Artificial Intelligence · Open Source · AI Agents · Technical

What the Heck Happened to OpenClaw?

OpenClaw went from a weekend AI experiment with a lobster joke to an open-source agent runtime underneath serious products. Here is what changed, why security became such a big deal, and why Microsoft is now building on it.

By Danny · September 28, 2026 at 3:25 PM · 9 min read

If you looked at OpenClaw early this year and then stopped paying attention for a few months, you could be forgiven for wondering:

What the heck happened to OpenClaw?

Wasn't this the slightly crazy lobster-themed project that let you talk to an AI agent through WhatsApp?

Wasn't it called something else first?

Didn't it have security problems?

And why is Microsoft now talking about building an always-on agent on top of it?

The short answer is:

OpenClaw did not disappear. It grew up — very, very quickly.

And somewhere along the way, it stopped being interesting merely as an AI assistant and became interesting as infrastructure.

First: OpenClaw is not an AI model

This is the most important thing to understand.

OpenClaw is not a competitor to GPT, Claude or a local Llama model.

It is better to think of it as the layer that can connect a model to the things you actually want it to do.

A simplified OpenClaw setup looks something like this:

WhatsApp / Telegram / Slack / Teams / Web
                    ↓
              OpenClaw Gateway
                    ↓
        ┌───────────┴───────────┐
        ↓                       ↓
   AI model                 Tools / Skills
 GPT / Claude              Browser / Files
 Codex / Local             Shell / Email
        ↓                  Calendar / Apps
        └───────────┬───────────┘
                    ↓
              Actual actions

The Gateway is the important part.

It runs on your own computer or server and coordinates conversations, models, memory, tools, permissions and connected devices.

The model may do the reasoning.

OpenClaw is the machinery that gives that reasoning somewhere to go.

That distinction matters because an AI that only produces text is one thing.

An AI that can read your mail, use your browser, run commands, modify files, send messages and keep working when you are not sitting in front of it is something quite different.

It started much smaller

Peter Steinberger originally hacked together what he described as a weekend project called WhatsApp Relay in late 2025.

It then became Clawd, a deliberate play on Anthropic's Claude.

Anthropic's legal team understandably wasn't thrilled with a project name sitting that close to its trademark, so Clawd became Moltbot.

That lasted roughly long enough for everyone to decide that Moltbot was difficult to say.

On January 29, 2026, the project became OpenClaw.

By then, this little weekend experiment had already passed 100,000 GitHub stars and, according to Steinberger, attracted two million website visitors in a single week.

Today the GitHub project is sitting at roughly 390,000 stars.

That is not normal growth for an infrastructure project.

Then people realised the interesting part wasn't the chatbot

The early demos were fun.

Message your lobster.

Ask it to check something.

Have it order something.

Let it control a browser.

But the bigger idea gradually became clearer.

The valuable thing was not that OpenClaw had its own AI personality.

The valuable thing was that it created a persistent agent environment.

Instead of opening ChatGPT, asking a question and closing the tab, you could have an agent that:

That is much closer to an operating layer for agents than to a chatbot.

OpenClaw's own documentation now describes the project as an extensible, proactive agent that works on your machine, in your messages and against your accounts.

That is a much more ambitious proposition than "AI in WhatsApp."

And that is where things became dangerous

The moment you give an AI agent real capabilities, the security problem changes completely.

Imagine the difference:

A normal chatbot sees this:

Please summarise this email.

An agent may see this:

Read my inbox, open the attachment, visit the website in it, use my credentials, update the spreadsheet and email the result to the client.

Much more useful.

Also much more dangerous.

If the model misunderstands an instruction, follows malicious content inside a webpage, uses the wrong account, leaks a secret or runs a destructive command, the consequences are no longer limited to a bad paragraph.

This is why OpenClaw's security story became such a major part of the project.

Yes, OpenClaw had a rough period

The project itself has been refreshingly open about this.

In May, Steinberger published a post literally titled "OpenClaw Had a Rough Week", discussing problems around the 2026.4.24 and 2026.4.29 releases.

The speed of development was colliding with the reality of maintaining software that had access to users' machines and accounts.

Since then, the project has put much more structure around releases, security boundaries, approvals, sandboxing and long-lived stable versions.

OpenClaw now has an extended-stable release channel — essentially its version of an LTS track — for people who would rather not live on the bleeding edge.

That is a sign of a project changing character.

A hacker project can say: "Pull the newest version and see what happens."

Infrastructure cannot.

The security numbers are fascinating

OpenClaw now publishes unusually detailed security statistics.

As of September 2026, its security page reports:

Those numbers should not be read as a simple score of whether OpenClaw is "safe" or "unsafe."

A project that publishes vulnerabilities openly can appear to have more problems than a project that simply never documents them.

But the numbers do tell us something else:

This is software with a very large attack surface.

It touches credentials, networks, browsers, plugins, messaging platforms, filesystems and command execution.

That requires serious security engineering.

The project now scans ClawHub skills, uses security tooling including CodeQL and other static analysis, works with NVIDIA on skill security, and recently completed a Trail of Bits audit through OpenAI's Patch the Planet initiative.

That is quite a journey from a WhatsApp relay.

OpenClaw 2.0 happened almost by accident

In August, the project released what it called OpenClaw 2.0, Accidentally.

The amusing title hides how large the change actually was.

The 2026.8.1 release touched installation, messaging, memory, skills, models, automations, browsers, native applications, plugins, security and the web interface.

The release documentation lists 16,977 pull requests, 698 direct commits and 987 contributors in the release-scale accounting.

OpenClaw now has native apps, a rebuilt control interface, persistent memory workflows, browser and computer-use capabilities, plugin management and a much more formal permissions model.

This is no longer one developer's funny lobster project.

Then came the Foundation

In July, OpenClaw moved under the OpenClaw Foundation, an independent US 501(c)(3) nonprofit.

That decision is more important than it sounds.

The project is still MIT licensed.

There is no separate enterprise edition.

There is no paid OpenClaw tier.

There is no OpenClaw token.

The Foundation says donors help fund development but do not own or control the project.

Those donors include organisations such as OpenAI, Amazon, Red Hat and the University of Michigan.

And one potentially confusing detail deserves to be made very clear:

OpenClaw is not an OpenAI product.

Peter Steinberger works at OpenAI and OpenAI supports the Foundation, but OpenClaw is independently governed and is designed to work with multiple model providers.

That model neutrality may turn out to be one of its most important characteristics.

And then Microsoft showed up

This is probably the part that made me look at OpenClaw again.

Microsoft announced Scout in June as an always-on personal agent for work.

Microsoft explicitly said Scout was powered by OpenClaw open-source technology.

Scout has since become part of Microsoft's broader Autopilot direction.

And on September 25, the OpenClaw Foundation described Microsoft Autopilot's foundation as OpenClaw, while also documenting Microsoft engineers contributing improvements back upstream.

Think about that progression for a moment.

Late 2025:

"I made a WhatsApp relay for my AI."

September 2026:

Microsoft is using the project as part of the runtime underneath an enterprise-grade autonomous agent.

That is one hell of a year.

Why doesn't Microsoft just build its own?

It is.

Microsoft adds its own enterprise identity, governance, compliance, policy enforcement and security infrastructure.

But using OpenClaw underneath gives it access to an open ecosystem that already understands models, channels, agent sessions, tools and continuous execution.

Microsoft can then contribute improvements back to the open-source project.

This is exactly the kind of relationship that made Linux, Chromium and other open-source infrastructure so important.

Companies do not necessarily need to own the foundation layer in order to build valuable products on top of it.

The architecture is becoming the real story

The most interesting question about OpenClaw today is no longer:

"Which AI model does it use?"

The answer can be GPT, Claude, Codex, a local model or something else.

A better question is:

"Who controls the environment around the model?"

Where does memory live?

Who holds the credentials?

Which tools can execute?

Which actions require approval?

Can execution be sandboxed?

Can I swap the model without rebuilding my entire setup?

Can the agent keep working when a provider changes?

That is the layer OpenClaw is trying to own — not commercially, but architecturally.

And that may be much more important than building yet another model.

Is OpenClaw ready for everybody?

I still would not describe OpenClaw as something every casual computer user should install tomorrow.

The desktop installers and onboarding have become much easier, but this remains extremely powerful software.

You are potentially giving an autonomous system access to your:

That deserves more thought than installing another chat app.

For technical users, developers and companies willing to understand the permissions model, however, OpenClaw has become one of the most interesting agent platforms to watch.

And the new extended-stable releases make it increasingly possible to choose reliability over constant experimentation.

So, what the heck happened to OpenClaw?

It didn't vanish.

It became infrastructure.

The lobster jokes are still there.

The open-source chaos is still there.

But underneath that is now a serious attempt to create a vendor-neutral runtime for AI agents: one that can run locally, use different models, connect to real tools and remain independent of any single AI company.

That also means OpenClaw has inherited all the difficult problems that come with infrastructure:

security, permissions, identity, reliability, updates, governance and trust.

Those problems are much less exciting than a viral demo of an AI ordering pizza.

They are also exactly the problems that need to be solved if autonomous agents are ever going to become normal computing.

And perhaps that is the real answer.

OpenClaw stopped being merely a cool demo.

It started becoming part of the stack.


Sources

Artificial Intelligence Open Source AI Agents Technical