OpenClaw Enterprise offers open-source governance for self-hosted AI agents
OpenClaw Enterprise launches as an open-source control plane for managing persistent AI agents, backed by OpenAI, Nvidia, and Red Hat.
The OpenClaw Foundation has introduced OpenClaw Enterprise (OCE), an open-source platform designed to govern persistent AI agents within corporate infrastructure. Backed by major technology firms including OpenAI, Nvidia, and Red Hat, the project aims to provide a standardized control plane for teams that self-host their software and AI workloads. This release marks a significant shift from informal agent usage to structured enterprise management.
What happened
OpenClaw began as a personal project by Austrian developer Peter Steinberger in late 2025. It quickly gained traction, accumulating over 100,000 GitHub stars by February 2026, which led to Steinberger’s hiring by OpenAI. To ensure neutral oversight, the independent OpenClaw Foundation was established with support from sponsors like GitHub, Red Hat, and Nvidia. The foundation’s latest move is the launch of OCE, intended to address the security and governance gaps that currently prevent many IT departments from adopting agent platforms.
Kevin Lin, a member of technical staff at OpenAI leading the OCE effort, explained that most organizations currently ban agentic platforms due to a lack of common security standards. OCE seeks to change this by offering a vendor-neutral solution that runs on existing infrastructure. The platform is being developed in the open ahead of its 1.0 release later this year, allowing companies to inspect the code and contribute to its development during this early phase.
Key details
- OpenClaw Enterprise is an open-source control plane for managing persistent AI agents, currently in pre-1.0 development.
- Major backers include OpenAI, Nvidia, Red Hat, and GitHub, with the project overseen by the independent OpenClaw Foundation.
- The architecture separates the control plane from agent execution, using gateways for messages and harnesses for tool execution.
- Deployment options include Kubernetes clusters for full functionality and Docker or Podman Compose for control-plane previews.
- The platform features isolated namespaces, credential management, permission controls, and audit logs for agent activities.
- OCE is free for any organization to use and is designed to run on self-hosted infrastructure.
Background
Persistent AI agents differ from standard chatbots because they maintain state and can execute actions across multiple systems over time. This capability introduces complex security challenges, such as managing access to codebases, credentials, and internal messaging channels. Without proper governance, these agents can pose significant risks if they act unexpectedly or access sensitive data without authorization.
The comparison to Kubernetes is central to OpenClaw’s strategy. Just as Kubernetes became the standard for orchestrating containerized applications, OCE aims to become the standard for orchestrating AI agents. It provides a layer of abstraction that allows administrators to deploy, isolate, and monitor agents regardless of the underlying model or tools they use. This approach mirrors the enterprise adoption patterns seen with Linux and containers, where open-source standards eventually replaced proprietary solutions.
Why it matters
For teams that run their own software, the ability to self-host AI agents is crucial for maintaining data privacy and control. However, the operational burden of managing these agents securely has been a barrier to entry. OCE addresses this by providing built-in isolation between trusted and untrusted workloads, sandboxing capabilities, and granular permissions. This allows IT leads to enforce safety standards without relying on external vendors or black-box services.
The involvement of Red Hat and Nvidia signals a broader industry recognition that AI agents require robust infrastructure support. Red Hat’s contribution leverages its experience with Linux and Kubernetes to help shape OCE into a production-ready tool. For DevOps engineers and sysadmins, this means future agent deployments may integrate seamlessly with existing Kubernetes clusters and monitoring stacks, reducing the friction of adopting new AI technologies.
Additionally, the open-source nature of OCE allows organizations to audit the code and adapt it to their specific compliance requirements. This transparency is vital for industries with strict regulatory obligations, where understanding exactly how an agent processes data and makes decisions is non-negotiable. By providing a reference architecture for security, OpenClaw helps teams build trust in their automated workflows.
What you can do
- Review the OpenClaw Enterprise documentation on GitHub to understand the current architecture and API capabilities.
- Test the local development environment using Kubernetes to evaluate how the control plane manages agent namespaces.
- Assess your current infrastructure for compatibility with OCE, particularly regarding PostgreSQL backends and gateway configurations.
- Participate in the open development process by providing feedback on security features and governance tools before the 1.0 release.
- Plan pilot projects for internal teams, keeping in mind that the platform is still in an embryonic phase and not yet ready for critical production workloads.
- Monitor updates from the OpenClaw Foundation regarding completed features like external gateway admission and workload authentication.



