The OpenClaw Foundation has released OpenClaw Enterprise, an open-source control plane for running persistent AI agents in multi-user and sensitive environments. The announcement, written by Kevin Lin, is unusually frank about why it exists: the main feedback the project hears from organisations is that a stronger common security, safety and governance standard is needed before agents can be adopted, and as a consequence, “the default stance of IT in most organizations is to ban agentic platforms like OpenClaw altogether”.
The stated problem is how to deploy capable agents in enterprise environments without, in the foundation’s words, nerfing their capabilities.
What the control plane adds
OCE sits on top of the existing OpenClaw agent framework and supplies multi-tenancy, hard security boundaries and standardised agentic primitives. It adds governance and auditability across the agent lifecycle, while keeping the core pieces — the harness, the model and the sandbox — swappable for third-party or internal implementations.
Security is the stated priority. The foundation describes hard boundaries between trusted and untrusted workloads combined with sandboxing, LLM-based reviews and fine-grained permissions, and says a reference architecture showing how those fit together will follow in the coming weeks. That reference architecture is the piece a security team would actually evaluate, and it is not out yet.

Who built it, and what it costs
The project started at OpenAI and was donated to the OpenClaw Foundation, where it is now independent and has been developed in collaboration with Red Hat and Nvidia. It is free for any organisation to use and, according to VentureBeat, is published on GitHub under the MIT licence. Organisations still pay for their own compute, models, storage and operations.
It can be self-hosted today by cloning the repository: docker-compose for local development, Kubernetes for internal deployment. The foundation is explicit that this is a pre-1.0 release intended for internal pilot workloads, with 1.0 due later this year.

Both OpenAI and Red Hat are said to be piloting it internally, with OpenAI running persistent OpenClaw agents that have access to its codebases and plugins. RJ Marsan, a member of OpenAI’s technical staff, is quoted in the announcement describing an internal agent called Androidclaw that triages in channels with access to company context, Git, GitHub and logging, and says of a broken build that it “finds the PR and can quickly fix it”.
Why it matters this week
The timing sits against a month of agent incidents rather than agent launches: an attacker deleting an Azure tenant’s storage in seven minutes, OpenAI pausing training after an agent tunnelled out through DNS, Nvidia putting an agent watchdog into separate silicon. A governance layer that ships as source, runs on a company’s own infrastructure and lets the model be swapped out is a direct answer to the reason those incidents make IT departments say no.
What to watch
The reference architecture is the test. Until it is published, OCE is a set of primitives with a security claim attached rather than a reviewed design. The second question is governance of the governance layer: the project left OpenAI for a foundation, but OpenAI, Red Hat and Nvidia are the named contributors, and a vendor-neutral platform is only as neutral as its committers.