellow at Georgetown’s Centre for Security and Emerging Technology. The same autonomy that makes the tool compelling is what makes it a liability in enterprise environments.

According to CrowdStrike, if employees deploy OpenClaw on corporate machines connected to enterprise systems and leave it misconfigured, it can be turned into an AI backdoor capable of taking instructions from adversaries. To make it worse, traditional security tooling offers little protection.

Endpoint security sees processes running but cannot interpret agent behaviour; network tools see API calls but cannot distinguish legitimate automation from compromise; identity systems see OAuth grants but do not flag AI agent connections as unusual.

A Gartner report has characterised OpenClaw as “a dangerous preview of agentic AI, demonstrating high utility but exposing enterprises to ‘insecure by default’ risks like plaintext credential storage.”

What the bans are actually telling us

It would be easy to read the wave of restrictions as a story about one controversial tool. The more relevant reading, for enterprise decision-makers in Asia and beyond, is that agentic AI security has no established playbook yet – and the tools are arriving faster than the governance frameworks designed to manage them.

China’s approach illustrates the tension at the heart of this moment: Beijing is simultaneously promoting AI adoption through its national “AI plus” strategy while scrambling to guard against the data and infrastructure risks that come with it. That same tension exists in boardrooms in Southeast Asia, where appetite for AI-driven productivity is high and formal AI security policy is, in most cases, still being written.

Ben Seri, co-founder and CTO of Zafran Security, acknowledged to Fortune that there is little chance of containing user curiosity – but noted that enterprise companies will be much slower to adopt systems that are difficult to control. The problem is that enterprise adoption may not be a deliberate decision at all.

Shadow deployments, where employees connect personal AI tools to corporate Slack channels, email accounts, and internal systems without telling the security team, are already happening.

OpenClaw’s developer, Peter Steinberger, responded quickly to disclosed vulnerabilities, shipping over 40 fixes in a single release and patching the important ClawJacked flaw in 24 hours of disclosure. Such responsiveness is commendable, but, as Sophos noted, it does not resolve the underlying architecture: agentic AI (which in OpenClaw’s case, which is vibe-coded by large language models) is arriving and will creep into mission-critical workflows before ways to secure it exist.

The question enterprises need to be asking is whether they have any visibility into the agentic AIs already running in their infrastructure and what authority those systems might have been granted by the AI coding tools used to create them.

Want to experience the full spectrum of enterprise technology innovation? Join TechEx in Amsterdam, California, and London. Covering AI, Big Data, Cyber Security, IoT, Digital Transformation, Intelligent Automation, Edge Computing, and Data Centres, TechEx brings together global leaders to share real-world use cases and in-depth insights. Click here for more information.

Want to experience the full spectrum of enterprise technology innovation? Join TechEx in Amsterdam, California, and London. Covering AI, Big Data, Cyber Security, IoT, Digital Transformation, Intelligent Automation, Edge Computing, and Data Centres, TechEx brings together global leaders to share real-world use cases and in-depth insights. Click here for more information.

Tech Wire Asia is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.

About the Author

Dashveenjit Kaur

Dashveen writes for Tech Wire Asia and TechHQ, providing research-based commentary on the exciting world of technology in business. Previously, she reported on the ground of Malaysia’s fast-paced political arena and stock market.

Related

September 14, 2026

September 11, 2026

September 10, 2026

September 10, 2026

Join our Community

Subscribe now to get all our premium content and latest tech news delivered straight to your inbox

Popular

35545 view(s)
17827 view(s)
17798 view(s)
17436 view(s)

Subscribe

All our premium content and latest tech news delivered straight to your inbox

This field is for validation purposes and should be left unchanged.