Skip to content
AI EmployeeSuper-AgentsAgent-to-AgentTutorialsPricingBlogContact

OpenClaw Enterprise: The Open Agent Control Plane

At a glanceQuick answers
What is OpenClaw Enterprise?
An open source control plane for deploying and governing persistent agents on your own infrastructure; its README calls it Kubernetes for agents.
Who is it for?
Organizations with a platform team that want agents inside their own cluster, under their own security and audit controls.
What is the caveat?
It is pre-1.0 and meant for internal pilots; the security reference architecture has not been published.
Editorial data illustration on a near-white ground titled OpenClaw Enterprise: a navy control console wired to eight small sandboxes, each holding a red claw, one sandbox outlined in amber with a padlock, with callouts MIT open source license and Pre-1.0 internal pilots today
Fig 0One control plane, many sandboxed agents. Made by CellCog's image agent, running GPT Image 2.5.

OpenClaw now has an enterprise edition. On September 29, 2026, the OpenClaw Foundation announced OpenClaw Enterprise (OCE), “an open source, vendor neutral platform for managing persistent agents in sensitive environments.” It is pre-1.0, MIT-licensed, free, and built to run on your own infrastructure. The project started inside OpenAI, was donated to the Foundation, and is being developed with Red Hat and NVIDIA.

This page is read from the OpenClaw announcement by Kevin Lin, the OCE repository README, and Red Hat’s post by Joe Fernandes, all dated September 29.

On this page · 11 sectionsOpen
  1. What OCE is
  2. Why it exists
  3. The security design
  4. What running it takes
  5. Who is behind it
  6. The same day as dots
  7. Where CellCog fits
  8. What is not known
  9. What we are watching for
  10. Update log
  11. Sources
Key points6 · 6 min full read
  1. The OpenClaw Foundation announced OpenClaw Enterprise (OCE) on September 29, 2026: an open source, vendor neutral platform for managing persistent agents in sensitive environments.
  2. OCE is a control plane for agents, with multi-tenancy, hard security boundaries, standardized agentic primitives, and governance and auditability across the agent lifecycle.
  3. It is MIT-licensed on GitHub, runs on your own infrastructure, and the announcement says it will always be free for any organization to use.
  4. It is pre-1.0: the Foundation calls it fit for internal pilot workloads today, with a 1.0 release later this year.
  5. The project started at OpenAI, was donated to the OpenClaw Foundation, and is developed with Red Hat and NVIDIA; Red Hat and OpenAI pilot it internally.
  6. The security reference architecture is promised in the coming weeks and is not published yet.

§ 01What OCE is

Item What the primary sources say
What it is An enterprise grade control plane for agents; the README calls it Kubernetes for agents
Core features Multi-tenancy, hard security boundaries, standardized agentic primitives, governance and auditability across the agent lifecycle
Swappable parts The harness, model and sandbox can be replaced with third-party or internal implementations
License and price MIT on GitHub; always free for any organization to use
Where it runs Your own infrastructure: docker-compose for local development, Kubernetes for internal deployment
Maturity Pre-1.0, for internal pilot workloads; 1.0 later this year
Who built it Started at OpenAI, donated to the OpenClaw Foundation, developed with Red Hat and NVIDIA
Who pilots it Red Hat and OpenAI, internally
Table 1OpenClaw Enterprise at announcement, September 29, 2026

§ 02Why it exists

Lin’s announcement opens with the adoption problem, not the feature list. Almost a year after OpenClaw launched, “the actual deployment of persistent agents remains limited.” The reason, in his words: “the default stance of IT in most organizations is to ban agentic platforms like OpenClaw altogether.”

That reputation is earned. The Register’s coverage on September 30 recalls Gartner’s warning about the project and quotes China’s national emergency response team on its “extremely weak default security configurations.” Our own OpenClaw security record tracks the advisories behind it.

OCE is the answer Lin proposes: “how do we safely deploy powerful agents without nerfing their capabilities in enterprise environments?”

§ 03The security design

“Security is the primary focus of OpenClaw Enterprise,” the announcement says. It names four layers: hard boundaries between trusted and untrusted workloads, sandboxing, LLM-based reviews, and fine-grained permissions. The repository’s code layout matches that: separate packages for identities and resource authorization, and for audit events with sensitive-value sanitization.

What is missing is the document that shows how the layers fit. The Foundation says it will share a reference architecture “in the coming weeks.” Until it lands, OCE’s security claims are a design intent, not something a security team can review end to end.

§ 04What running it takes

OCE is infrastructure. The README’s local setup asks for Docker Engine or Podman, k3d, kubectl, Helm, Bash, Python 3, Go, Node.js 24 or newer and pnpm, or an existing Kubernetes cluster for the production path. Deploying a first agent needs an OpenAI API key with access to the default model or a selected override.

That makes OCE a platform team’s project. It gives an IT department the controls it asked for, on hardware it already runs, and leaves the agents, models and workflows for the team to build on top.

§ 05Who is behind it

The cast is the story. OpenAI started the project and its staff still lead it. Red Hat announced it is sponsoring the OpenClaw Foundation and “putting engineers behind it,” and plans to run OCE for its own internal agents. NVIDIA is named as a development partner.

Fernandes frames it as Red Hat’s third act: Linux moved enterprise apps onto open infrastructure, Kubernetes moved them to containers, and “Today, AI agents are driving the next evolution of enterprise applications.”

The announcement carries one user story, from RJ Marsan at OpenAI, about an internal agent called Androidclaw that has codebase, logging and GitHub access: “Alert about a broken build? Androidclaw finds the PR and can quickly fix it.”

§ 06The same day as dots

OCE surfaced on the same day OpenAI launched dots, its own hosted personal agents. OpenAI is now behind both a proprietary agent product and an open control plane it donated to a foundation. The two answer different buyers: dots is for a person, OCE is for an IT department that wants agents inside its own walls.

§ 07Where CellCog fits

We build AI employees, so read this section as our view. OCE and CellCog solve the same fear from opposite ends. OCE hands an organization the control plane to host and govern its own agents. CellCog is the hosted route: you hire an AI employee for a role, it gets its own secure VM, file system and browser identity, and anything it does that reaches your world passes an approval step first.

If you have a platform team and a mandate to keep agents on your own cluster, OCE is worth a pilot. If you want the work done without running the cluster, that is what we are for.

§ 08What is not known

  • The reference architecture. Promised in the coming weeks, not published.
  • The 1.0 date. Only later this year, per the announcement.
  • Other adopters. Red Hat and OpenAI are the only named pilots.
  • Model breadth in practice. The model is swappable by design, but the getting-started path assumes an OpenAI key.

§ 09What we are watching for

  • The reference architecture post and how it describes trusted and untrusted workloads.
  • A 1.0 release or a named production deployment.
  • Whether other model labs or cloud providers join the project.

§ 10Update log

  • October 1, 2026: page opened, from the OpenClaw announcement, the OCE README and Red Hat’s post.

§ 11Sources

Frequently asked6 questions

Q1Is OpenClaw Enterprise free?

Yes. The code is MIT-licensed on GitHub and the announcement says OCE will always be free for any organization to use. You pay for your own infrastructure and model usage.

Q2Who built OpenClaw Enterprise?

It started at OpenAI, was donated to the OpenClaw Foundation as an independent project, and is being developed with Red Hat and NVIDIA. Kevin Lin leads the effort at OpenAI.

Q3Can I use it in production?

Not yet by the project’s own description. The announcement says organizations can use it for internal pilot workloads, with a 1.0 release later this year.

Q4What do I need to run it?

Per the README: Docker or Podman, k3d, kubectl, Helm, Go, Node.js 24 or newer and pnpm for local setup, or an existing Kubernetes cluster, plus an OpenAI API key with access to the default model or your chosen override.

Q5How is it different from OpenAI's dots?

dots is OpenAI’s own hosted personal agent product. OCE is an open control plane you host yourself. Both surfaced on September 29, 2026.

Q6Where does CellCog fit?

CellCog is the hosted route: you hire AI employees for roles, each with its own secure VM, file system and browser identity, and anything that reaches your world passes an approval step. OCE is the route for teams that want to run their own control plane.

Published 01 October 2026 All Choosing a platform →