# OpenClaw Foundation begins a free open-source enterprise control plane for AI agents > OpenClaw Enterprise, backed by Red Hat, Nvidia and OpenAI, aims to give organisations that ban AI agents a way to govern them. What is described, and what is unfinished. FireAI Security & Research Team (HisnLabs) ยท Published 2026-10-01 Canonical: https://hisnlabs.com/en/news/openclaw-enterprise-control-plane-foundation-business-bans The OpenClaw project has started work on OpenClaw Enterprise (OCE), an open-source control plane for governing persistent AI agents, with contributions from Red Hat, Nvidia and OpenAI. OpenAI's Kevin Lin announced it on 30 September 2026, saying that the default stance of IT in most organisations is to ban agent platforms such as OpenClaw [[1]](https://www.theregister.com/ai-and-ml/2026/09/30/openclaw-slips-on-a-suit-to-evade-widespread-business-bans/5299962) [[2]](https://thenewstack.io/openclaw-enterprise-kubernetes-agents/). The software is described as an early pilot-stage project, not a finished product [[2]](https://thenewstack.io/openclaw-enterprise-kubernetes-agents/). ## Background OpenClaw is an open-source, self-hosted AI agent harness that lets users build agents and connect them to applications and services [[3]](https://www.theregister.com/ai-and-ml/2026/08/31/openclaw-20-pours-glitter-on-slow-burning-security-dumpster-fire/5293492). The Register reports that Gartner labelled the project an "unacceptable cybersecurity risk" for business users and that China's national CERT warned of "extremely weak default security configurations" [[1]](https://www.theregister.com/ai-and-ml/2026/09/30/openclaw-slips-on-a-suit-to-evade-widespread-business-bans/5299962). The New Stack reports that OpenClaw has since set up an independent OpenClaw Foundation, with sponsors including OpenAI, Nvidia, Red Hat and GitHub [[2]](https://thenewstack.io/openclaw-enterprise-kubernetes-agents/). A separate Register report on 31 August 2026 about OpenClaw 2.0 noted that most security responsibility remained with users, and that sandboxing for contributor-controlled code was turned off by default [[3]](https://www.theregister.com/ai-and-ml/2026/08/31/openclaw-20-pours-glitter-on-slow-burning-security-dumpster-fire/5293492). ## What the reports describe Lin wrote that "the main feedback we hear from organizations is that a stronger common security, safety, and governance standard is needed before agents can be fully adopted," and that "actual deployment of persistent agents remains limited" [[1]](https://www.theregister.com/ai-and-ml/2026/09/30/openclaw-slips-on-a-suit-to-evade-widespread-business-bans/5299962) [[2]](https://thenewstack.io/openclaw-enterprise-kubernetes-agents/). He describes version 1.0 of OCE as introducing a control plane with support for multi-tenancy, hard security boundaries and standardised agent primitives, plus governance and auditability across the agent lifecycle, with the harness, model and sandbox replaceable by third-party or internal components [[1]](https://www.theregister.com/ai-and-ml/2026/09/30/openclaw-slips-on-a-suit-to-evade-widespread-business-bans/5299962). The New Stack describes the OpenClaw Control Plane (OCC) as the central place where administrators deploy agents, separate them into isolated namespaces, manage configuration and credentials, set permissions and keep a record of changes. Gateways receive messages, and harnesses handle agent turns, model calls and tool execution. Per the OpenClaw architecture documentation cited by the article, the API, console, persistent worker, PostgreSQL backend and Kubernetes packaging are implemented, while external gateway admission, workload authentication back to OCC and some approaches to model authentication are unfinished [[2]](https://thenewstack.io/openclaw-enterprise-kubernetes-agents/). On licensing and availability, Lin is quoted as saying that OCE "is built to run on your own infrastructure and will always be free for any organization to use." The code is on GitHub, 1.0 is planned for later this year, and the project is suitable for internal pilot projects only for now [[2]](https://thenewstack.io/openclaw-enterprise-kubernetes-agents/). The work "originally started at OpenAI and then was donated to the OpenClaw Foundation" [[1]](https://www.theregister.com/ai-and-ml/2026/09/30/openclaw-slips-on-a-suit-to-evade-widespread-business-bans/5299962). OpenAI and Red Hat are testing the software internally, and Red Hat's Joe Fernandes compares the effort to RHEL and OpenShift [[1]](https://www.theregister.com/ai-and-ml/2026/09/30/openclaw-slips-on-a-suit-to-evade-widespread-business-bans/5299962) [[2]](https://thenewstack.io/openclaw-enterprise-kubernetes-agents/). The OCE repository tells readers to think of the project as "Kubernetes for agents" [[1]](https://www.theregister.com/ai-and-ml/2026/09/30/openclaw-slips-on-a-suit-to-evade-widespread-business-bans/5299962). > FireAI, the on-device firewall for macOS developed by HisnLabs, shows which app opens a connection and lets its owner allow or block a destination, whichever agent is installed. A 17-day trial is available. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## Implications for organisations The announcement targets the reason organisations give for bans: agents hold credentials and can act on company systems, and central teams lack a way to police them [[2]](https://thenewstack.io/openclaw-enterprise-kubernetes-agents/). OCE is aimed at deployments where several agents, users and teams share infrastructure. The reports say nothing about individual Macs running OpenClaw outside such a deployment, which the control plane does not claim to cover [[2]](https://thenewstack.io/openclaw-enterprise-kubernetes-agents/). The security measures the project says it is concentrating on are isolation between trusted and untrusted workloads, sandboxing, granular permissions and LLM-assisted review, and it plans to publish a reference architecture [[2]](https://thenewstack.io/openclaw-enterprise-kubernetes-agents/). Those are plans, not yet released components. ## Recommendations 1. Treat OCE as a pilot: Lin states it is suitable only for internal pilot projects before the 1.0 release [[2]](https://thenewstack.io/openclaw-enterprise-kubernetes-agents/). 2. Keep existing restrictions on OpenClaw in place until the reference architecture and the unfinished parts, such as workload authentication, are published [[2]](https://thenewstack.io/openclaw-enterprise-kubernetes-agents/). 3. For OpenClaw 2.0 installs, read the release notes on secrets and sandboxing: the Register quotes them as stating that Secret Store values are not encrypted at rest and that shared-session controls are not a security boundary [[3]](https://www.theregister.com/ai-and-ml/2026/08/31/openclaw-20-pours-glitter-on-slow-burning-security-dumpster-fire/5293492). 4. Individuals who run OpenClaw on a personal Mac remain responsible for isolation and credential handling, because the control plane described is for organisational deployments [[2]](https://thenewstack.io/openclaw-enterprise-kubernetes-agents/). ## Relevance to FireAI FireAI works on one Mac. It identifies an app by its code signature or path, shows each connection the app makes, and applies [per-app rules](https://hisnlabs.com/en/docs/per-app-rules) and [security modes](https://hisnlabs.com/en/docs/security-modes) to them. For an agent installed on a Mac, FireAI shows the interpreter that runs it, usually Node.js or Python, and a rule on that interpreter applies to every script it runs. FireAI is not a control plane. It does not provide multi-tenancy, audit trails across a fleet, credential management, agent sandboxing or governance policy, and it has no integration with OpenClaw or OCE. It does not read the contents of encrypted connections and cannot stop an agent from reading or deleting local files. > An agent with credentials still needs the network to send anything out. FireAI asks before an app connects to a destination it has no rule for. Try it free for 17 days. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## Limitations The sources are two trade-press articles that restate announcements by OpenAI and Red Hat staff; the OCE documentation and the Lin and Fernandes posts themselves were not fetched. A qz.com article on the same announcement was not accessible and is not used. The claims about OCE are intentions for a 1.0 release that has not shipped, and no independent security assessment of OCE is cited. The Gartner and China CERT statements are reported by The Register and were not checked against the original publications [[1]](https://www.theregister.com/ai-and-ml/2026/09/30/openclaw-slips-on-a-suit-to-evade-widespread-business-bans/5299962). Try [FireAI, by HisnLabs](https://hisnlabs.com/en/download) free for 17 days. ## Sources - [The Register, 30 September 2026: OpenClaw slips on a suit to evade widespread business bans](https://www.theregister.com/ai-and-ml/2026/09/30/openclaw-slips-on-a-suit-to-evade-widespread-business-bans/5299962) - [The New Stack, 30 September 2026: "Think of it as Kubernetes for agents": OpenClaw lands in the enterprise](https://thenewstack.io/openclaw-enterprise-kubernetes-agents/) - [The Register, 31 August 2026: OpenClaw 2.0 pours glitter on slow-burning security dumpster fire](https://www.theregister.com/ai-and-ml/2026/08/31/openclaw-20-pours-glitter-on-slow-burning-security-dumpster-fire/5293492)