• Nosotros
  • Publicidad
  • Trabaja con nosotros
  • Contactos
martes, septiembre 1, 2026
  • Login
No Result
View All Result
NEWSLETTER
Despertar Matinal
  • Titulares del Día
    • All
    • En Portada
    «Estamos en momentos muy difíciles»; director de INAPA llama a racionar el agua

    «Estamos en momentos muy difíciles»; director de INAPA llama a racionar el agua

    RD Vial ha destinado más de RD$70 mil millones a obras viales desde 2021

    RD Vial ha destinado más de RD$70 mil millones a obras viales desde 2021

    Gobierno proyecta eliminar semáforos en principales accesos al Gran Santo Domingo

    Gobierno proyecta eliminar semáforos en principales accesos al Gran Santo Domingo

    Banco Central mantiene tasa de política monetaria en 5.25 % anual

    Banco Central mantiene tasa de política monetaria en 5.25 % anual

    Ministro de Justicia defiende preparación del CNM para evaluar a jueces: “No es como piensan algunos opinadores”

    Ministro de Justicia defiende preparación del CNM para evaluar a jueces: “No es como piensan algunos opinadores”

    Fuerza del Pueblo pone en marcha Centro de Estudios para formular políticas de movilidad segura

    Fuerza del Pueblo pone en marcha Centro de Estudios para formular políticas de movilidad segura

    El regreso a las aulas moviliza a miles en el Gran Santo Domingo y Santiago: presentan alternativas de ahorro para la movilidad universitaria

    El regreso a las aulas moviliza a miles en el Gran Santo Domingo y Santiago: presentan alternativas de ahorro para la movilidad universitaria

    Fuerza del Pueblo juramenta nuevos miembros y apertura local en Polo

    Fuerza del Pueblo juramenta nuevos miembros y apertura local en Polo

    Leonel encabeza asambleas en La Vega y Bonao y asegura Fuerza del Pueblo ganará las próximas elecciones

    Leonel encabeza asambleas en La Vega y Bonao y asegura Fuerza del Pueblo ganará las próximas elecciones

    Trending Tags

    • Mundo
      • All
      • América Latina
      • Conflictos Internacionales
      • Estados Unidos
      • Europa
      • Geopolítica
      • Haití
      • Medio Oriente
      El régimen comunista chino intensifica el cerco militar sobre Taiwán mientras prepara nuevas tácticas de combate

      El régimen comunista chino intensifica el cerco militar sobre Taiwán mientras prepara nuevas tácticas de combate

      Nico Occhiato y Marcelo Tinelli homenajearon a Showmatch en un especial de Luzu

      Nico Occhiato y Marcelo Tinelli homenajearon a Showmatch en un especial de Luzu

      Yair Netanyahu respaldó la soberanía argentina sobre las Malvinas y discutió con los ingleses

      Yair Netanyahu respaldó la soberanía argentina sobre las Malvinas y discutió con los ingleses

      El emotivo mensaje de Enzo Fernández a Messi tras su retiro de la Selección

      El emotivo mensaje de Enzo Fernández a Messi tras su retiro de la Selección

      La Unión Europea lanzó un paquete para hiper-regular a ChatGPT, Roblox y Reddit

      La Unión Europea lanzó un paquete para hiper-regular a ChatGPT, Roblox y Reddit

      Cuánto se dispararon las exportaciones argentinas a Europa gracias al acuerdo Mercosur-Unión Europea

      Cuánto se dispararon las exportaciones argentinas a Europa gracias al acuerdo Mercosur-Unión Europea

      Milei habló en el Congreso de la FIA y pidió el regreso de la Fórmula 1 a la Argentina

      Milei habló en el Congreso de la FIA y pidió el regreso de la Fórmula 1 a la Argentina

      Los 10 mejores goles de Lionel Messi con la Selección Argentina

      Los 10 mejores goles de Lionel Messi con la Selección Argentina

      Chequeado salió en defensa de Lula y confirmó la presencia de inmigrantes marroquíes en Brasil

      Chequeado salió en defensa de Lula y confirmó la presencia de inmigrantes marroquíes en Brasil

      Trending Tags

      • Nacionales
        • All
        • Bávaro Punta Cana
        • Educación
        • Gobierno
        • Infraestructura
        • Justicia
        • Obras Públicas
        • Opinión
        • Provincias
        • Seguridad Ciudadana
        • semana santa 2026
        • Sociedad
        • Transporte
        «Estamos en momentos muy difíciles»; director de INAPA llama a racionar el agua

        «Estamos en momentos muy difíciles»; director de INAPA llama a racionar el agua

        RD Vial ha destinado más de RD$70 mil millones a obras viales desde 2021

        RD Vial ha destinado más de RD$70 mil millones a obras viales desde 2021

        Gobierno proyecta eliminar semáforos en principales accesos al Gran Santo Domingo

        Gobierno proyecta eliminar semáforos en principales accesos al Gran Santo Domingo

        UASD y JCE abren centro para captura de datos y emisión inmediata de la nueva cédula

        UASD y JCE abren centro para captura de datos y emisión inmediata de la nueva cédula

        Banco Central mantiene tasa de política monetaria en 5.25 % anual

        Banco Central mantiene tasa de política monetaria en 5.25 % anual

        Ministro de Justicia defiende preparación del CNM para evaluar a jueces: “No es como piensan algunos opinadores”

        Ministro de Justicia defiende preparación del CNM para evaluar a jueces: “No es como piensan algunos opinadores”

        Gresefu celebra sus 23 años de trayectoria y servicio a las familias dominicanas

        Gresefu celebra sus 23 años de trayectoria y servicio a las familias dominicanas

        Fuerza del Pueblo pone en marcha Centro de Estudios para formular políticas de movilidad segura

        Fuerza del Pueblo pone en marcha Centro de Estudios para formular políticas de movilidad segura

        El regreso a las aulas moviliza a miles en el Gran Santo Domingo y Santiago: presentan alternativas de ahorro para la movilidad universitaria

        El regreso a las aulas moviliza a miles en el Gran Santo Domingo y Santiago: presentan alternativas de ahorro para la movilidad universitaria

        Trending Tags

        • Política
          • All
          • Congreso
          • Opinión Política
          • Partidos Políticos
          • Poder Municipal
          • Transparencia y Corrupción
          ¡Leonel Fernández llega a San Juan! La Fuerza del Pueblo prepara gran acto de juramentación de nuevos miembros

          ¡Leonel Fernández llega a San Juan! La Fuerza del Pueblo prepara gran acto de juramentación de nuevos miembros

          Dicen proyecto presidencial de Gonzalo Castillo impacta más de 40 territorios el fin de semana

          Dicen proyecto presidencial de Gonzalo Castillo impacta más de 40 territorios el fin de semana

          Antonio Marte juramenta nuevas estructuras fortalecen PPG

          Antonio Marte juramenta nuevas estructuras fortalecen PPG

          Leonel Fernández encabeza asambleas provinciales en despliegue nacional de la Fuerza del Pueblo

          Leonel Fernández encabeza asambleas provinciales en despliegue nacional de la Fuerza del Pueblo

          Rafael Méndez “El Conde” anuncia aspiración a regidor por Fuerza del Pueblo en San Juan de la Maguana

          Rafael Méndez “El Conde” anuncia aspiración a regidor por Fuerza del Pueblo en San Juan de la Maguana

          Vicealcaldesa de Los Alcarrizos abandona el PRM y se juramenta en la Fuerza del Pueblo junto a más de 300 dirigentes

          Vicealcaldesa de Los Alcarrizos abandona el PRM y se juramenta en la Fuerza del Pueblo junto a más de 300 dirigentes

          Leonel afirma PRM no pudo mantener 24 horas de electricidad y la gente está cansada de apagones

          Leonel afirma PRM no pudo mantener 24 horas de electricidad y la gente está cansada de apagones

          Johnny Pujols afirma PLD fortalece su estructura territorial mientras PRM va en picada

          Johnny Pujols afirma PLD fortalece su estructura territorial mientras PRM va en picada

          Advierte año escolar iniciará con problemas de fondo ante un...

          Advierte año escolar iniciará con problemas de fondo ante un…

          Trending Tags

          • Deportes
            • All
            • Atletas Dominicanos
            • Béisbol
            DR Open Kiteboarding Championship reúne atletas de 15 países y reafirma a Cabarete como capital del kitesurf del Caribe

            Cabarete se corona como capital histórica del kitesurf con el DR Open Championship 2026

            El impulso olímpico del billar recibe un impulso de los dos campeones mundiales consecutivos de China

            El impulso olímpico del billar recibe un impulso de los dos campeones mundiales consecutivos de China

            La reboteadora líder de todos los tiempos de la WNBA, Tina Charles, se retira del baloncesto

            La reboteadora líder de todos los tiempos de la WNBA, Tina Charles, se retira del baloncesto

            Sabalenka pide boicot si los jugadores no obtienen una mayor parte de los ingresos del Grand Slam

            Sabalenka pide boicot si los jugadores no obtienen una mayor parte de los ingresos del Grand Slam

            Los 76ers tienen un cambio breve y luego una noche larga con una derrota aplastante en el Juego 1

            Los 76ers tienen un cambio breve y luego una noche larga con una derrota aplastante en el Juego 1

            Ex empleado de Stefon Diggs subirá al estrado por segundo día en el juicio por agresión a un jugador de la NFL

            Ex empleado de Stefon Diggs subirá al estrado por segundo día en el juicio por agresión a un jugador de la NFL

            Kansas City es la sede central de la Copa del Mundo y alberga a Inglaterra, Argentina y Holanda, además de 6 partidos.

            Kansas City es la sede central de la Copa del Mundo y alberga a Inglaterra, Argentina y Holanda, además de 6 partidos.

            30 pasajeros son evacuados después de que un crucero encallara en un arrecife en Fiji

            Buffalo recibe a Montreal para abrir la segunda ronda

            Judge quiere una nueva tradición del Bronx: “¡Los Yankees ganan!” de Sterling. antes de la canción de Sinatra

            Judge quiere una nueva tradición del Bronx: “¡Los Yankees ganan!” de Sterling. antes de la canción de Sinatra

            Trending Tags

            • Economía
              • All
              • Combustibles
              • Energía
              • Indicadores Económicos
              • Sector Energético
              • Turismo
              Aerodom anuncia nuevas rutas aéreas, pero la pregunta de fondo es quién fiscaliza la concesión

              Aerodom anuncia nuevas rutas aéreas, pero la pregunta de fondo es quién fiscaliza la concesión

              Aventúrate RD 2026

              Aventúrate RD 2026 revela agenda oficial y consolida el turismo de aventura dominicano

              WTTC: Una inversión de más de un billón de dólares en viajes y turismo es una muestra de confianza en el futuro del sector

              WTTC: Una inversión de más de un billón de dólares en viajes y turismo es una muestra de confianza en el futuro del sector

              Una semana para crear en Samaná: Atelier Yubarta busca conectar arte, naturaleza y turismo en Cayo Levantado Resort

              Una semana para crear en Samaná: Atelier Yubarta busca conectar arte, naturaleza y turismo en Cayo Levantado Resort

              Meta RD 2036: el plan turístico que el Gobierno aplaude sin fiscalización

              Meta RD 2036: el plan turístico que el Gobierno aplaude sin fiscalización

              Viva Resorts impulsa el turismo interno en República Dominicana con jornada exclusiva en Bayahibe

              Viva Resorts impulsa el turismo interno en República Dominicana con jornada exclusiva en Bayahibe

              El ministerio de Turismo cierra con éxito festival gastronómico “Saborea el Paraíso” en Sánchez, Samaná

              El Ministerio de Turismo celebra un exitoso cierre del festival gastronómico «Saborea el Paraíso» en Sánchez, Samaná

              El Consejo Mundial de Viajes y Turismo (WTTC) informa la incorporación de Piñero como miembro global

              El Consejo Mundial de Viajes y Turismo (WTTC) informa la incorporación de Piñero como miembro global

              Más allá del comercio: los efectos del arancel estadounidense sobre el turismo dominicano

              Arancel de EE.UU. pone a prueba al turismo dominicano y al silencio oficial del gobierno

              Trending Tags

              • Ciencia
                • All
                • Energía
                • Innovación
                • Investigación Científica
                • Salud y Medicina
                • Tecnología Médica
                Shein shares fall in long-awaited stock market debut

                Shein shares fall in long-awaited stock market debut

                Dan Driscoll: US army secretary resigns after months of tension

                Dan Driscoll: US army secretary resigns after months of tension

                Uniqlo, Muji: Japan Inc is betting big on India as China risks deepen

                Uniqlo, Muji: Japan Inc is betting big on India as China risks deepen

                Supreme Court clears way for Trump to keep building White House ballroom

                Supreme Court clears way for Trump to keep building White House ballroom

                Gonzalo visita 40 territorios en un fin de semana

                Gonzalo visita 40 territorios en un fin de semana

                Festival honouring Dolly Parton set for Nashville and London

                Festival honouring Dolly Parton set for Nashville and London

                Ex-congressman George Santos banned from betting platform Kalshi for life

                Ex-congressman George Santos banned from betting platform Kalshi for life

                US singer D4vd's celebrity lawyers withdraw from murder case

                US singer D4vd’s celebrity lawyers withdraw from murder case

                Nepal rescuers blast hillside in search of hydropower workers as families wait anxiously

                Nepal rescuers blast hillside in search of hydropower workers as families wait anxiously

                Trending Tags

                • Tecnología
                  • All
                  • Aplicaciones
                  • Inteligencia Artificial
                  OpenClaw 2.0 is here, ushering in the era of 'multiplayer' AI coding: What it means for enterprises

                  OpenClaw 2.0 is here, ushering in the era of ‘multiplayer’ AI coding: What it means for enterprises

                  El nuevo trabajo de los ingenieros de software no es escribir código, sino diseñar los límites que los agentes de IA no pueden romper

                  El nuevo trabajo de los ingenieros de software no es escribir código, sino diseñar los límites que los agentes de IA no pueden romper

                  La identidad y los permisos no son suficientes para gobernar el comportamiento de los agentes de IA

                  La identidad y los permisos no son suficientes para gobernar el comportamiento de los agentes de IA

                  Japón reforzará su defensa con drones, inteligencia artificial y misiles, según muestran los planes presupuestarios de defensa

                  Japón reforzará su defensa con drones, inteligencia artificial y misiles, según muestran los planes presupuestarios de defensa

                  Los fabricantes de automóviles japoneses Nissan y Honda acuerdan trabajar juntos en software para automóviles

                  Los fabricantes de automóviles japoneses Nissan y Honda acuerdan trabajar juntos en software para automóviles

                  El lago Ontario ahora se llama Lake America en Google Maps para los usuarios de EE. UU. después de que Trump ordenara el cambio de nombre

                  El lago Ontario ahora se llama Lake America en Google Maps para los usuarios de EE. UU. después de que Trump ordenara el cambio de nombre

                  Qué transmitir: 'Mandalorian & Grogu', el reality show de Alix Earle, 'I Know Too Much' de Ellie Goulding

                  Qué transmitir: ‘Mandalorian & Grogu’, el reality show de Alix Earle, ‘I Know Too Much’ de Ellie Goulding

                  La inteligencia artificial y la robótica impulsan un auge de las OPI en China mientras Shein cotiza en Hong Kong

                  La inteligencia artificial y la robótica impulsan un auge de las OPI en China mientras Shein cotiza en Hong Kong

                  Los agentes de IA necesitan su propia identidad antes de necesitar una puerta de enlace

                  Los agentes de IA necesitan su propia identidad antes de necesitar una puerta de enlace

                  Trending Tags

                  • Entretenimiento
                    • All
                    • Cine y Series
                    • Cultura Digital
                    • Cultura Popular
                    • Gastronomía
                    • Música
                    Celine Dion está de regreso en París, pero su primera canción sigue siendo "un gran secreto"

                    Celine Dion está de regreso en París, pero su primera canción sigue siendo «un gran secreto»

                    30 pasajeros son evacuados después de que un crucero encallara en un arrecife en Fiji

                    La ‘Odisea’ de Emily Wilson se convirtió en un punto de inflamación cultural. Ahora ella está retraduciendo todo.

                    Editor, editor y reportero de Stars and Stripes demandan al Pentágono para impugnar sus despidos

                    Editor, editor y reportero de Stars and Stripes demandan al Pentágono para impugnar sus despidos

                    Muere Peter Cullen, el prolífico actor de doblaje que le dio a Optimus Prime su autoritario barítono

                    Muere Peter Cullen, el prolífico actor de doblaje que le dio a Optimus Prime su autoritario barítono

                    Juez pregunta por qué el Kennedy Center se está moviendo tan rápido para devolver el nombre de Trump al edificio

                    Juez pregunta por qué el Kennedy Center se está moviendo tan rápido para devolver el nombre de Trump al edificio

                    En el conflictivo norte de Nigeria, una animada vida nocturna convive con una policía moral e inseguridad.

                    En el conflictivo norte de Nigeria, una animada vida nocturna convive con una policía moral e inseguridad.

                    Un teatro reinventa la Odisea de Homero a través de la agonía de la guerra de Ucrania

                    Un teatro reinventa la Odisea de Homero a través de la agonía de la guerra de Ucrania

                    El rapero Yung Filly regresará a Gran Bretaña antes del juicio por violación en Australia el próximo año

                    El rapero Yung Filly regresará a Gran Bretaña antes del juicio por violación en Australia el próximo año

                    30 pasajeros son evacuados después de que un crucero encallara en un arrecife en Fiji

                    Los británicos tienen la oportunidad de leer las memorias de Jason Arday en las librerías del Reino Unido

                    Trending Tags

                    • Titulares del Día
                      • All
                      • En Portada
                      «Estamos en momentos muy difíciles»; director de INAPA llama a racionar el agua

                      «Estamos en momentos muy difíciles»; director de INAPA llama a racionar el agua

                      RD Vial ha destinado más de RD$70 mil millones a obras viales desde 2021

                      RD Vial ha destinado más de RD$70 mil millones a obras viales desde 2021

                      Gobierno proyecta eliminar semáforos en principales accesos al Gran Santo Domingo

                      Gobierno proyecta eliminar semáforos en principales accesos al Gran Santo Domingo

                      Banco Central mantiene tasa de política monetaria en 5.25 % anual

                      Banco Central mantiene tasa de política monetaria en 5.25 % anual

                      Ministro de Justicia defiende preparación del CNM para evaluar a jueces: “No es como piensan algunos opinadores”

                      Ministro de Justicia defiende preparación del CNM para evaluar a jueces: “No es como piensan algunos opinadores”

                      Fuerza del Pueblo pone en marcha Centro de Estudios para formular políticas de movilidad segura

                      Fuerza del Pueblo pone en marcha Centro de Estudios para formular políticas de movilidad segura

                      El regreso a las aulas moviliza a miles en el Gran Santo Domingo y Santiago: presentan alternativas de ahorro para la movilidad universitaria

                      El regreso a las aulas moviliza a miles en el Gran Santo Domingo y Santiago: presentan alternativas de ahorro para la movilidad universitaria

                      Fuerza del Pueblo juramenta nuevos miembros y apertura local en Polo

                      Fuerza del Pueblo juramenta nuevos miembros y apertura local en Polo

                      Leonel encabeza asambleas en La Vega y Bonao y asegura Fuerza del Pueblo ganará las próximas elecciones

                      Leonel encabeza asambleas en La Vega y Bonao y asegura Fuerza del Pueblo ganará las próximas elecciones

                      Trending Tags

                      • Mundo
                        • All
                        • América Latina
                        • Conflictos Internacionales
                        • Estados Unidos
                        • Europa
                        • Geopolítica
                        • Haití
                        • Medio Oriente
                        El régimen comunista chino intensifica el cerco militar sobre Taiwán mientras prepara nuevas tácticas de combate

                        El régimen comunista chino intensifica el cerco militar sobre Taiwán mientras prepara nuevas tácticas de combate

                        Nico Occhiato y Marcelo Tinelli homenajearon a Showmatch en un especial de Luzu

                        Nico Occhiato y Marcelo Tinelli homenajearon a Showmatch en un especial de Luzu

                        Yair Netanyahu respaldó la soberanía argentina sobre las Malvinas y discutió con los ingleses

                        Yair Netanyahu respaldó la soberanía argentina sobre las Malvinas y discutió con los ingleses

                        El emotivo mensaje de Enzo Fernández a Messi tras su retiro de la Selección

                        El emotivo mensaje de Enzo Fernández a Messi tras su retiro de la Selección

                        La Unión Europea lanzó un paquete para hiper-regular a ChatGPT, Roblox y Reddit

                        La Unión Europea lanzó un paquete para hiper-regular a ChatGPT, Roblox y Reddit

                        Cuánto se dispararon las exportaciones argentinas a Europa gracias al acuerdo Mercosur-Unión Europea

                        Cuánto se dispararon las exportaciones argentinas a Europa gracias al acuerdo Mercosur-Unión Europea

                        Milei habló en el Congreso de la FIA y pidió el regreso de la Fórmula 1 a la Argentina

                        Milei habló en el Congreso de la FIA y pidió el regreso de la Fórmula 1 a la Argentina

                        Los 10 mejores goles de Lionel Messi con la Selección Argentina

                        Los 10 mejores goles de Lionel Messi con la Selección Argentina

                        Chequeado salió en defensa de Lula y confirmó la presencia de inmigrantes marroquíes en Brasil

                        Chequeado salió en defensa de Lula y confirmó la presencia de inmigrantes marroquíes en Brasil

                        Trending Tags

                        • Nacionales
                          • All
                          • Bávaro Punta Cana
                          • Educación
                          • Gobierno
                          • Infraestructura
                          • Justicia
                          • Obras Públicas
                          • Opinión
                          • Provincias
                          • Seguridad Ciudadana
                          • semana santa 2026
                          • Sociedad
                          • Transporte
                          «Estamos en momentos muy difíciles»; director de INAPA llama a racionar el agua

                          «Estamos en momentos muy difíciles»; director de INAPA llama a racionar el agua

                          RD Vial ha destinado más de RD$70 mil millones a obras viales desde 2021

                          RD Vial ha destinado más de RD$70 mil millones a obras viales desde 2021

                          Gobierno proyecta eliminar semáforos en principales accesos al Gran Santo Domingo

                          Gobierno proyecta eliminar semáforos en principales accesos al Gran Santo Domingo

                          UASD y JCE abren centro para captura de datos y emisión inmediata de la nueva cédula

                          UASD y JCE abren centro para captura de datos y emisión inmediata de la nueva cédula

                          Banco Central mantiene tasa de política monetaria en 5.25 % anual

                          Banco Central mantiene tasa de política monetaria en 5.25 % anual

                          Ministro de Justicia defiende preparación del CNM para evaluar a jueces: “No es como piensan algunos opinadores”

                          Ministro de Justicia defiende preparación del CNM para evaluar a jueces: “No es como piensan algunos opinadores”

                          Gresefu celebra sus 23 años de trayectoria y servicio a las familias dominicanas

                          Gresefu celebra sus 23 años de trayectoria y servicio a las familias dominicanas

                          Fuerza del Pueblo pone en marcha Centro de Estudios para formular políticas de movilidad segura

                          Fuerza del Pueblo pone en marcha Centro de Estudios para formular políticas de movilidad segura

                          El regreso a las aulas moviliza a miles en el Gran Santo Domingo y Santiago: presentan alternativas de ahorro para la movilidad universitaria

                          El regreso a las aulas moviliza a miles en el Gran Santo Domingo y Santiago: presentan alternativas de ahorro para la movilidad universitaria

                          Trending Tags

                          • Política
                            • All
                            • Congreso
                            • Opinión Política
                            • Partidos Políticos
                            • Poder Municipal
                            • Transparencia y Corrupción
                            ¡Leonel Fernández llega a San Juan! La Fuerza del Pueblo prepara gran acto de juramentación de nuevos miembros

                            ¡Leonel Fernández llega a San Juan! La Fuerza del Pueblo prepara gran acto de juramentación de nuevos miembros

                            Dicen proyecto presidencial de Gonzalo Castillo impacta más de 40 territorios el fin de semana

                            Dicen proyecto presidencial de Gonzalo Castillo impacta más de 40 territorios el fin de semana

                            Antonio Marte juramenta nuevas estructuras fortalecen PPG

                            Antonio Marte juramenta nuevas estructuras fortalecen PPG

                            Leonel Fernández encabeza asambleas provinciales en despliegue nacional de la Fuerza del Pueblo

                            Leonel Fernández encabeza asambleas provinciales en despliegue nacional de la Fuerza del Pueblo

                            Rafael Méndez “El Conde” anuncia aspiración a regidor por Fuerza del Pueblo en San Juan de la Maguana

                            Rafael Méndez “El Conde” anuncia aspiración a regidor por Fuerza del Pueblo en San Juan de la Maguana

                            Vicealcaldesa de Los Alcarrizos abandona el PRM y se juramenta en la Fuerza del Pueblo junto a más de 300 dirigentes

                            Vicealcaldesa de Los Alcarrizos abandona el PRM y se juramenta en la Fuerza del Pueblo junto a más de 300 dirigentes

                            Leonel afirma PRM no pudo mantener 24 horas de electricidad y la gente está cansada de apagones

                            Leonel afirma PRM no pudo mantener 24 horas de electricidad y la gente está cansada de apagones

                            Johnny Pujols afirma PLD fortalece su estructura territorial mientras PRM va en picada

                            Johnny Pujols afirma PLD fortalece su estructura territorial mientras PRM va en picada

                            Advierte año escolar iniciará con problemas de fondo ante un...

                            Advierte año escolar iniciará con problemas de fondo ante un…

                            Trending Tags

                            • Deportes
                              • All
                              • Atletas Dominicanos
                              • Béisbol
                              DR Open Kiteboarding Championship reúne atletas de 15 países y reafirma a Cabarete como capital del kitesurf del Caribe

                              Cabarete se corona como capital histórica del kitesurf con el DR Open Championship 2026

                              El impulso olímpico del billar recibe un impulso de los dos campeones mundiales consecutivos de China

                              El impulso olímpico del billar recibe un impulso de los dos campeones mundiales consecutivos de China

                              La reboteadora líder de todos los tiempos de la WNBA, Tina Charles, se retira del baloncesto

                              La reboteadora líder de todos los tiempos de la WNBA, Tina Charles, se retira del baloncesto

                              Sabalenka pide boicot si los jugadores no obtienen una mayor parte de los ingresos del Grand Slam

                              Sabalenka pide boicot si los jugadores no obtienen una mayor parte de los ingresos del Grand Slam

                              Los 76ers tienen un cambio breve y luego una noche larga con una derrota aplastante en el Juego 1

                              Los 76ers tienen un cambio breve y luego una noche larga con una derrota aplastante en el Juego 1

                              Ex empleado de Stefon Diggs subirá al estrado por segundo día en el juicio por agresión a un jugador de la NFL

                              Ex empleado de Stefon Diggs subirá al estrado por segundo día en el juicio por agresión a un jugador de la NFL

                              Kansas City es la sede central de la Copa del Mundo y alberga a Inglaterra, Argentina y Holanda, además de 6 partidos.

                              Kansas City es la sede central de la Copa del Mundo y alberga a Inglaterra, Argentina y Holanda, además de 6 partidos.

                              30 pasajeros son evacuados después de que un crucero encallara en un arrecife en Fiji

                              Buffalo recibe a Montreal para abrir la segunda ronda

                              Judge quiere una nueva tradición del Bronx: “¡Los Yankees ganan!” de Sterling. antes de la canción de Sinatra

                              Judge quiere una nueva tradición del Bronx: “¡Los Yankees ganan!” de Sterling. antes de la canción de Sinatra

                              Trending Tags

                              • Economía
                                • All
                                • Combustibles
                                • Energía
                                • Indicadores Económicos
                                • Sector Energético
                                • Turismo
                                Aerodom anuncia nuevas rutas aéreas, pero la pregunta de fondo es quién fiscaliza la concesión

                                Aerodom anuncia nuevas rutas aéreas, pero la pregunta de fondo es quién fiscaliza la concesión

                                Aventúrate RD 2026

                                Aventúrate RD 2026 revela agenda oficial y consolida el turismo de aventura dominicano

                                WTTC: Una inversión de más de un billón de dólares en viajes y turismo es una muestra de confianza en el futuro del sector

                                WTTC: Una inversión de más de un billón de dólares en viajes y turismo es una muestra de confianza en el futuro del sector

                                Una semana para crear en Samaná: Atelier Yubarta busca conectar arte, naturaleza y turismo en Cayo Levantado Resort

                                Una semana para crear en Samaná: Atelier Yubarta busca conectar arte, naturaleza y turismo en Cayo Levantado Resort

                                Meta RD 2036: el plan turístico que el Gobierno aplaude sin fiscalización

                                Meta RD 2036: el plan turístico que el Gobierno aplaude sin fiscalización

                                Viva Resorts impulsa el turismo interno en República Dominicana con jornada exclusiva en Bayahibe

                                Viva Resorts impulsa el turismo interno en República Dominicana con jornada exclusiva en Bayahibe

                                El ministerio de Turismo cierra con éxito festival gastronómico “Saborea el Paraíso” en Sánchez, Samaná

                                El Ministerio de Turismo celebra un exitoso cierre del festival gastronómico «Saborea el Paraíso» en Sánchez, Samaná

                                El Consejo Mundial de Viajes y Turismo (WTTC) informa la incorporación de Piñero como miembro global

                                El Consejo Mundial de Viajes y Turismo (WTTC) informa la incorporación de Piñero como miembro global

                                Más allá del comercio: los efectos del arancel estadounidense sobre el turismo dominicano

                                Arancel de EE.UU. pone a prueba al turismo dominicano y al silencio oficial del gobierno

                                Trending Tags

                                • Ciencia
                                  • All
                                  • Energía
                                  • Innovación
                                  • Investigación Científica
                                  • Salud y Medicina
                                  • Tecnología Médica
                                  Shein shares fall in long-awaited stock market debut

                                  Shein shares fall in long-awaited stock market debut

                                  Dan Driscoll: US army secretary resigns after months of tension

                                  Dan Driscoll: US army secretary resigns after months of tension

                                  Uniqlo, Muji: Japan Inc is betting big on India as China risks deepen

                                  Uniqlo, Muji: Japan Inc is betting big on India as China risks deepen

                                  Supreme Court clears way for Trump to keep building White House ballroom

                                  Supreme Court clears way for Trump to keep building White House ballroom

                                  Gonzalo visita 40 territorios en un fin de semana

                                  Gonzalo visita 40 territorios en un fin de semana

                                  Festival honouring Dolly Parton set for Nashville and London

                                  Festival honouring Dolly Parton set for Nashville and London

                                  Ex-congressman George Santos banned from betting platform Kalshi for life

                                  Ex-congressman George Santos banned from betting platform Kalshi for life

                                  US singer D4vd's celebrity lawyers withdraw from murder case

                                  US singer D4vd’s celebrity lawyers withdraw from murder case

                                  Nepal rescuers blast hillside in search of hydropower workers as families wait anxiously

                                  Nepal rescuers blast hillside in search of hydropower workers as families wait anxiously

                                  Trending Tags

                                  • Tecnología
                                    • All
                                    • Aplicaciones
                                    • Inteligencia Artificial
                                    OpenClaw 2.0 is here, ushering in the era of 'multiplayer' AI coding: What it means for enterprises

                                    OpenClaw 2.0 is here, ushering in the era of ‘multiplayer’ AI coding: What it means for enterprises

                                    El nuevo trabajo de los ingenieros de software no es escribir código, sino diseñar los límites que los agentes de IA no pueden romper

                                    El nuevo trabajo de los ingenieros de software no es escribir código, sino diseñar los límites que los agentes de IA no pueden romper

                                    La identidad y los permisos no son suficientes para gobernar el comportamiento de los agentes de IA

                                    La identidad y los permisos no son suficientes para gobernar el comportamiento de los agentes de IA

                                    Japón reforzará su defensa con drones, inteligencia artificial y misiles, según muestran los planes presupuestarios de defensa

                                    Japón reforzará su defensa con drones, inteligencia artificial y misiles, según muestran los planes presupuestarios de defensa

                                    Los fabricantes de automóviles japoneses Nissan y Honda acuerdan trabajar juntos en software para automóviles

                                    Los fabricantes de automóviles japoneses Nissan y Honda acuerdan trabajar juntos en software para automóviles

                                    El lago Ontario ahora se llama Lake America en Google Maps para los usuarios de EE. UU. después de que Trump ordenara el cambio de nombre

                                    El lago Ontario ahora se llama Lake America en Google Maps para los usuarios de EE. UU. después de que Trump ordenara el cambio de nombre

                                    Qué transmitir: 'Mandalorian & Grogu', el reality show de Alix Earle, 'I Know Too Much' de Ellie Goulding

                                    Qué transmitir: ‘Mandalorian & Grogu’, el reality show de Alix Earle, ‘I Know Too Much’ de Ellie Goulding

                                    La inteligencia artificial y la robótica impulsan un auge de las OPI en China mientras Shein cotiza en Hong Kong

                                    La inteligencia artificial y la robótica impulsan un auge de las OPI en China mientras Shein cotiza en Hong Kong

                                    Los agentes de IA necesitan su propia identidad antes de necesitar una puerta de enlace

                                    Los agentes de IA necesitan su propia identidad antes de necesitar una puerta de enlace

                                    Trending Tags

                                    • Entretenimiento
                                      • All
                                      • Cine y Series
                                      • Cultura Digital
                                      • Cultura Popular
                                      • Gastronomía
                                      • Música
                                      Celine Dion está de regreso en París, pero su primera canción sigue siendo "un gran secreto"

                                      Celine Dion está de regreso en París, pero su primera canción sigue siendo «un gran secreto»

                                      30 pasajeros son evacuados después de que un crucero encallara en un arrecife en Fiji

                                      La ‘Odisea’ de Emily Wilson se convirtió en un punto de inflamación cultural. Ahora ella está retraduciendo todo.

                                      Editor, editor y reportero de Stars and Stripes demandan al Pentágono para impugnar sus despidos

                                      Editor, editor y reportero de Stars and Stripes demandan al Pentágono para impugnar sus despidos

                                      Muere Peter Cullen, el prolífico actor de doblaje que le dio a Optimus Prime su autoritario barítono

                                      Muere Peter Cullen, el prolífico actor de doblaje que le dio a Optimus Prime su autoritario barítono

                                      Juez pregunta por qué el Kennedy Center se está moviendo tan rápido para devolver el nombre de Trump al edificio

                                      Juez pregunta por qué el Kennedy Center se está moviendo tan rápido para devolver el nombre de Trump al edificio

                                      En el conflictivo norte de Nigeria, una animada vida nocturna convive con una policía moral e inseguridad.

                                      En el conflictivo norte de Nigeria, una animada vida nocturna convive con una policía moral e inseguridad.

                                      Un teatro reinventa la Odisea de Homero a través de la agonía de la guerra de Ucrania

                                      Un teatro reinventa la Odisea de Homero a través de la agonía de la guerra de Ucrania

                                      El rapero Yung Filly regresará a Gran Bretaña antes del juicio por violación en Australia el próximo año

                                      El rapero Yung Filly regresará a Gran Bretaña antes del juicio por violación en Australia el próximo año

                                      30 pasajeros son evacuados después de que un crucero encallara en un arrecife en Fiji

                                      Los británicos tienen la oportunidad de leer las memorias de Jason Arday en las librerías del Reino Unido

                                      Trending Tags

                                      No Result
                                      View All Result
                                      Despertar Matinal
                                      No Result
                                      View All Result

                                      OpenClaw 2.0 is here, ushering in the era of ‘multiplayer’ AI coding: What it means for enterprises

                                      by — Redacción Despertar Matinal
                                      31 de agosto de 2026
                                      in Tecnología
                                      0
                                      OpenClaw 2.0 is here, ushering in the era of 'multiplayer' AI coding: What it means for enterprises
                                      0
                                      SHARES
                                      2
                                      VIEWS
                                      Share on FacebookShare on Twitter

                                      The viral fervor we saw earlier this year around OpenClaw, the open source AI harness that turns powerful language models into autonomous workers the user can message via their favorite channels (Telegram, iMessage, WhatsApp, Discord etc), has cooled off substantially from its peak in March 2026.

                                      But over the weekend, OpenClaw’s creator Peter Steinberger and current team of co-developers gave the world — especially enterprises — a reason to look at it again, announcing OpenClaw 2.0, billed as the most significant update to the harness and surrounding platform yet.

                                      OpenClaw 2.0 seeks to transform what began largely as a personal agent harness into something increasingly designed for teams, shared infrastructure and enterprise workflows.

                                      OpenClaw 2.0 introduces a rebuilt browser interface that brings conversations, files, approvals, configuration and live agent activity into a common workspace. It adds shared cloud sessions and multi-user collaboration. And it expands the security model with stronger sandboxing, role-based permissions, approval controls, secrets handling and auditing.

                                      Together, those additions move OpenClaw closer to being infrastructure that an organization could deploy for employees rather than simply a powerful agent an individual developer runs locally.

                                      They also sharpen a competitive question surrounding the project: whether OpenClaw has addressed the security and isolation concerns that helped inspire newer alternatives such as NanoClaw.

                                      The answer is increasingly yes at the capability level — but not necessarily by default.

                                      OpenClaw wants to become the shared agent layer

                                      Released under the official name of v2026.8.1, the update spans installation, messaging, memory, skills, models, automations, browser and native applications, plugins and security.

                                      Steinberger described the development of OpenClaw 2.0 as an exercise in using the product to build itself.

                                      “Two months ago, we started the mission to ‘build OpenClaw with OpenClaw,’” Steinberger wrote on X early on August 31.

                                      Over that period, he said, OpenClaw gradually moved its team away from individual local coding harnesses and toward team.openclaw.ai, a shared agent environment aware of what team members are working on.

                                      “Multiplayer coding + infinite compute with nodes and cloud sessions has been a game changer for how we build,” Steinberger wrote, adding that local harnesses now “feel like relics of the past.”

                                      That claim points toward one of the more important changes in OpenClaw’s enterprise proposition.

                                      The dominant model for AI coding agents has generally been individual: a developer runs an agent in a terminal, IDE or desktop application, gives it access to a repository and lets it execute work within that environment.

                                      OpenClaw 2.0 is pushing toward something different. Agent sessions can become persistent workspaces that outlive a single terminal or employee. They can be shared with colleagues, executed across other machines or cloud workers, and supervised through a browser.

                                      For enterprises, that potentially turns the agent from an employee-level productivity application into a shared operational layer.

                                      A new UI could broaden OpenClaw beyond developers

                                      New OpenClaw UI promotional screenshot. Credit: OpenClaw

                                      The redesigned Control UI is central to that strategy.

                                      OpenClaw has shifted away from an Overview-first web application and made conversations the primary interface. Threads sit in a sidebar, while the active conversation occupies the main workspace. Files, approvals, settings and ongoing agent activity remain accessible around it.

                                      The design deliberately brings OpenClaw closer to the interaction model employees already know from OpenAI’s ChatGPT, Anthropic’s Claude, Google’s Gemini and other conversational AI products.

                                      That lowers an important barrier to enterprise adoption. Open-source agent frameworks are often powerful precisely because they expose low-level configuration, terminals, tools and runtime controls. Those same characteristics can make them difficult to deploy beyond engineering organizations.

                                      OpenClaw 2.0 attempts to preserve the underlying control while putting a conversational interface on top of it. An employee can ask an agent to perform work without treating the terminal as the primary product interface. But OpenClaw does not hide what is happening underneath. The Control UI can surface session files, terminal activity, Git-backed changes, pull-request state, browser activity and interactive dashboards.

                                      The release also places more emphasis on observability during agent execution. Tool calls and results are paired more clearly, file changes can appear as focused diffs, command activity is easier to inspect, and long-running background tasks can remain visible alongside the conversation. That combination matters for enterprise use.

                                      Employees get a simpler interface for delegating work. Technical users retain access to the artifacts and execution state behind the conversation. Administrators gain a centralized place to configure and supervise the system.

                                      The redesigned Settings workspace now encompasses agents, memory, plugins, MCP servers, devices, communication channels and device pairing. OpenClaw also consolidates model-provider administration, including credential status and, where providers expose it, model availability, quota, account balance, budget and spending information.

                                      Limited-access browser users can request administrator privileges rather than automatically receiving them, with another administrator required to approve the escalation.

                                      These are not especially flashy agent features. For companies deploying AI systems to dozens or hundreds of employees, they may be among the most important additions in the release.

                                      Multiplayer sessions turn agent context into shared context

                                      OpenClaw 2.0 also expands the agent from a personal workspace into a collaborative one.

                                      Shared cloud sessions allow another employee to enter work already in progress without discarding the context accumulated by the agent.

                                      Multi-user Gateways — the service that connects users and agents to tools, files, credentials and other resources — can track who created a conversation and which prompts were submitted by identified participants.

                                      Owners and administrators can determine whether another user can read a session, suggest changes, work in draft mode or participate directly.

                                      The interface adds session ownership, participant attribution, presence and even typing indicators. For coding teams, that introduces a workflow closer to collaborative software development than traditional AI chat.

                                      A developer could initiate a task and allow an agent to work on it remotely. Another engineer could inspect the resulting changes. A senior engineer or administrator could approve an operation requiring additional privileges. The work does not have to remain attached to the laptop or terminal where it started.

                                      Sessions can also move execution to paired devices or cloud workers while maintaining the broader workspace.

                                      For enterprises experimenting with long-running agents, that is significant. Persistent agents need mechanisms for shift changes, escalation, supervision and ownership transfer. Otherwise, organizations simply create fleets of personal agents whose state disappears into individual user environments.

                                      OpenClaw is attempting to turn that state into collaborative infrastructure. Already, some teams outside the developers of the open source project are adopting it.

                                      Colin Johnson, CEO of marketing metrics software firm Solvely, described a similar shift in his own development workflow in a post on X.

                                      His team had already been using OpenClaw agents through Discord, where developers could assign tasks, run commands and interact with their development environment. But he said that model still felt like “messaging a bot”: developers could share access to an agent without actually sharing the agent’s working context.

                                      The new multiplayer WebUI changed that, he wrote, because two developers could open the same live session, see the same history and artifacts, and add information without first exporting or reconstructing what the agent had already done. “We were working inside the same context,” Colin wrote.

                                      In one example, another developer was taking over a project he had been working on; instead of preparing a traditional handoff document, Colin joined the developer’s existing agent thread and added the missing project context directly. “The session itself became the handoff document,” he wrote.

                                      For enterprise teams, that is a useful illustration of why persistent multiplayer sessions may matter beyond convenience: agent context can become a shared work artifact rather than information trapped inside one employee’s private conversation.

                                      Colin’s deployment also illustrates both the enterprise potential and the remaining security boundary. His team runs its OpenClaw Gateway on a development server reachable through GitHub authentication, Cloudflare Access and a Cloudflare Tunnel, with the Gateway itself listening only on the server’s loopback interface rather than an exposed public port.

                                      But he explicitly cautioned that this does not make the shared Gateway a multitenant environment. The developers already trust one another with the repositories, tools and agent capabilities behind it. As he put it, Cloudflare controls who can enter the workspace, while OpenClaw tracks who created, owns or contributed to the work; stronger separation still requires separate infrastructure.

                                      Security becomes much more enterprise-oriented

                                      That shift creates a corresponding security problem: a shared agent can potentially act with broader organizational authority than one running on a developer laptop.

                                      OpenClaw 2.0 responds with considerably more granular controls.

                                      Approvals can now be tied to a specific request, command, session and person. Command permissions can be constrained to specific arguments and working directories. For script-backed execution, OpenClaw can verify that the script being executed still matches what was originally reviewed.

                                      Sessions can operate under different permission levels, including read-only, guarded, workspace and full-access modes, with the highest level restricted to administrators.

                                      Organizations can also define operator roles that require sandboxed execution for sessions created by specific identities. OpenClaw says those requirements cannot be bypassed using elevated execution or host overrides; if the required sandbox cannot be provisioned, execution fails rather than silently falling back to the host.

                                      Credentials receive additional protection.

                                      OpenClaw’s team-scoped Secret Store distinguishes protected secrets from ordinary environment data available to the agent. For supported requests, a protected credential can be substituted into a Gateway-hosted HTTPS request without exposing that credential directly to the model.

                                      OpenClaw can also reference external systems including 1Password and Vault.

                                      Auditing has expanded around execution identity, approvals, session actions and outbound messages. Plugin installation can trigger capability reviews associated with the specific artifact being installed.

                                      Those controls address questions enterprises inevitably face when deploying agents: Who initiated an action? Which agent performed it? What resources could it access? Who approved the operation? And what happens to those permissions when work moves between people or machines?

                                      NanoClaw still takes a different approach to security

                                      OpenClaw’s changes also make the comparison with open source, enterprise-friendly rival NanoClaw more nuanced.

                                      NanoClaw is one of several subsequent projects to emerge around the idea that AI agents need stronger isolation and simpler security boundaries. Its architecture places operating-system-level containment at the center of the design.

                                      NanoClaw runs agents inside Docker containers, limits those containers to explicitly mounted filesystems and runs their processes as an unprivileged user. Sessions and agent groups can remain isolated rather than automatically sharing files and conversation history.

                                      Its credential architecture follows the same principle. Supported outbound requests can pass through OneCLI’s Agent Vault, allowing credentials to be injected by a gateway rather than placed inside the agent container itself. NanoClaw also provides an optional egress-lockdown mode that puts agents on an internal Docker network and routes supported external traffic through the gateway.

                                      OpenClaw 2.0 can now reproduce many elements of that hardened model. It supports Docker and Podman sandboxes, per-agent and per-session sandbox scopes, configurable read-only or read-write workspace access, role-enforced sandboxing, remote execution nodes and disposable cloud workers.

                                      The key difference is the starting posture. OpenClaw’s documentation explicitly says sandboxing and execution approvals are off by default. Its baseline configuration assumes a trusted single operator and permits host execution unless administrators configure stronger restrictions. NanoClaw makes isolation more fundamental to how agent execution is structured.

                                      So does OpenClaw 2.0 have security parity with NanoClaw?

                                      In terms of available controls, it is much closer than before. In terms of defaults and architectural philosophy, no. An enterprise can configure OpenClaw into a substantially hardened environment, but it has to make that decision deliberately.

                                      One Gateway is still one trust domain

                                      Another limitation is particularly important for larger organizations. OpenClaw says a Gateway should be treated as a single trust domain.

                                      Its new multi-user permissions are designed to govern collaboration among trusted users. They should not be treated as hard isolation between mutually untrusted tenants.

                                      For organizations requiring stronger separation — between business units, customers or other security domains, for example — OpenClaw recommends separate Gateway instances, described as “cells,” with separate state, credentials and workspaces.

                                      Fleet tooling for managing those cells remains experimental.

                                      That distinction could matter significantly for enterprises considering OpenClaw as a centrally operated service.

                                      Role-based access inside one Gateway may be sufficient for a trusted engineering department or internal team. It is a different proposition from a multi-tenant platform intended to isolate customers or users who should be assumed hostile to one another.

                                      NanoClaw has its own configuration requirements and limitations, and even its stronger outbound-network lockdown remains optional. But its smaller architecture and container-centric execution model may appeal to organizations that want a narrower security boundary that is easier to reason about.

                                      OpenClaw is optimizing for a broader problem.

                                      OpenClaw’s biggest advantage may be the control plane

                                      The tradeoff is product breadth.

                                      NanoClaw emphasizes a relatively small codebase, container isolation and customization through code and skills. Its second-generation architecture supports owner, administrator and member roles, and a separate monitoring dashboard can provide visibility into deployments.

                                      OpenClaw 2.0 is trying to build a much broader operational environment.

                                      Its Control UI combines employee interaction, live execution, files, approvals, terminals, code review, model-provider configuration, devices and shared sessions.

                                      That gives OpenClaw a potential advantage for enterprises that need not only secure agent execution but a usable control plane around it.

                                      Security teams care about isolation. Platform teams also need deployment, authentication, model configuration, auditing and policy enforcement. Employees need an interface they can actually use. Managers need a way to understand what is running. Developers need access to the underlying files and tools when something goes wrong.

                                      OpenClaw 2.0 increasingly tries to serve all of those constituencies through one system.

                                      What is OpenAI’s role?

                                      OpenClaw says 933 contributors, including 569 first-time contributors, participated in the release, which includes more than 16,000 pull requests — roughly half of all pull requests ever merged into the project.

                                      Interestingly, the release was not shared by Steinberger’s employer, OpenAI. Recall that the Austrian developer announced on Feb. 14, 2026 that he was joining OpenAI to work on bringing agents to a broader audience, a move OpenAI CEO Sam Altman publicly confirmed the following day.

                                      But OpenClaw was not folded into OpenAI. Steinberger said at the time that OpenClaw would move to a foundation and “stay open and independent,” while OpenAI would support the project. OpenClaw now says it is stewarded by the OpenClaw Foundation, an independent 501(c)(3), with OpenAI listed alongside Microsoft, GitHub, NVIDIA, Atlassian, Tencent and other organizations as partners.

                                      Based on the available public information, OpenClaw 2.0 should therefore be understood as an OpenClaw Foundation release, not an OpenAI product or OpenAI software release, despite Steinberger’s employment at OpenAI and OpenAI’s financial and organizational support for the project.

                                      Enterprise readiness now depends on configuration

                                      OpenClaw 2.0 does not eliminate the security risks associated with autonomous agents, and its own documentation identifies limitations.

                                      Secret Store values, for example, are not themselves encrypted at rest and rely on filesystem protections. Protected credential substitution does not cover every possible execution path, including some raw sockets, containers, remote nodes and provider-native harnessesIts multi-user permissions are collaboration controls, not hostile-tenant isolation.

                                      Those caveats should prevent enterprises from interpreting OpenClaw 2.0 as secure-by-default agent infrastructure.But they also illustrate how much the conversation around the project has changed. The relevant comparison is increasingly not simply OpenClaw versus NanoClaw. It is a container-first, constrained system such as NanoClaw versus a deliberately hardened OpenClaw deployment that provides a substantially broader employee and administrator experience.

                                      NanoClaw retains a strong proposition for organizations prioritizing a small attack surface, container-first execution and architectural simplicity.

                                      OpenClaw is making another bet: that enterprises ultimately need an agent platform to function as both runtime and workplace.

                                      OpenClaw 2.0 provides many of the primitives needed to build that environment — sandboxing, permissions, protected credentials, approvals, identity, auditing and isolated deployments — alongside a browser interface designed to make the system accessible to employees who will never configure an agent from a terminal.

                                      The remaining caveat is important: enterprises have to turn those primitives into policy. OpenClaw 2.0 doesn’t automatically make OpenClaw enterprise-ready, but it does make an enterprise-grade OpenClaw deployment far easier out-of-the-box.

                                      And as Steinberger’s description of OpenClaw’s own development process suggests, the long-term ambition may be larger still. Rather than giving every employee another AI assistant, OpenClaw is positioning the agent itself as shared infrastructure — a persistent layer where people, models and compute collaborate on the same work.

                                      Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado

                                      The viral fervor we saw earlier this year around OpenClaw, the open source AI harness that turns powerful language models into autonomous workers the user can message via their favorite channels (Telegram, iMessage, WhatsApp, Discord etc), has cooled off substantially from its peak in March 2026.

                                      But over the weekend, OpenClaw’s creator Peter Steinberger and current team of co-developers gave the world — especially enterprises — a reason to look at it again, announcing OpenClaw 2.0, billed as the most significant update to the harness and surrounding platform yet.

                                      OpenClaw 2.0 seeks to transform what began largely as a personal agent harness into something increasingly designed for teams, shared infrastructure and enterprise workflows.

                                      OpenClaw 2.0 introduces a rebuilt browser interface that brings conversations, files, approvals, configuration and live agent activity into a common workspace. It adds shared cloud sessions and multi-user collaboration. And it expands the security model with stronger sandboxing, role-based permissions, approval controls, secrets handling and auditing.

                                      Together, those additions move OpenClaw closer to being infrastructure that an organization could deploy for employees rather than simply a powerful agent an individual developer runs locally.

                                      They also sharpen a competitive question surrounding the project: whether OpenClaw has addressed the security and isolation concerns that helped inspire newer alternatives such as NanoClaw.

                                      The answer is increasingly yes at the capability level — but not necessarily by default.

                                      OpenClaw wants to become the shared agent layer

                                      Released under the official name of v2026.8.1, the update spans installation, messaging, memory, skills, models, automations, browser and native applications, plugins and security.

                                      Steinberger described the development of OpenClaw 2.0 as an exercise in using the product to build itself.

                                      “Two months ago, we started the mission to ‘build OpenClaw with OpenClaw,’” Steinberger wrote on X early on August 31.

                                      Over that period, he said, OpenClaw gradually moved its team away from individual local coding harnesses and toward team.openclaw.ai, a shared agent environment aware of what team members are working on.

                                      “Multiplayer coding + infinite compute with nodes and cloud sessions has been a game changer for how we build,” Steinberger wrote, adding that local harnesses now “feel like relics of the past.”

                                      That claim points toward one of the more important changes in OpenClaw’s enterprise proposition.

                                      The dominant model for AI coding agents has generally been individual: a developer runs an agent in a terminal, IDE or desktop application, gives it access to a repository and lets it execute work within that environment.

                                      OpenClaw 2.0 is pushing toward something different. Agent sessions can become persistent workspaces that outlive a single terminal or employee. They can be shared with colleagues, executed across other machines or cloud workers, and supervised through a browser.

                                      For enterprises, that potentially turns the agent from an employee-level productivity application into a shared operational layer.

                                      A new UI could broaden OpenClaw beyond developers

                                      New OpenClaw UI promotional screenshot. Credit: OpenClaw

                                      The redesigned Control UI is central to that strategy.

                                      OpenClaw has shifted away from an Overview-first web application and made conversations the primary interface. Threads sit in a sidebar, while the active conversation occupies the main workspace. Files, approvals, settings and ongoing agent activity remain accessible around it.

                                      The design deliberately brings OpenClaw closer to the interaction model employees already know from OpenAI’s ChatGPT, Anthropic’s Claude, Google’s Gemini and other conversational AI products.

                                      That lowers an important barrier to enterprise adoption. Open-source agent frameworks are often powerful precisely because they expose low-level configuration, terminals, tools and runtime controls. Those same characteristics can make them difficult to deploy beyond engineering organizations.

                                      OpenClaw 2.0 attempts to preserve the underlying control while putting a conversational interface on top of it. An employee can ask an agent to perform work without treating the terminal as the primary product interface. But OpenClaw does not hide what is happening underneath. The Control UI can surface session files, terminal activity, Git-backed changes, pull-request state, browser activity and interactive dashboards.

                                      The release also places more emphasis on observability during agent execution. Tool calls and results are paired more clearly, file changes can appear as focused diffs, command activity is easier to inspect, and long-running background tasks can remain visible alongside the conversation. That combination matters for enterprise use.

                                      Employees get a simpler interface for delegating work. Technical users retain access to the artifacts and execution state behind the conversation. Administrators gain a centralized place to configure and supervise the system.

                                      The redesigned Settings workspace now encompasses agents, memory, plugins, MCP servers, devices, communication channels and device pairing. OpenClaw also consolidates model-provider administration, including credential status and, where providers expose it, model availability, quota, account balance, budget and spending information.

                                      Limited-access browser users can request administrator privileges rather than automatically receiving them, with another administrator required to approve the escalation.

                                      These are not especially flashy agent features. For companies deploying AI systems to dozens or hundreds of employees, they may be among the most important additions in the release.

                                      Multiplayer sessions turn agent context into shared context

                                      OpenClaw 2.0 also expands the agent from a personal workspace into a collaborative one.

                                      Shared cloud sessions allow another employee to enter work already in progress without discarding the context accumulated by the agent.

                                      Multi-user Gateways — the service that connects users and agents to tools, files, credentials and other resources — can track who created a conversation and which prompts were submitted by identified participants.

                                      Owners and administrators can determine whether another user can read a session, suggest changes, work in draft mode or participate directly.

                                      The interface adds session ownership, participant attribution, presence and even typing indicators. For coding teams, that introduces a workflow closer to collaborative software development than traditional AI chat.

                                      A developer could initiate a task and allow an agent to work on it remotely. Another engineer could inspect the resulting changes. A senior engineer or administrator could approve an operation requiring additional privileges. The work does not have to remain attached to the laptop or terminal where it started.

                                      Sessions can also move execution to paired devices or cloud workers while maintaining the broader workspace.

                                      For enterprises experimenting with long-running agents, that is significant. Persistent agents need mechanisms for shift changes, escalation, supervision and ownership transfer. Otherwise, organizations simply create fleets of personal agents whose state disappears into individual user environments.

                                      OpenClaw is attempting to turn that state into collaborative infrastructure. Already, some teams outside the developers of the open source project are adopting it.

                                      Colin Johnson, CEO of marketing metrics software firm Solvely, described a similar shift in his own development workflow in a post on X.

                                      His team had already been using OpenClaw agents through Discord, where developers could assign tasks, run commands and interact with their development environment. But he said that model still felt like “messaging a bot”: developers could share access to an agent without actually sharing the agent’s working context.

                                      The new multiplayer WebUI changed that, he wrote, because two developers could open the same live session, see the same history and artifacts, and add information without first exporting or reconstructing what the agent had already done. “We were working inside the same context,” Colin wrote.

                                      In one example, another developer was taking over a project he had been working on; instead of preparing a traditional handoff document, Colin joined the developer’s existing agent thread and added the missing project context directly. “The session itself became the handoff document,” he wrote.

                                      For enterprise teams, that is a useful illustration of why persistent multiplayer sessions may matter beyond convenience: agent context can become a shared work artifact rather than information trapped inside one employee’s private conversation.

                                      Colin’s deployment also illustrates both the enterprise potential and the remaining security boundary. His team runs its OpenClaw Gateway on a development server reachable through GitHub authentication, Cloudflare Access and a Cloudflare Tunnel, with the Gateway itself listening only on the server’s loopback interface rather than an exposed public port.

                                      But he explicitly cautioned that this does not make the shared Gateway a multitenant environment. The developers already trust one another with the repositories, tools and agent capabilities behind it. As he put it, Cloudflare controls who can enter the workspace, while OpenClaw tracks who created, owns or contributed to the work; stronger separation still requires separate infrastructure.

                                      Security becomes much more enterprise-oriented

                                      That shift creates a corresponding security problem: a shared agent can potentially act with broader organizational authority than one running on a developer laptop.

                                      OpenClaw 2.0 responds with considerably more granular controls.

                                      Approvals can now be tied to a specific request, command, session and person. Command permissions can be constrained to specific arguments and working directories. For script-backed execution, OpenClaw can verify that the script being executed still matches what was originally reviewed.

                                      Sessions can operate under different permission levels, including read-only, guarded, workspace and full-access modes, with the highest level restricted to administrators.

                                      Organizations can also define operator roles that require sandboxed execution for sessions created by specific identities. OpenClaw says those requirements cannot be bypassed using elevated execution or host overrides; if the required sandbox cannot be provisioned, execution fails rather than silently falling back to the host.

                                      Credentials receive additional protection.

                                      OpenClaw’s team-scoped Secret Store distinguishes protected secrets from ordinary environment data available to the agent. For supported requests, a protected credential can be substituted into a Gateway-hosted HTTPS request without exposing that credential directly to the model.

                                      OpenClaw can also reference external systems including 1Password and Vault.

                                      Auditing has expanded around execution identity, approvals, session actions and outbound messages. Plugin installation can trigger capability reviews associated with the specific artifact being installed.

                                      Those controls address questions enterprises inevitably face when deploying agents: Who initiated an action? Which agent performed it? What resources could it access? Who approved the operation? And what happens to those permissions when work moves between people or machines?

                                      NanoClaw still takes a different approach to security

                                      OpenClaw’s changes also make the comparison with open source, enterprise-friendly rival NanoClaw more nuanced.

                                      NanoClaw is one of several subsequent projects to emerge around the idea that AI agents need stronger isolation and simpler security boundaries. Its architecture places operating-system-level containment at the center of the design.

                                      NanoClaw runs agents inside Docker containers, limits those containers to explicitly mounted filesystems and runs their processes as an unprivileged user. Sessions and agent groups can remain isolated rather than automatically sharing files and conversation history.

                                      Its credential architecture follows the same principle. Supported outbound requests can pass through OneCLI’s Agent Vault, allowing credentials to be injected by a gateway rather than placed inside the agent container itself. NanoClaw also provides an optional egress-lockdown mode that puts agents on an internal Docker network and routes supported external traffic through the gateway.

                                      OpenClaw 2.0 can now reproduce many elements of that hardened model. It supports Docker and Podman sandboxes, per-agent and per-session sandbox scopes, configurable read-only or read-write workspace access, role-enforced sandboxing, remote execution nodes and disposable cloud workers.

                                      The key difference is the starting posture. OpenClaw’s documentation explicitly says sandboxing and execution approvals are off by default. Its baseline configuration assumes a trusted single operator and permits host execution unless administrators configure stronger restrictions. NanoClaw makes isolation more fundamental to how agent execution is structured.

                                      So does OpenClaw 2.0 have security parity with NanoClaw?

                                      In terms of available controls, it is much closer than before. In terms of defaults and architectural philosophy, no. An enterprise can configure OpenClaw into a substantially hardened environment, but it has to make that decision deliberately.

                                      One Gateway is still one trust domain

                                      Another limitation is particularly important for larger organizations. OpenClaw says a Gateway should be treated as a single trust domain.

                                      Its new multi-user permissions are designed to govern collaboration among trusted users. They should not be treated as hard isolation between mutually untrusted tenants.

                                      For organizations requiring stronger separation — between business units, customers or other security domains, for example — OpenClaw recommends separate Gateway instances, described as “cells,” with separate state, credentials and workspaces.

                                      Fleet tooling for managing those cells remains experimental.

                                      That distinction could matter significantly for enterprises considering OpenClaw as a centrally operated service.

                                      Role-based access inside one Gateway may be sufficient for a trusted engineering department or internal team. It is a different proposition from a multi-tenant platform intended to isolate customers or users who should be assumed hostile to one another.

                                      NanoClaw has its own configuration requirements and limitations, and even its stronger outbound-network lockdown remains optional. But its smaller architecture and container-centric execution model may appeal to organizations that want a narrower security boundary that is easier to reason about.

                                      OpenClaw is optimizing for a broader problem.

                                      OpenClaw’s biggest advantage may be the control plane

                                      The tradeoff is product breadth.

                                      NanoClaw emphasizes a relatively small codebase, container isolation and customization through code and skills. Its second-generation architecture supports owner, administrator and member roles, and a separate monitoring dashboard can provide visibility into deployments.

                                      OpenClaw 2.0 is trying to build a much broader operational environment.

                                      Its Control UI combines employee interaction, live execution, files, approvals, terminals, code review, model-provider configuration, devices and shared sessions.

                                      That gives OpenClaw a potential advantage for enterprises that need not only secure agent execution but a usable control plane around it.

                                      Security teams care about isolation. Platform teams also need deployment, authentication, model configuration, auditing and policy enforcement. Employees need an interface they can actually use. Managers need a way to understand what is running. Developers need access to the underlying files and tools when something goes wrong.

                                      OpenClaw 2.0 increasingly tries to serve all of those constituencies through one system.

                                      What is OpenAI’s role?

                                      OpenClaw says 933 contributors, including 569 first-time contributors, participated in the release, which includes more than 16,000 pull requests — roughly half of all pull requests ever merged into the project.

                                      Interestingly, the release was not shared by Steinberger’s employer, OpenAI. Recall that the Austrian developer announced on Feb. 14, 2026 that he was joining OpenAI to work on bringing agents to a broader audience, a move OpenAI CEO Sam Altman publicly confirmed the following day.

                                      But OpenClaw was not folded into OpenAI. Steinberger said at the time that OpenClaw would move to a foundation and “stay open and independent,” while OpenAI would support the project. OpenClaw now says it is stewarded by the OpenClaw Foundation, an independent 501(c)(3), with OpenAI listed alongside Microsoft, GitHub, NVIDIA, Atlassian, Tencent and other organizations as partners.

                                      Based on the available public information, OpenClaw 2.0 should therefore be understood as an OpenClaw Foundation release, not an OpenAI product or OpenAI software release, despite Steinberger’s employment at OpenAI and OpenAI’s financial and organizational support for the project.

                                      Enterprise readiness now depends on configuration

                                      OpenClaw 2.0 does not eliminate the security risks associated with autonomous agents, and its own documentation identifies limitations.

                                      Secret Store values, for example, are not themselves encrypted at rest and rely on filesystem protections. Protected credential substitution does not cover every possible execution path, including some raw sockets, containers, remote nodes and provider-native harnessesIts multi-user permissions are collaboration controls, not hostile-tenant isolation.

                                      Those caveats should prevent enterprises from interpreting OpenClaw 2.0 as secure-by-default agent infrastructure.But they also illustrate how much the conversation around the project has changed. The relevant comparison is increasingly not simply OpenClaw versus NanoClaw. It is a container-first, constrained system such as NanoClaw versus a deliberately hardened OpenClaw deployment that provides a substantially broader employee and administrator experience.

                                      NanoClaw retains a strong proposition for organizations prioritizing a small attack surface, container-first execution and architectural simplicity.

                                      OpenClaw is making another bet: that enterprises ultimately need an agent platform to function as both runtime and workplace.

                                      OpenClaw 2.0 provides many of the primitives needed to build that environment — sandboxing, permissions, protected credentials, approvals, identity, auditing and isolated deployments — alongside a browser interface designed to make the system accessible to employees who will never configure an agent from a terminal.

                                      The remaining caveat is important: enterprises have to turn those primitives into policy. OpenClaw 2.0 doesn’t automatically make OpenClaw enterprise-ready, but it does make an enterprise-grade OpenClaw deployment far easier out-of-the-box.

                                      And as Steinberger’s description of OpenClaw’s own development process suggests, the long-term ambition may be larger still. Rather than giving every employee another AI assistant, OpenClaw is positioning the agent itself as shared infrastructure — a persistent layer where people, models and compute collaborate on the same work.

                                      Tours Colombia Todo el año Tours Colombia Todo el año Tours Colombia Todo el año

                                      The viral fervor we saw earlier this year around OpenClaw, the open source AI harness that turns powerful language models into autonomous workers the user can message via their favorite channels (Telegram, iMessage, WhatsApp, Discord etc), has cooled off substantially from its peak in March 2026.

                                      But over the weekend, OpenClaw’s creator Peter Steinberger and current team of co-developers gave the world — especially enterprises — a reason to look at it again, announcing OpenClaw 2.0, billed as the most significant update to the harness and surrounding platform yet.

                                      OpenClaw 2.0 seeks to transform what began largely as a personal agent harness into something increasingly designed for teams, shared infrastructure and enterprise workflows.

                                      OpenClaw 2.0 introduces a rebuilt browser interface that brings conversations, files, approvals, configuration and live agent activity into a common workspace. It adds shared cloud sessions and multi-user collaboration. And it expands the security model with stronger sandboxing, role-based permissions, approval controls, secrets handling and auditing.

                                      Together, those additions move OpenClaw closer to being infrastructure that an organization could deploy for employees rather than simply a powerful agent an individual developer runs locally.

                                      They also sharpen a competitive question surrounding the project: whether OpenClaw has addressed the security and isolation concerns that helped inspire newer alternatives such as NanoClaw.

                                      The answer is increasingly yes at the capability level — but not necessarily by default.

                                      OpenClaw wants to become the shared agent layer

                                      Released under the official name of v2026.8.1, the update spans installation, messaging, memory, skills, models, automations, browser and native applications, plugins and security.

                                      Steinberger described the development of OpenClaw 2.0 as an exercise in using the product to build itself.

                                      “Two months ago, we started the mission to ‘build OpenClaw with OpenClaw,’” Steinberger wrote on X early on August 31.

                                      Over that period, he said, OpenClaw gradually moved its team away from individual local coding harnesses and toward team.openclaw.ai, a shared agent environment aware of what team members are working on.

                                      “Multiplayer coding + infinite compute with nodes and cloud sessions has been a game changer for how we build,” Steinberger wrote, adding that local harnesses now “feel like relics of the past.”

                                      That claim points toward one of the more important changes in OpenClaw’s enterprise proposition.

                                      The dominant model for AI coding agents has generally been individual: a developer runs an agent in a terminal, IDE or desktop application, gives it access to a repository and lets it execute work within that environment.

                                      OpenClaw 2.0 is pushing toward something different. Agent sessions can become persistent workspaces that outlive a single terminal or employee. They can be shared with colleagues, executed across other machines or cloud workers, and supervised through a browser.

                                      For enterprises, that potentially turns the agent from an employee-level productivity application into a shared operational layer.

                                      A new UI could broaden OpenClaw beyond developers

                                      New OpenClaw UI promotional screenshot. Credit: OpenClaw

                                      The redesigned Control UI is central to that strategy.

                                      OpenClaw has shifted away from an Overview-first web application and made conversations the primary interface. Threads sit in a sidebar, while the active conversation occupies the main workspace. Files, approvals, settings and ongoing agent activity remain accessible around it.

                                      The design deliberately brings OpenClaw closer to the interaction model employees already know from OpenAI’s ChatGPT, Anthropic’s Claude, Google’s Gemini and other conversational AI products.

                                      That lowers an important barrier to enterprise adoption. Open-source agent frameworks are often powerful precisely because they expose low-level configuration, terminals, tools and runtime controls. Those same characteristics can make them difficult to deploy beyond engineering organizations.

                                      OpenClaw 2.0 attempts to preserve the underlying control while putting a conversational interface on top of it. An employee can ask an agent to perform work without treating the terminal as the primary product interface. But OpenClaw does not hide what is happening underneath. The Control UI can surface session files, terminal activity, Git-backed changes, pull-request state, browser activity and interactive dashboards.

                                      The release also places more emphasis on observability during agent execution. Tool calls and results are paired more clearly, file changes can appear as focused diffs, command activity is easier to inspect, and long-running background tasks can remain visible alongside the conversation. That combination matters for enterprise use.

                                      Employees get a simpler interface for delegating work. Technical users retain access to the artifacts and execution state behind the conversation. Administrators gain a centralized place to configure and supervise the system.

                                      The redesigned Settings workspace now encompasses agents, memory, plugins, MCP servers, devices, communication channels and device pairing. OpenClaw also consolidates model-provider administration, including credential status and, where providers expose it, model availability, quota, account balance, budget and spending information.

                                      Limited-access browser users can request administrator privileges rather than automatically receiving them, with another administrator required to approve the escalation.

                                      These are not especially flashy agent features. For companies deploying AI systems to dozens or hundreds of employees, they may be among the most important additions in the release.

                                      Multiplayer sessions turn agent context into shared context

                                      OpenClaw 2.0 also expands the agent from a personal workspace into a collaborative one.

                                      Shared cloud sessions allow another employee to enter work already in progress without discarding the context accumulated by the agent.

                                      Multi-user Gateways — the service that connects users and agents to tools, files, credentials and other resources — can track who created a conversation and which prompts were submitted by identified participants.

                                      Owners and administrators can determine whether another user can read a session, suggest changes, work in draft mode or participate directly.

                                      The interface adds session ownership, participant attribution, presence and even typing indicators. For coding teams, that introduces a workflow closer to collaborative software development than traditional AI chat.

                                      A developer could initiate a task and allow an agent to work on it remotely. Another engineer could inspect the resulting changes. A senior engineer or administrator could approve an operation requiring additional privileges. The work does not have to remain attached to the laptop or terminal where it started.

                                      Sessions can also move execution to paired devices or cloud workers while maintaining the broader workspace.

                                      For enterprises experimenting with long-running agents, that is significant. Persistent agents need mechanisms for shift changes, escalation, supervision and ownership transfer. Otherwise, organizations simply create fleets of personal agents whose state disappears into individual user environments.

                                      OpenClaw is attempting to turn that state into collaborative infrastructure. Already, some teams outside the developers of the open source project are adopting it.

                                      Colin Johnson, CEO of marketing metrics software firm Solvely, described a similar shift in his own development workflow in a post on X.

                                      His team had already been using OpenClaw agents through Discord, where developers could assign tasks, run commands and interact with their development environment. But he said that model still felt like “messaging a bot”: developers could share access to an agent without actually sharing the agent’s working context.

                                      The new multiplayer WebUI changed that, he wrote, because two developers could open the same live session, see the same history and artifacts, and add information without first exporting or reconstructing what the agent had already done. “We were working inside the same context,” Colin wrote.

                                      In one example, another developer was taking over a project he had been working on; instead of preparing a traditional handoff document, Colin joined the developer’s existing agent thread and added the missing project context directly. “The session itself became the handoff document,” he wrote.

                                      For enterprise teams, that is a useful illustration of why persistent multiplayer sessions may matter beyond convenience: agent context can become a shared work artifact rather than information trapped inside one employee’s private conversation.

                                      Colin’s deployment also illustrates both the enterprise potential and the remaining security boundary. His team runs its OpenClaw Gateway on a development server reachable through GitHub authentication, Cloudflare Access and a Cloudflare Tunnel, with the Gateway itself listening only on the server’s loopback interface rather than an exposed public port.

                                      But he explicitly cautioned that this does not make the shared Gateway a multitenant environment. The developers already trust one another with the repositories, tools and agent capabilities behind it. As he put it, Cloudflare controls who can enter the workspace, while OpenClaw tracks who created, owns or contributed to the work; stronger separation still requires separate infrastructure.

                                      Security becomes much more enterprise-oriented

                                      That shift creates a corresponding security problem: a shared agent can potentially act with broader organizational authority than one running on a developer laptop.

                                      OpenClaw 2.0 responds with considerably more granular controls.

                                      Approvals can now be tied to a specific request, command, session and person. Command permissions can be constrained to specific arguments and working directories. For script-backed execution, OpenClaw can verify that the script being executed still matches what was originally reviewed.

                                      Sessions can operate under different permission levels, including read-only, guarded, workspace and full-access modes, with the highest level restricted to administrators.

                                      Organizations can also define operator roles that require sandboxed execution for sessions created by specific identities. OpenClaw says those requirements cannot be bypassed using elevated execution or host overrides; if the required sandbox cannot be provisioned, execution fails rather than silently falling back to the host.

                                      Credentials receive additional protection.

                                      OpenClaw’s team-scoped Secret Store distinguishes protected secrets from ordinary environment data available to the agent. For supported requests, a protected credential can be substituted into a Gateway-hosted HTTPS request without exposing that credential directly to the model.

                                      OpenClaw can also reference external systems including 1Password and Vault.

                                      Auditing has expanded around execution identity, approvals, session actions and outbound messages. Plugin installation can trigger capability reviews associated with the specific artifact being installed.

                                      Those controls address questions enterprises inevitably face when deploying agents: Who initiated an action? Which agent performed it? What resources could it access? Who approved the operation? And what happens to those permissions when work moves between people or machines?

                                      NanoClaw still takes a different approach to security

                                      OpenClaw’s changes also make the comparison with open source, enterprise-friendly rival NanoClaw more nuanced.

                                      NanoClaw is one of several subsequent projects to emerge around the idea that AI agents need stronger isolation and simpler security boundaries. Its architecture places operating-system-level containment at the center of the design.

                                      NanoClaw runs agents inside Docker containers, limits those containers to explicitly mounted filesystems and runs their processes as an unprivileged user. Sessions and agent groups can remain isolated rather than automatically sharing files and conversation history.

                                      Its credential architecture follows the same principle. Supported outbound requests can pass through OneCLI’s Agent Vault, allowing credentials to be injected by a gateway rather than placed inside the agent container itself. NanoClaw also provides an optional egress-lockdown mode that puts agents on an internal Docker network and routes supported external traffic through the gateway.

                                      OpenClaw 2.0 can now reproduce many elements of that hardened model. It supports Docker and Podman sandboxes, per-agent and per-session sandbox scopes, configurable read-only or read-write workspace access, role-enforced sandboxing, remote execution nodes and disposable cloud workers.

                                      The key difference is the starting posture. OpenClaw’s documentation explicitly says sandboxing and execution approvals are off by default. Its baseline configuration assumes a trusted single operator and permits host execution unless administrators configure stronger restrictions. NanoClaw makes isolation more fundamental to how agent execution is structured.

                                      So does OpenClaw 2.0 have security parity with NanoClaw?

                                      In terms of available controls, it is much closer than before. In terms of defaults and architectural philosophy, no. An enterprise can configure OpenClaw into a substantially hardened environment, but it has to make that decision deliberately.

                                      One Gateway is still one trust domain

                                      Another limitation is particularly important for larger organizations. OpenClaw says a Gateway should be treated as a single trust domain.

                                      Its new multi-user permissions are designed to govern collaboration among trusted users. They should not be treated as hard isolation between mutually untrusted tenants.

                                      For organizations requiring stronger separation — between business units, customers or other security domains, for example — OpenClaw recommends separate Gateway instances, described as “cells,” with separate state, credentials and workspaces.

                                      Fleet tooling for managing those cells remains experimental.

                                      That distinction could matter significantly for enterprises considering OpenClaw as a centrally operated service.

                                      Role-based access inside one Gateway may be sufficient for a trusted engineering department or internal team. It is a different proposition from a multi-tenant platform intended to isolate customers or users who should be assumed hostile to one another.

                                      NanoClaw has its own configuration requirements and limitations, and even its stronger outbound-network lockdown remains optional. But its smaller architecture and container-centric execution model may appeal to organizations that want a narrower security boundary that is easier to reason about.

                                      OpenClaw is optimizing for a broader problem.

                                      OpenClaw’s biggest advantage may be the control plane

                                      The tradeoff is product breadth.

                                      NanoClaw emphasizes a relatively small codebase, container isolation and customization through code and skills. Its second-generation architecture supports owner, administrator and member roles, and a separate monitoring dashboard can provide visibility into deployments.

                                      OpenClaw 2.0 is trying to build a much broader operational environment.

                                      Its Control UI combines employee interaction, live execution, files, approvals, terminals, code review, model-provider configuration, devices and shared sessions.

                                      That gives OpenClaw a potential advantage for enterprises that need not only secure agent execution but a usable control plane around it.

                                      Security teams care about isolation. Platform teams also need deployment, authentication, model configuration, auditing and policy enforcement. Employees need an interface they can actually use. Managers need a way to understand what is running. Developers need access to the underlying files and tools when something goes wrong.

                                      OpenClaw 2.0 increasingly tries to serve all of those constituencies through one system.

                                      What is OpenAI’s role?

                                      OpenClaw says 933 contributors, including 569 first-time contributors, participated in the release, which includes more than 16,000 pull requests — roughly half of all pull requests ever merged into the project.

                                      Interestingly, the release was not shared by Steinberger’s employer, OpenAI. Recall that the Austrian developer announced on Feb. 14, 2026 that he was joining OpenAI to work on bringing agents to a broader audience, a move OpenAI CEO Sam Altman publicly confirmed the following day.

                                      But OpenClaw was not folded into OpenAI. Steinberger said at the time that OpenClaw would move to a foundation and “stay open and independent,” while OpenAI would support the project. OpenClaw now says it is stewarded by the OpenClaw Foundation, an independent 501(c)(3), with OpenAI listed alongside Microsoft, GitHub, NVIDIA, Atlassian, Tencent and other organizations as partners.

                                      Based on the available public information, OpenClaw 2.0 should therefore be understood as an OpenClaw Foundation release, not an OpenAI product or OpenAI software release, despite Steinberger’s employment at OpenAI and OpenAI’s financial and organizational support for the project.

                                      Enterprise readiness now depends on configuration

                                      OpenClaw 2.0 does not eliminate the security risks associated with autonomous agents, and its own documentation identifies limitations.

                                      Secret Store values, for example, are not themselves encrypted at rest and rely on filesystem protections. Protected credential substitution does not cover every possible execution path, including some raw sockets, containers, remote nodes and provider-native harnessesIts multi-user permissions are collaboration controls, not hostile-tenant isolation.

                                      Those caveats should prevent enterprises from interpreting OpenClaw 2.0 as secure-by-default agent infrastructure.But they also illustrate how much the conversation around the project has changed. The relevant comparison is increasingly not simply OpenClaw versus NanoClaw. It is a container-first, constrained system such as NanoClaw versus a deliberately hardened OpenClaw deployment that provides a substantially broader employee and administrator experience.

                                      NanoClaw retains a strong proposition for organizations prioritizing a small attack surface, container-first execution and architectural simplicity.

                                      OpenClaw is making another bet: that enterprises ultimately need an agent platform to function as both runtime and workplace.

                                      OpenClaw 2.0 provides many of the primitives needed to build that environment — sandboxing, permissions, protected credentials, approvals, identity, auditing and isolated deployments — alongside a browser interface designed to make the system accessible to employees who will never configure an agent from a terminal.

                                      The remaining caveat is important: enterprises have to turn those primitives into policy. OpenClaw 2.0 doesn’t automatically make OpenClaw enterprise-ready, but it does make an enterprise-grade OpenClaw deployment far easier out-of-the-box.

                                      And as Steinberger’s description of OpenClaw’s own development process suggests, the long-term ambition may be larger still. Rather than giving every employee another AI assistant, OpenClaw is positioning the agent itself as shared infrastructure — a persistent layer where people, models and compute collaborate on the same work.

                                      Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado

                                      The viral fervor we saw earlier this year around OpenClaw, the open source AI harness that turns powerful language models into autonomous workers the user can message via their favorite channels (Telegram, iMessage, WhatsApp, Discord etc), has cooled off substantially from its peak in March 2026.

                                      But over the weekend, OpenClaw’s creator Peter Steinberger and current team of co-developers gave the world — especially enterprises — a reason to look at it again, announcing OpenClaw 2.0, billed as the most significant update to the harness and surrounding platform yet.

                                      OpenClaw 2.0 seeks to transform what began largely as a personal agent harness into something increasingly designed for teams, shared infrastructure and enterprise workflows.

                                      OpenClaw 2.0 introduces a rebuilt browser interface that brings conversations, files, approvals, configuration and live agent activity into a common workspace. It adds shared cloud sessions and multi-user collaboration. And it expands the security model with stronger sandboxing, role-based permissions, approval controls, secrets handling and auditing.

                                      Together, those additions move OpenClaw closer to being infrastructure that an organization could deploy for employees rather than simply a powerful agent an individual developer runs locally.

                                      They also sharpen a competitive question surrounding the project: whether OpenClaw has addressed the security and isolation concerns that helped inspire newer alternatives such as NanoClaw.

                                      The answer is increasingly yes at the capability level — but not necessarily by default.

                                      OpenClaw wants to become the shared agent layer

                                      Released under the official name of v2026.8.1, the update spans installation, messaging, memory, skills, models, automations, browser and native applications, plugins and security.

                                      Steinberger described the development of OpenClaw 2.0 as an exercise in using the product to build itself.

                                      “Two months ago, we started the mission to ‘build OpenClaw with OpenClaw,’” Steinberger wrote on X early on August 31.

                                      Over that period, he said, OpenClaw gradually moved its team away from individual local coding harnesses and toward team.openclaw.ai, a shared agent environment aware of what team members are working on.

                                      “Multiplayer coding + infinite compute with nodes and cloud sessions has been a game changer for how we build,” Steinberger wrote, adding that local harnesses now “feel like relics of the past.”

                                      That claim points toward one of the more important changes in OpenClaw’s enterprise proposition.

                                      The dominant model for AI coding agents has generally been individual: a developer runs an agent in a terminal, IDE or desktop application, gives it access to a repository and lets it execute work within that environment.

                                      OpenClaw 2.0 is pushing toward something different. Agent sessions can become persistent workspaces that outlive a single terminal or employee. They can be shared with colleagues, executed across other machines or cloud workers, and supervised through a browser.

                                      For enterprises, that potentially turns the agent from an employee-level productivity application into a shared operational layer.

                                      A new UI could broaden OpenClaw beyond developers

                                      New OpenClaw UI promotional screenshot. Credit: OpenClaw

                                      The redesigned Control UI is central to that strategy.

                                      OpenClaw has shifted away from an Overview-first web application and made conversations the primary interface. Threads sit in a sidebar, while the active conversation occupies the main workspace. Files, approvals, settings and ongoing agent activity remain accessible around it.

                                      The design deliberately brings OpenClaw closer to the interaction model employees already know from OpenAI’s ChatGPT, Anthropic’s Claude, Google’s Gemini and other conversational AI products.

                                      That lowers an important barrier to enterprise adoption. Open-source agent frameworks are often powerful precisely because they expose low-level configuration, terminals, tools and runtime controls. Those same characteristics can make them difficult to deploy beyond engineering organizations.

                                      OpenClaw 2.0 attempts to preserve the underlying control while putting a conversational interface on top of it. An employee can ask an agent to perform work without treating the terminal as the primary product interface. But OpenClaw does not hide what is happening underneath. The Control UI can surface session files, terminal activity, Git-backed changes, pull-request state, browser activity and interactive dashboards.

                                      The release also places more emphasis on observability during agent execution. Tool calls and results are paired more clearly, file changes can appear as focused diffs, command activity is easier to inspect, and long-running background tasks can remain visible alongside the conversation. That combination matters for enterprise use.

                                      Employees get a simpler interface for delegating work. Technical users retain access to the artifacts and execution state behind the conversation. Administrators gain a centralized place to configure and supervise the system.

                                      The redesigned Settings workspace now encompasses agents, memory, plugins, MCP servers, devices, communication channels and device pairing. OpenClaw also consolidates model-provider administration, including credential status and, where providers expose it, model availability, quota, account balance, budget and spending information.

                                      Limited-access browser users can request administrator privileges rather than automatically receiving them, with another administrator required to approve the escalation.

                                      These are not especially flashy agent features. For companies deploying AI systems to dozens or hundreds of employees, they may be among the most important additions in the release.

                                      Multiplayer sessions turn agent context into shared context

                                      OpenClaw 2.0 also expands the agent from a personal workspace into a collaborative one.

                                      Shared cloud sessions allow another employee to enter work already in progress without discarding the context accumulated by the agent.

                                      Multi-user Gateways — the service that connects users and agents to tools, files, credentials and other resources — can track who created a conversation and which prompts were submitted by identified participants.

                                      Owners and administrators can determine whether another user can read a session, suggest changes, work in draft mode or participate directly.

                                      The interface adds session ownership, participant attribution, presence and even typing indicators. For coding teams, that introduces a workflow closer to collaborative software development than traditional AI chat.

                                      A developer could initiate a task and allow an agent to work on it remotely. Another engineer could inspect the resulting changes. A senior engineer or administrator could approve an operation requiring additional privileges. The work does not have to remain attached to the laptop or terminal where it started.

                                      Sessions can also move execution to paired devices or cloud workers while maintaining the broader workspace.

                                      For enterprises experimenting with long-running agents, that is significant. Persistent agents need mechanisms for shift changes, escalation, supervision and ownership transfer. Otherwise, organizations simply create fleets of personal agents whose state disappears into individual user environments.

                                      OpenClaw is attempting to turn that state into collaborative infrastructure. Already, some teams outside the developers of the open source project are adopting it.

                                      Colin Johnson, CEO of marketing metrics software firm Solvely, described a similar shift in his own development workflow in a post on X.

                                      His team had already been using OpenClaw agents through Discord, where developers could assign tasks, run commands and interact with their development environment. But he said that model still felt like “messaging a bot”: developers could share access to an agent without actually sharing the agent’s working context.

                                      The new multiplayer WebUI changed that, he wrote, because two developers could open the same live session, see the same history and artifacts, and add information without first exporting or reconstructing what the agent had already done. “We were working inside the same context,” Colin wrote.

                                      In one example, another developer was taking over a project he had been working on; instead of preparing a traditional handoff document, Colin joined the developer’s existing agent thread and added the missing project context directly. “The session itself became the handoff document,” he wrote.

                                      For enterprise teams, that is a useful illustration of why persistent multiplayer sessions may matter beyond convenience: agent context can become a shared work artifact rather than information trapped inside one employee’s private conversation.

                                      Colin’s deployment also illustrates both the enterprise potential and the remaining security boundary. His team runs its OpenClaw Gateway on a development server reachable through GitHub authentication, Cloudflare Access and a Cloudflare Tunnel, with the Gateway itself listening only on the server’s loopback interface rather than an exposed public port.

                                      But he explicitly cautioned that this does not make the shared Gateway a multitenant environment. The developers already trust one another with the repositories, tools and agent capabilities behind it. As he put it, Cloudflare controls who can enter the workspace, while OpenClaw tracks who created, owns or contributed to the work; stronger separation still requires separate infrastructure.

                                      Security becomes much more enterprise-oriented

                                      That shift creates a corresponding security problem: a shared agent can potentially act with broader organizational authority than one running on a developer laptop.

                                      OpenClaw 2.0 responds with considerably more granular controls.

                                      Approvals can now be tied to a specific request, command, session and person. Command permissions can be constrained to specific arguments and working directories. For script-backed execution, OpenClaw can verify that the script being executed still matches what was originally reviewed.

                                      Sessions can operate under different permission levels, including read-only, guarded, workspace and full-access modes, with the highest level restricted to administrators.

                                      Organizations can also define operator roles that require sandboxed execution for sessions created by specific identities. OpenClaw says those requirements cannot be bypassed using elevated execution or host overrides; if the required sandbox cannot be provisioned, execution fails rather than silently falling back to the host.

                                      Credentials receive additional protection.

                                      OpenClaw’s team-scoped Secret Store distinguishes protected secrets from ordinary environment data available to the agent. For supported requests, a protected credential can be substituted into a Gateway-hosted HTTPS request without exposing that credential directly to the model.

                                      OpenClaw can also reference external systems including 1Password and Vault.

                                      Auditing has expanded around execution identity, approvals, session actions and outbound messages. Plugin installation can trigger capability reviews associated with the specific artifact being installed.

                                      Those controls address questions enterprises inevitably face when deploying agents: Who initiated an action? Which agent performed it? What resources could it access? Who approved the operation? And what happens to those permissions when work moves between people or machines?

                                      NanoClaw still takes a different approach to security

                                      OpenClaw’s changes also make the comparison with open source, enterprise-friendly rival NanoClaw more nuanced.

                                      NanoClaw is one of several subsequent projects to emerge around the idea that AI agents need stronger isolation and simpler security boundaries. Its architecture places operating-system-level containment at the center of the design.

                                      NanoClaw runs agents inside Docker containers, limits those containers to explicitly mounted filesystems and runs their processes as an unprivileged user. Sessions and agent groups can remain isolated rather than automatically sharing files and conversation history.

                                      Its credential architecture follows the same principle. Supported outbound requests can pass through OneCLI’s Agent Vault, allowing credentials to be injected by a gateway rather than placed inside the agent container itself. NanoClaw also provides an optional egress-lockdown mode that puts agents on an internal Docker network and routes supported external traffic through the gateway.

                                      OpenClaw 2.0 can now reproduce many elements of that hardened model. It supports Docker and Podman sandboxes, per-agent and per-session sandbox scopes, configurable read-only or read-write workspace access, role-enforced sandboxing, remote execution nodes and disposable cloud workers.

                                      The key difference is the starting posture. OpenClaw’s documentation explicitly says sandboxing and execution approvals are off by default. Its baseline configuration assumes a trusted single operator and permits host execution unless administrators configure stronger restrictions. NanoClaw makes isolation more fundamental to how agent execution is structured.

                                      So does OpenClaw 2.0 have security parity with NanoClaw?

                                      In terms of available controls, it is much closer than before. In terms of defaults and architectural philosophy, no. An enterprise can configure OpenClaw into a substantially hardened environment, but it has to make that decision deliberately.

                                      One Gateway is still one trust domain

                                      Another limitation is particularly important for larger organizations. OpenClaw says a Gateway should be treated as a single trust domain.

                                      Its new multi-user permissions are designed to govern collaboration among trusted users. They should not be treated as hard isolation between mutually untrusted tenants.

                                      For organizations requiring stronger separation — between business units, customers or other security domains, for example — OpenClaw recommends separate Gateway instances, described as “cells,” with separate state, credentials and workspaces.

                                      Fleet tooling for managing those cells remains experimental.

                                      That distinction could matter significantly for enterprises considering OpenClaw as a centrally operated service.

                                      Role-based access inside one Gateway may be sufficient for a trusted engineering department or internal team. It is a different proposition from a multi-tenant platform intended to isolate customers or users who should be assumed hostile to one another.

                                      NanoClaw has its own configuration requirements and limitations, and even its stronger outbound-network lockdown remains optional. But its smaller architecture and container-centric execution model may appeal to organizations that want a narrower security boundary that is easier to reason about.

                                      OpenClaw is optimizing for a broader problem.

                                      OpenClaw’s biggest advantage may be the control plane

                                      The tradeoff is product breadth.

                                      NanoClaw emphasizes a relatively small codebase, container isolation and customization through code and skills. Its second-generation architecture supports owner, administrator and member roles, and a separate monitoring dashboard can provide visibility into deployments.

                                      OpenClaw 2.0 is trying to build a much broader operational environment.

                                      Its Control UI combines employee interaction, live execution, files, approvals, terminals, code review, model-provider configuration, devices and shared sessions.

                                      That gives OpenClaw a potential advantage for enterprises that need not only secure agent execution but a usable control plane around it.

                                      Security teams care about isolation. Platform teams also need deployment, authentication, model configuration, auditing and policy enforcement. Employees need an interface they can actually use. Managers need a way to understand what is running. Developers need access to the underlying files and tools when something goes wrong.

                                      OpenClaw 2.0 increasingly tries to serve all of those constituencies through one system.

                                      What is OpenAI’s role?

                                      OpenClaw says 933 contributors, including 569 first-time contributors, participated in the release, which includes more than 16,000 pull requests — roughly half of all pull requests ever merged into the project.

                                      Interestingly, the release was not shared by Steinberger’s employer, OpenAI. Recall that the Austrian developer announced on Feb. 14, 2026 that he was joining OpenAI to work on bringing agents to a broader audience, a move OpenAI CEO Sam Altman publicly confirmed the following day.

                                      But OpenClaw was not folded into OpenAI. Steinberger said at the time that OpenClaw would move to a foundation and “stay open and independent,” while OpenAI would support the project. OpenClaw now says it is stewarded by the OpenClaw Foundation, an independent 501(c)(3), with OpenAI listed alongside Microsoft, GitHub, NVIDIA, Atlassian, Tencent and other organizations as partners.

                                      Based on the available public information, OpenClaw 2.0 should therefore be understood as an OpenClaw Foundation release, not an OpenAI product or OpenAI software release, despite Steinberger’s employment at OpenAI and OpenAI’s financial and organizational support for the project.

                                      Enterprise readiness now depends on configuration

                                      OpenClaw 2.0 does not eliminate the security risks associated with autonomous agents, and its own documentation identifies limitations.

                                      Secret Store values, for example, are not themselves encrypted at rest and rely on filesystem protections. Protected credential substitution does not cover every possible execution path, including some raw sockets, containers, remote nodes and provider-native harnessesIts multi-user permissions are collaboration controls, not hostile-tenant isolation.

                                      Those caveats should prevent enterprises from interpreting OpenClaw 2.0 as secure-by-default agent infrastructure.But they also illustrate how much the conversation around the project has changed. The relevant comparison is increasingly not simply OpenClaw versus NanoClaw. It is a container-first, constrained system such as NanoClaw versus a deliberately hardened OpenClaw deployment that provides a substantially broader employee and administrator experience.

                                      NanoClaw retains a strong proposition for organizations prioritizing a small attack surface, container-first execution and architectural simplicity.

                                      OpenClaw is making another bet: that enterprises ultimately need an agent platform to function as both runtime and workplace.

                                      OpenClaw 2.0 provides many of the primitives needed to build that environment — sandboxing, permissions, protected credentials, approvals, identity, auditing and isolated deployments — alongside a browser interface designed to make the system accessible to employees who will never configure an agent from a terminal.

                                      The remaining caveat is important: enterprises have to turn those primitives into policy. OpenClaw 2.0 doesn’t automatically make OpenClaw enterprise-ready, but it does make an enterprise-grade OpenClaw deployment far easier out-of-the-box.

                                      And as Steinberger’s description of OpenClaw’s own development process suggests, the long-term ambition may be larger still. Rather than giving every employee another AI assistant, OpenClaw is positioning the agent itself as shared infrastructure — a persistent layer where people, models and compute collaborate on the same work.

                                      ¡No te pierdas las noticias destacadas!

                                      Suscríbete y recibe las historias más importantes del día.

                                      Al suscribirte aceptas nuestros términos y condiciones y política de privacidad.

                                      The viral fervor we saw earlier this year around OpenClaw, the open source AI harness that turns powerful language models into autonomous workers the user can message via their favorite channels (Telegram, iMessage, WhatsApp, Discord etc), has cooled off substantially from its peak in March 2026.

                                      But over the weekend, OpenClaw’s creator Peter Steinberger and current team of co-developers gave the world — especially enterprises — a reason to look at it again, announcing OpenClaw 2.0, billed as the most significant update to the harness and surrounding platform yet.

                                      OpenClaw 2.0 seeks to transform what began largely as a personal agent harness into something increasingly designed for teams, shared infrastructure and enterprise workflows.

                                      OpenClaw 2.0 introduces a rebuilt browser interface that brings conversations, files, approvals, configuration and live agent activity into a common workspace. It adds shared cloud sessions and multi-user collaboration. And it expands the security model with stronger sandboxing, role-based permissions, approval controls, secrets handling and auditing.

                                      Together, those additions move OpenClaw closer to being infrastructure that an organization could deploy for employees rather than simply a powerful agent an individual developer runs locally.

                                      They also sharpen a competitive question surrounding the project: whether OpenClaw has addressed the security and isolation concerns that helped inspire newer alternatives such as NanoClaw.

                                      The answer is increasingly yes at the capability level — but not necessarily by default.

                                      OpenClaw wants to become the shared agent layer

                                      Released under the official name of v2026.8.1, the update spans installation, messaging, memory, skills, models, automations, browser and native applications, plugins and security.

                                      Steinberger described the development of OpenClaw 2.0 as an exercise in using the product to build itself.

                                      “Two months ago, we started the mission to ‘build OpenClaw with OpenClaw,’” Steinberger wrote on X early on August 31.

                                      Over that period, he said, OpenClaw gradually moved its team away from individual local coding harnesses and toward team.openclaw.ai, a shared agent environment aware of what team members are working on.

                                      “Multiplayer coding + infinite compute with nodes and cloud sessions has been a game changer for how we build,” Steinberger wrote, adding that local harnesses now “feel like relics of the past.”

                                      That claim points toward one of the more important changes in OpenClaw’s enterprise proposition.

                                      The dominant model for AI coding agents has generally been individual: a developer runs an agent in a terminal, IDE or desktop application, gives it access to a repository and lets it execute work within that environment.

                                      OpenClaw 2.0 is pushing toward something different. Agent sessions can become persistent workspaces that outlive a single terminal or employee. They can be shared with colleagues, executed across other machines or cloud workers, and supervised through a browser.

                                      For enterprises, that potentially turns the agent from an employee-level productivity application into a shared operational layer.

                                      A new UI could broaden OpenClaw beyond developers

                                      New OpenClaw UI promotional screenshot. Credit: OpenClaw

                                      The redesigned Control UI is central to that strategy.

                                      OpenClaw has shifted away from an Overview-first web application and made conversations the primary interface. Threads sit in a sidebar, while the active conversation occupies the main workspace. Files, approvals, settings and ongoing agent activity remain accessible around it.

                                      The design deliberately brings OpenClaw closer to the interaction model employees already know from OpenAI’s ChatGPT, Anthropic’s Claude, Google’s Gemini and other conversational AI products.

                                      That lowers an important barrier to enterprise adoption. Open-source agent frameworks are often powerful precisely because they expose low-level configuration, terminals, tools and runtime controls. Those same characteristics can make them difficult to deploy beyond engineering organizations.

                                      OpenClaw 2.0 attempts to preserve the underlying control while putting a conversational interface on top of it. An employee can ask an agent to perform work without treating the terminal as the primary product interface. But OpenClaw does not hide what is happening underneath. The Control UI can surface session files, terminal activity, Git-backed changes, pull-request state, browser activity and interactive dashboards.

                                      The release also places more emphasis on observability during agent execution. Tool calls and results are paired more clearly, file changes can appear as focused diffs, command activity is easier to inspect, and long-running background tasks can remain visible alongside the conversation. That combination matters for enterprise use.

                                      Employees get a simpler interface for delegating work. Technical users retain access to the artifacts and execution state behind the conversation. Administrators gain a centralized place to configure and supervise the system.

                                      The redesigned Settings workspace now encompasses agents, memory, plugins, MCP servers, devices, communication channels and device pairing. OpenClaw also consolidates model-provider administration, including credential status and, where providers expose it, model availability, quota, account balance, budget and spending information.

                                      Limited-access browser users can request administrator privileges rather than automatically receiving them, with another administrator required to approve the escalation.

                                      These are not especially flashy agent features. For companies deploying AI systems to dozens or hundreds of employees, they may be among the most important additions in the release.

                                      Multiplayer sessions turn agent context into shared context

                                      OpenClaw 2.0 also expands the agent from a personal workspace into a collaborative one.

                                      Shared cloud sessions allow another employee to enter work already in progress without discarding the context accumulated by the agent.

                                      Multi-user Gateways — the service that connects users and agents to tools, files, credentials and other resources — can track who created a conversation and which prompts were submitted by identified participants.

                                      Owners and administrators can determine whether another user can read a session, suggest changes, work in draft mode or participate directly.

                                      The interface adds session ownership, participant attribution, presence and even typing indicators. For coding teams, that introduces a workflow closer to collaborative software development than traditional AI chat.

                                      A developer could initiate a task and allow an agent to work on it remotely. Another engineer could inspect the resulting changes. A senior engineer or administrator could approve an operation requiring additional privileges. The work does not have to remain attached to the laptop or terminal where it started.

                                      Sessions can also move execution to paired devices or cloud workers while maintaining the broader workspace.

                                      For enterprises experimenting with long-running agents, that is significant. Persistent agents need mechanisms for shift changes, escalation, supervision and ownership transfer. Otherwise, organizations simply create fleets of personal agents whose state disappears into individual user environments.

                                      OpenClaw is attempting to turn that state into collaborative infrastructure. Already, some teams outside the developers of the open source project are adopting it.

                                      Colin Johnson, CEO of marketing metrics software firm Solvely, described a similar shift in his own development workflow in a post on X.

                                      His team had already been using OpenClaw agents through Discord, where developers could assign tasks, run commands and interact with their development environment. But he said that model still felt like “messaging a bot”: developers could share access to an agent without actually sharing the agent’s working context.

                                      The new multiplayer WebUI changed that, he wrote, because two developers could open the same live session, see the same history and artifacts, and add information without first exporting or reconstructing what the agent had already done. “We were working inside the same context,” Colin wrote.

                                      In one example, another developer was taking over a project he had been working on; instead of preparing a traditional handoff document, Colin joined the developer’s existing agent thread and added the missing project context directly. “The session itself became the handoff document,” he wrote.

                                      For enterprise teams, that is a useful illustration of why persistent multiplayer sessions may matter beyond convenience: agent context can become a shared work artifact rather than information trapped inside one employee’s private conversation.

                                      Colin’s deployment also illustrates both the enterprise potential and the remaining security boundary. His team runs its OpenClaw Gateway on a development server reachable through GitHub authentication, Cloudflare Access and a Cloudflare Tunnel, with the Gateway itself listening only on the server’s loopback interface rather than an exposed public port.

                                      But he explicitly cautioned that this does not make the shared Gateway a multitenant environment. The developers already trust one another with the repositories, tools and agent capabilities behind it. As he put it, Cloudflare controls who can enter the workspace, while OpenClaw tracks who created, owns or contributed to the work; stronger separation still requires separate infrastructure.

                                      Security becomes much more enterprise-oriented

                                      That shift creates a corresponding security problem: a shared agent can potentially act with broader organizational authority than one running on a developer laptop.

                                      OpenClaw 2.0 responds with considerably more granular controls.

                                      Approvals can now be tied to a specific request, command, session and person. Command permissions can be constrained to specific arguments and working directories. For script-backed execution, OpenClaw can verify that the script being executed still matches what was originally reviewed.

                                      Sessions can operate under different permission levels, including read-only, guarded, workspace and full-access modes, with the highest level restricted to administrators.

                                      Organizations can also define operator roles that require sandboxed execution for sessions created by specific identities. OpenClaw says those requirements cannot be bypassed using elevated execution or host overrides; if the required sandbox cannot be provisioned, execution fails rather than silently falling back to the host.

                                      Credentials receive additional protection.

                                      OpenClaw’s team-scoped Secret Store distinguishes protected secrets from ordinary environment data available to the agent. For supported requests, a protected credential can be substituted into a Gateway-hosted HTTPS request without exposing that credential directly to the model.

                                      OpenClaw can also reference external systems including 1Password and Vault.

                                      Auditing has expanded around execution identity, approvals, session actions and outbound messages. Plugin installation can trigger capability reviews associated with the specific artifact being installed.

                                      Those controls address questions enterprises inevitably face when deploying agents: Who initiated an action? Which agent performed it? What resources could it access? Who approved the operation? And what happens to those permissions when work moves between people or machines?

                                      NanoClaw still takes a different approach to security

                                      OpenClaw’s changes also make the comparison with open source, enterprise-friendly rival NanoClaw more nuanced.

                                      NanoClaw is one of several subsequent projects to emerge around the idea that AI agents need stronger isolation and simpler security boundaries. Its architecture places operating-system-level containment at the center of the design.

                                      NanoClaw runs agents inside Docker containers, limits those containers to explicitly mounted filesystems and runs their processes as an unprivileged user. Sessions and agent groups can remain isolated rather than automatically sharing files and conversation history.

                                      Its credential architecture follows the same principle. Supported outbound requests can pass through OneCLI’s Agent Vault, allowing credentials to be injected by a gateway rather than placed inside the agent container itself. NanoClaw also provides an optional egress-lockdown mode that puts agents on an internal Docker network and routes supported external traffic through the gateway.

                                      OpenClaw 2.0 can now reproduce many elements of that hardened model. It supports Docker and Podman sandboxes, per-agent and per-session sandbox scopes, configurable read-only or read-write workspace access, role-enforced sandboxing, remote execution nodes and disposable cloud workers.

                                      The key difference is the starting posture. OpenClaw’s documentation explicitly says sandboxing and execution approvals are off by default. Its baseline configuration assumes a trusted single operator and permits host execution unless administrators configure stronger restrictions. NanoClaw makes isolation more fundamental to how agent execution is structured.

                                      So does OpenClaw 2.0 have security parity with NanoClaw?

                                      In terms of available controls, it is much closer than before. In terms of defaults and architectural philosophy, no. An enterprise can configure OpenClaw into a substantially hardened environment, but it has to make that decision deliberately.

                                      One Gateway is still one trust domain

                                      Another limitation is particularly important for larger organizations. OpenClaw says a Gateway should be treated as a single trust domain.

                                      Its new multi-user permissions are designed to govern collaboration among trusted users. They should not be treated as hard isolation between mutually untrusted tenants.

                                      For organizations requiring stronger separation — between business units, customers or other security domains, for example — OpenClaw recommends separate Gateway instances, described as “cells,” with separate state, credentials and workspaces.

                                      Fleet tooling for managing those cells remains experimental.

                                      That distinction could matter significantly for enterprises considering OpenClaw as a centrally operated service.

                                      Role-based access inside one Gateway may be sufficient for a trusted engineering department or internal team. It is a different proposition from a multi-tenant platform intended to isolate customers or users who should be assumed hostile to one another.

                                      NanoClaw has its own configuration requirements and limitations, and even its stronger outbound-network lockdown remains optional. But its smaller architecture and container-centric execution model may appeal to organizations that want a narrower security boundary that is easier to reason about.

                                      OpenClaw is optimizing for a broader problem.

                                      OpenClaw’s biggest advantage may be the control plane

                                      The tradeoff is product breadth.

                                      NanoClaw emphasizes a relatively small codebase, container isolation and customization through code and skills. Its second-generation architecture supports owner, administrator and member roles, and a separate monitoring dashboard can provide visibility into deployments.

                                      OpenClaw 2.0 is trying to build a much broader operational environment.

                                      Its Control UI combines employee interaction, live execution, files, approvals, terminals, code review, model-provider configuration, devices and shared sessions.

                                      That gives OpenClaw a potential advantage for enterprises that need not only secure agent execution but a usable control plane around it.

                                      Security teams care about isolation. Platform teams also need deployment, authentication, model configuration, auditing and policy enforcement. Employees need an interface they can actually use. Managers need a way to understand what is running. Developers need access to the underlying files and tools when something goes wrong.

                                      OpenClaw 2.0 increasingly tries to serve all of those constituencies through one system.

                                      What is OpenAI’s role?

                                      OpenClaw says 933 contributors, including 569 first-time contributors, participated in the release, which includes more than 16,000 pull requests — roughly half of all pull requests ever merged into the project.

                                      Interestingly, the release was not shared by Steinberger’s employer, OpenAI. Recall that the Austrian developer announced on Feb. 14, 2026 that he was joining OpenAI to work on bringing agents to a broader audience, a move OpenAI CEO Sam Altman publicly confirmed the following day.

                                      But OpenClaw was not folded into OpenAI. Steinberger said at the time that OpenClaw would move to a foundation and “stay open and independent,” while OpenAI would support the project. OpenClaw now says it is stewarded by the OpenClaw Foundation, an independent 501(c)(3), with OpenAI listed alongside Microsoft, GitHub, NVIDIA, Atlassian, Tencent and other organizations as partners.

                                      Based on the available public information, OpenClaw 2.0 should therefore be understood as an OpenClaw Foundation release, not an OpenAI product or OpenAI software release, despite Steinberger’s employment at OpenAI and OpenAI’s financial and organizational support for the project.

                                      Enterprise readiness now depends on configuration

                                      OpenClaw 2.0 does not eliminate the security risks associated with autonomous agents, and its own documentation identifies limitations.

                                      Secret Store values, for example, are not themselves encrypted at rest and rely on filesystem protections. Protected credential substitution does not cover every possible execution path, including some raw sockets, containers, remote nodes and provider-native harnessesIts multi-user permissions are collaboration controls, not hostile-tenant isolation.

                                      Those caveats should prevent enterprises from interpreting OpenClaw 2.0 as secure-by-default agent infrastructure.But they also illustrate how much the conversation around the project has changed. The relevant comparison is increasingly not simply OpenClaw versus NanoClaw. It is a container-first, constrained system such as NanoClaw versus a deliberately hardened OpenClaw deployment that provides a substantially broader employee and administrator experience.

                                      NanoClaw retains a strong proposition for organizations prioritizing a small attack surface, container-first execution and architectural simplicity.

                                      OpenClaw is making another bet: that enterprises ultimately need an agent platform to function as both runtime and workplace.

                                      OpenClaw 2.0 provides many of the primitives needed to build that environment — sandboxing, permissions, protected credentials, approvals, identity, auditing and isolated deployments — alongside a browser interface designed to make the system accessible to employees who will never configure an agent from a terminal.

                                      The remaining caveat is important: enterprises have to turn those primitives into policy. OpenClaw 2.0 doesn’t automatically make OpenClaw enterprise-ready, but it does make an enterprise-grade OpenClaw deployment far easier out-of-the-box.

                                      And as Steinberger’s description of OpenClaw’s own development process suggests, the long-term ambition may be larger still. Rather than giving every employee another AI assistant, OpenClaw is positioning the agent itself as shared infrastructure — a persistent layer where people, models and compute collaborate on the same work.

                                      Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado

                                      The viral fervor we saw earlier this year around OpenClaw, the open source AI harness that turns powerful language models into autonomous workers the user can message via their favorite channels (Telegram, iMessage, WhatsApp, Discord etc), has cooled off substantially from its peak in March 2026.

                                      But over the weekend, OpenClaw’s creator Peter Steinberger and current team of co-developers gave the world — especially enterprises — a reason to look at it again, announcing OpenClaw 2.0, billed as the most significant update to the harness and surrounding platform yet.

                                      OpenClaw 2.0 seeks to transform what began largely as a personal agent harness into something increasingly designed for teams, shared infrastructure and enterprise workflows.

                                      OpenClaw 2.0 introduces a rebuilt browser interface that brings conversations, files, approvals, configuration and live agent activity into a common workspace. It adds shared cloud sessions and multi-user collaboration. And it expands the security model with stronger sandboxing, role-based permissions, approval controls, secrets handling and auditing.

                                      Together, those additions move OpenClaw closer to being infrastructure that an organization could deploy for employees rather than simply a powerful agent an individual developer runs locally.

                                      They also sharpen a competitive question surrounding the project: whether OpenClaw has addressed the security and isolation concerns that helped inspire newer alternatives such as NanoClaw.

                                      The answer is increasingly yes at the capability level — but not necessarily by default.

                                      OpenClaw wants to become the shared agent layer

                                      Released under the official name of v2026.8.1, the update spans installation, messaging, memory, skills, models, automations, browser and native applications, plugins and security.

                                      Steinberger described the development of OpenClaw 2.0 as an exercise in using the product to build itself.

                                      “Two months ago, we started the mission to ‘build OpenClaw with OpenClaw,’” Steinberger wrote on X early on August 31.

                                      Over that period, he said, OpenClaw gradually moved its team away from individual local coding harnesses and toward team.openclaw.ai, a shared agent environment aware of what team members are working on.

                                      “Multiplayer coding + infinite compute with nodes and cloud sessions has been a game changer for how we build,” Steinberger wrote, adding that local harnesses now “feel like relics of the past.”

                                      That claim points toward one of the more important changes in OpenClaw’s enterprise proposition.

                                      The dominant model for AI coding agents has generally been individual: a developer runs an agent in a terminal, IDE or desktop application, gives it access to a repository and lets it execute work within that environment.

                                      OpenClaw 2.0 is pushing toward something different. Agent sessions can become persistent workspaces that outlive a single terminal or employee. They can be shared with colleagues, executed across other machines or cloud workers, and supervised through a browser.

                                      For enterprises, that potentially turns the agent from an employee-level productivity application into a shared operational layer.

                                      A new UI could broaden OpenClaw beyond developers

                                      New OpenClaw UI promotional screenshot. Credit: OpenClaw

                                      The redesigned Control UI is central to that strategy.

                                      OpenClaw has shifted away from an Overview-first web application and made conversations the primary interface. Threads sit in a sidebar, while the active conversation occupies the main workspace. Files, approvals, settings and ongoing agent activity remain accessible around it.

                                      The design deliberately brings OpenClaw closer to the interaction model employees already know from OpenAI’s ChatGPT, Anthropic’s Claude, Google’s Gemini and other conversational AI products.

                                      That lowers an important barrier to enterprise adoption. Open-source agent frameworks are often powerful precisely because they expose low-level configuration, terminals, tools and runtime controls. Those same characteristics can make them difficult to deploy beyond engineering organizations.

                                      OpenClaw 2.0 attempts to preserve the underlying control while putting a conversational interface on top of it. An employee can ask an agent to perform work without treating the terminal as the primary product interface. But OpenClaw does not hide what is happening underneath. The Control UI can surface session files, terminal activity, Git-backed changes, pull-request state, browser activity and interactive dashboards.

                                      The release also places more emphasis on observability during agent execution. Tool calls and results are paired more clearly, file changes can appear as focused diffs, command activity is easier to inspect, and long-running background tasks can remain visible alongside the conversation. That combination matters for enterprise use.

                                      Employees get a simpler interface for delegating work. Technical users retain access to the artifacts and execution state behind the conversation. Administrators gain a centralized place to configure and supervise the system.

                                      The redesigned Settings workspace now encompasses agents, memory, plugins, MCP servers, devices, communication channels and device pairing. OpenClaw also consolidates model-provider administration, including credential status and, where providers expose it, model availability, quota, account balance, budget and spending information.

                                      Limited-access browser users can request administrator privileges rather than automatically receiving them, with another administrator required to approve the escalation.

                                      These are not especially flashy agent features. For companies deploying AI systems to dozens or hundreds of employees, they may be among the most important additions in the release.

                                      Multiplayer sessions turn agent context into shared context

                                      OpenClaw 2.0 also expands the agent from a personal workspace into a collaborative one.

                                      Shared cloud sessions allow another employee to enter work already in progress without discarding the context accumulated by the agent.

                                      Multi-user Gateways — the service that connects users and agents to tools, files, credentials and other resources — can track who created a conversation and which prompts were submitted by identified participants.

                                      Owners and administrators can determine whether another user can read a session, suggest changes, work in draft mode or participate directly.

                                      The interface adds session ownership, participant attribution, presence and even typing indicators. For coding teams, that introduces a workflow closer to collaborative software development than traditional AI chat.

                                      A developer could initiate a task and allow an agent to work on it remotely. Another engineer could inspect the resulting changes. A senior engineer or administrator could approve an operation requiring additional privileges. The work does not have to remain attached to the laptop or terminal where it started.

                                      Sessions can also move execution to paired devices or cloud workers while maintaining the broader workspace.

                                      For enterprises experimenting with long-running agents, that is significant. Persistent agents need mechanisms for shift changes, escalation, supervision and ownership transfer. Otherwise, organizations simply create fleets of personal agents whose state disappears into individual user environments.

                                      OpenClaw is attempting to turn that state into collaborative infrastructure. Already, some teams outside the developers of the open source project are adopting it.

                                      Colin Johnson, CEO of marketing metrics software firm Solvely, described a similar shift in his own development workflow in a post on X.

                                      His team had already been using OpenClaw agents through Discord, where developers could assign tasks, run commands and interact with their development environment. But he said that model still felt like “messaging a bot”: developers could share access to an agent without actually sharing the agent’s working context.

                                      The new multiplayer WebUI changed that, he wrote, because two developers could open the same live session, see the same history and artifacts, and add information without first exporting or reconstructing what the agent had already done. “We were working inside the same context,” Colin wrote.

                                      In one example, another developer was taking over a project he had been working on; instead of preparing a traditional handoff document, Colin joined the developer’s existing agent thread and added the missing project context directly. “The session itself became the handoff document,” he wrote.

                                      For enterprise teams, that is a useful illustration of why persistent multiplayer sessions may matter beyond convenience: agent context can become a shared work artifact rather than information trapped inside one employee’s private conversation.

                                      Colin’s deployment also illustrates both the enterprise potential and the remaining security boundary. His team runs its OpenClaw Gateway on a development server reachable through GitHub authentication, Cloudflare Access and a Cloudflare Tunnel, with the Gateway itself listening only on the server’s loopback interface rather than an exposed public port.

                                      But he explicitly cautioned that this does not make the shared Gateway a multitenant environment. The developers already trust one another with the repositories, tools and agent capabilities behind it. As he put it, Cloudflare controls who can enter the workspace, while OpenClaw tracks who created, owns or contributed to the work; stronger separation still requires separate infrastructure.

                                      Security becomes much more enterprise-oriented

                                      That shift creates a corresponding security problem: a shared agent can potentially act with broader organizational authority than one running on a developer laptop.

                                      OpenClaw 2.0 responds with considerably more granular controls.

                                      Approvals can now be tied to a specific request, command, session and person. Command permissions can be constrained to specific arguments and working directories. For script-backed execution, OpenClaw can verify that the script being executed still matches what was originally reviewed.

                                      Sessions can operate under different permission levels, including read-only, guarded, workspace and full-access modes, with the highest level restricted to administrators.

                                      Organizations can also define operator roles that require sandboxed execution for sessions created by specific identities. OpenClaw says those requirements cannot be bypassed using elevated execution or host overrides; if the required sandbox cannot be provisioned, execution fails rather than silently falling back to the host.

                                      Credentials receive additional protection.

                                      OpenClaw’s team-scoped Secret Store distinguishes protected secrets from ordinary environment data available to the agent. For supported requests, a protected credential can be substituted into a Gateway-hosted HTTPS request without exposing that credential directly to the model.

                                      OpenClaw can also reference external systems including 1Password and Vault.

                                      Auditing has expanded around execution identity, approvals, session actions and outbound messages. Plugin installation can trigger capability reviews associated with the specific artifact being installed.

                                      Those controls address questions enterprises inevitably face when deploying agents: Who initiated an action? Which agent performed it? What resources could it access? Who approved the operation? And what happens to those permissions when work moves between people or machines?

                                      NanoClaw still takes a different approach to security

                                      OpenClaw’s changes also make the comparison with open source, enterprise-friendly rival NanoClaw more nuanced.

                                      NanoClaw is one of several subsequent projects to emerge around the idea that AI agents need stronger isolation and simpler security boundaries. Its architecture places operating-system-level containment at the center of the design.

                                      NanoClaw runs agents inside Docker containers, limits those containers to explicitly mounted filesystems and runs their processes as an unprivileged user. Sessions and agent groups can remain isolated rather than automatically sharing files and conversation history.

                                      Its credential architecture follows the same principle. Supported outbound requests can pass through OneCLI’s Agent Vault, allowing credentials to be injected by a gateway rather than placed inside the agent container itself. NanoClaw also provides an optional egress-lockdown mode that puts agents on an internal Docker network and routes supported external traffic through the gateway.

                                      OpenClaw 2.0 can now reproduce many elements of that hardened model. It supports Docker and Podman sandboxes, per-agent and per-session sandbox scopes, configurable read-only or read-write workspace access, role-enforced sandboxing, remote execution nodes and disposable cloud workers.

                                      The key difference is the starting posture. OpenClaw’s documentation explicitly says sandboxing and execution approvals are off by default. Its baseline configuration assumes a trusted single operator and permits host execution unless administrators configure stronger restrictions. NanoClaw makes isolation more fundamental to how agent execution is structured.

                                      So does OpenClaw 2.0 have security parity with NanoClaw?

                                      In terms of available controls, it is much closer than before. In terms of defaults and architectural philosophy, no. An enterprise can configure OpenClaw into a substantially hardened environment, but it has to make that decision deliberately.

                                      One Gateway is still one trust domain

                                      Another limitation is particularly important for larger organizations. OpenClaw says a Gateway should be treated as a single trust domain.

                                      Its new multi-user permissions are designed to govern collaboration among trusted users. They should not be treated as hard isolation between mutually untrusted tenants.

                                      For organizations requiring stronger separation — between business units, customers or other security domains, for example — OpenClaw recommends separate Gateway instances, described as “cells,” with separate state, credentials and workspaces.

                                      Fleet tooling for managing those cells remains experimental.

                                      That distinction could matter significantly for enterprises considering OpenClaw as a centrally operated service.

                                      Role-based access inside one Gateway may be sufficient for a trusted engineering department or internal team. It is a different proposition from a multi-tenant platform intended to isolate customers or users who should be assumed hostile to one another.

                                      NanoClaw has its own configuration requirements and limitations, and even its stronger outbound-network lockdown remains optional. But its smaller architecture and container-centric execution model may appeal to organizations that want a narrower security boundary that is easier to reason about.

                                      OpenClaw is optimizing for a broader problem.

                                      OpenClaw’s biggest advantage may be the control plane

                                      The tradeoff is product breadth.

                                      NanoClaw emphasizes a relatively small codebase, container isolation and customization through code and skills. Its second-generation architecture supports owner, administrator and member roles, and a separate monitoring dashboard can provide visibility into deployments.

                                      OpenClaw 2.0 is trying to build a much broader operational environment.

                                      Its Control UI combines employee interaction, live execution, files, approvals, terminals, code review, model-provider configuration, devices and shared sessions.

                                      That gives OpenClaw a potential advantage for enterprises that need not only secure agent execution but a usable control plane around it.

                                      Security teams care about isolation. Platform teams also need deployment, authentication, model configuration, auditing and policy enforcement. Employees need an interface they can actually use. Managers need a way to understand what is running. Developers need access to the underlying files and tools when something goes wrong.

                                      OpenClaw 2.0 increasingly tries to serve all of those constituencies through one system.

                                      What is OpenAI’s role?

                                      OpenClaw says 933 contributors, including 569 first-time contributors, participated in the release, which includes more than 16,000 pull requests — roughly half of all pull requests ever merged into the project.

                                      Interestingly, the release was not shared by Steinberger’s employer, OpenAI. Recall that the Austrian developer announced on Feb. 14, 2026 that he was joining OpenAI to work on bringing agents to a broader audience, a move OpenAI CEO Sam Altman publicly confirmed the following day.

                                      But OpenClaw was not folded into OpenAI. Steinberger said at the time that OpenClaw would move to a foundation and “stay open and independent,” while OpenAI would support the project. OpenClaw now says it is stewarded by the OpenClaw Foundation, an independent 501(c)(3), with OpenAI listed alongside Microsoft, GitHub, NVIDIA, Atlassian, Tencent and other organizations as partners.

                                      Based on the available public information, OpenClaw 2.0 should therefore be understood as an OpenClaw Foundation release, not an OpenAI product or OpenAI software release, despite Steinberger’s employment at OpenAI and OpenAI’s financial and organizational support for the project.

                                      Enterprise readiness now depends on configuration

                                      OpenClaw 2.0 does not eliminate the security risks associated with autonomous agents, and its own documentation identifies limitations.

                                      Secret Store values, for example, are not themselves encrypted at rest and rely on filesystem protections. Protected credential substitution does not cover every possible execution path, including some raw sockets, containers, remote nodes and provider-native harnessesIts multi-user permissions are collaboration controls, not hostile-tenant isolation.

                                      Those caveats should prevent enterprises from interpreting OpenClaw 2.0 as secure-by-default agent infrastructure.But they also illustrate how much the conversation around the project has changed. The relevant comparison is increasingly not simply OpenClaw versus NanoClaw. It is a container-first, constrained system such as NanoClaw versus a deliberately hardened OpenClaw deployment that provides a substantially broader employee and administrator experience.

                                      NanoClaw retains a strong proposition for organizations prioritizing a small attack surface, container-first execution and architectural simplicity.

                                      OpenClaw is making another bet: that enterprises ultimately need an agent platform to function as both runtime and workplace.

                                      OpenClaw 2.0 provides many of the primitives needed to build that environment — sandboxing, permissions, protected credentials, approvals, identity, auditing and isolated deployments — alongside a browser interface designed to make the system accessible to employees who will never configure an agent from a terminal.

                                      The remaining caveat is important: enterprises have to turn those primitives into policy. OpenClaw 2.0 doesn’t automatically make OpenClaw enterprise-ready, but it does make an enterprise-grade OpenClaw deployment far easier out-of-the-box.

                                      And as Steinberger’s description of OpenClaw’s own development process suggests, the long-term ambition may be larger still. Rather than giving every employee another AI assistant, OpenClaw is positioning the agent itself as shared infrastructure — a persistent layer where people, models and compute collaborate on the same work.

                                      Tours Colombia Todo el año Tours Colombia Todo el año Tours Colombia Todo el año

                                      The viral fervor we saw earlier this year around OpenClaw, the open source AI harness that turns powerful language models into autonomous workers the user can message via their favorite channels (Telegram, iMessage, WhatsApp, Discord etc), has cooled off substantially from its peak in March 2026.

                                      But over the weekend, OpenClaw’s creator Peter Steinberger and current team of co-developers gave the world — especially enterprises — a reason to look at it again, announcing OpenClaw 2.0, billed as the most significant update to the harness and surrounding platform yet.

                                      OpenClaw 2.0 seeks to transform what began largely as a personal agent harness into something increasingly designed for teams, shared infrastructure and enterprise workflows.

                                      OpenClaw 2.0 introduces a rebuilt browser interface that brings conversations, files, approvals, configuration and live agent activity into a common workspace. It adds shared cloud sessions and multi-user collaboration. And it expands the security model with stronger sandboxing, role-based permissions, approval controls, secrets handling and auditing.

                                      Together, those additions move OpenClaw closer to being infrastructure that an organization could deploy for employees rather than simply a powerful agent an individual developer runs locally.

                                      They also sharpen a competitive question surrounding the project: whether OpenClaw has addressed the security and isolation concerns that helped inspire newer alternatives such as NanoClaw.

                                      The answer is increasingly yes at the capability level — but not necessarily by default.

                                      OpenClaw wants to become the shared agent layer

                                      Released under the official name of v2026.8.1, the update spans installation, messaging, memory, skills, models, automations, browser and native applications, plugins and security.

                                      Steinberger described the development of OpenClaw 2.0 as an exercise in using the product to build itself.

                                      “Two months ago, we started the mission to ‘build OpenClaw with OpenClaw,’” Steinberger wrote on X early on August 31.

                                      Over that period, he said, OpenClaw gradually moved its team away from individual local coding harnesses and toward team.openclaw.ai, a shared agent environment aware of what team members are working on.

                                      “Multiplayer coding + infinite compute with nodes and cloud sessions has been a game changer for how we build,” Steinberger wrote, adding that local harnesses now “feel like relics of the past.”

                                      That claim points toward one of the more important changes in OpenClaw’s enterprise proposition.

                                      The dominant model for AI coding agents has generally been individual: a developer runs an agent in a terminal, IDE or desktop application, gives it access to a repository and lets it execute work within that environment.

                                      OpenClaw 2.0 is pushing toward something different. Agent sessions can become persistent workspaces that outlive a single terminal or employee. They can be shared with colleagues, executed across other machines or cloud workers, and supervised through a browser.

                                      For enterprises, that potentially turns the agent from an employee-level productivity application into a shared operational layer.

                                      A new UI could broaden OpenClaw beyond developers

                                      New OpenClaw UI promotional screenshot. Credit: OpenClaw

                                      The redesigned Control UI is central to that strategy.

                                      OpenClaw has shifted away from an Overview-first web application and made conversations the primary interface. Threads sit in a sidebar, while the active conversation occupies the main workspace. Files, approvals, settings and ongoing agent activity remain accessible around it.

                                      The design deliberately brings OpenClaw closer to the interaction model employees already know from OpenAI’s ChatGPT, Anthropic’s Claude, Google’s Gemini and other conversational AI products.

                                      That lowers an important barrier to enterprise adoption. Open-source agent frameworks are often powerful precisely because they expose low-level configuration, terminals, tools and runtime controls. Those same characteristics can make them difficult to deploy beyond engineering organizations.

                                      OpenClaw 2.0 attempts to preserve the underlying control while putting a conversational interface on top of it. An employee can ask an agent to perform work without treating the terminal as the primary product interface. But OpenClaw does not hide what is happening underneath. The Control UI can surface session files, terminal activity, Git-backed changes, pull-request state, browser activity and interactive dashboards.

                                      The release also places more emphasis on observability during agent execution. Tool calls and results are paired more clearly, file changes can appear as focused diffs, command activity is easier to inspect, and long-running background tasks can remain visible alongside the conversation. That combination matters for enterprise use.

                                      Employees get a simpler interface for delegating work. Technical users retain access to the artifacts and execution state behind the conversation. Administrators gain a centralized place to configure and supervise the system.

                                      The redesigned Settings workspace now encompasses agents, memory, plugins, MCP servers, devices, communication channels and device pairing. OpenClaw also consolidates model-provider administration, including credential status and, where providers expose it, model availability, quota, account balance, budget and spending information.

                                      Limited-access browser users can request administrator privileges rather than automatically receiving them, with another administrator required to approve the escalation.

                                      These are not especially flashy agent features. For companies deploying AI systems to dozens or hundreds of employees, they may be among the most important additions in the release.

                                      Multiplayer sessions turn agent context into shared context

                                      OpenClaw 2.0 also expands the agent from a personal workspace into a collaborative one.

                                      Shared cloud sessions allow another employee to enter work already in progress without discarding the context accumulated by the agent.

                                      Multi-user Gateways — the service that connects users and agents to tools, files, credentials and other resources — can track who created a conversation and which prompts were submitted by identified participants.

                                      Owners and administrators can determine whether another user can read a session, suggest changes, work in draft mode or participate directly.

                                      The interface adds session ownership, participant attribution, presence and even typing indicators. For coding teams, that introduces a workflow closer to collaborative software development than traditional AI chat.

                                      A developer could initiate a task and allow an agent to work on it remotely. Another engineer could inspect the resulting changes. A senior engineer or administrator could approve an operation requiring additional privileges. The work does not have to remain attached to the laptop or terminal where it started.

                                      Sessions can also move execution to paired devices or cloud workers while maintaining the broader workspace.

                                      For enterprises experimenting with long-running agents, that is significant. Persistent agents need mechanisms for shift changes, escalation, supervision and ownership transfer. Otherwise, organizations simply create fleets of personal agents whose state disappears into individual user environments.

                                      OpenClaw is attempting to turn that state into collaborative infrastructure. Already, some teams outside the developers of the open source project are adopting it.

                                      Colin Johnson, CEO of marketing metrics software firm Solvely, described a similar shift in his own development workflow in a post on X.

                                      His team had already been using OpenClaw agents through Discord, where developers could assign tasks, run commands and interact with their development environment. But he said that model still felt like “messaging a bot”: developers could share access to an agent without actually sharing the agent’s working context.

                                      The new multiplayer WebUI changed that, he wrote, because two developers could open the same live session, see the same history and artifacts, and add information without first exporting or reconstructing what the agent had already done. “We were working inside the same context,” Colin wrote.

                                      In one example, another developer was taking over a project he had been working on; instead of preparing a traditional handoff document, Colin joined the developer’s existing agent thread and added the missing project context directly. “The session itself became the handoff document,” he wrote.

                                      For enterprise teams, that is a useful illustration of why persistent multiplayer sessions may matter beyond convenience: agent context can become a shared work artifact rather than information trapped inside one employee’s private conversation.

                                      Colin’s deployment also illustrates both the enterprise potential and the remaining security boundary. His team runs its OpenClaw Gateway on a development server reachable through GitHub authentication, Cloudflare Access and a Cloudflare Tunnel, with the Gateway itself listening only on the server’s loopback interface rather than an exposed public port.

                                      But he explicitly cautioned that this does not make the shared Gateway a multitenant environment. The developers already trust one another with the repositories, tools and agent capabilities behind it. As he put it, Cloudflare controls who can enter the workspace, while OpenClaw tracks who created, owns or contributed to the work; stronger separation still requires separate infrastructure.

                                      Security becomes much more enterprise-oriented

                                      That shift creates a corresponding security problem: a shared agent can potentially act with broader organizational authority than one running on a developer laptop.

                                      OpenClaw 2.0 responds with considerably more granular controls.

                                      Approvals can now be tied to a specific request, command, session and person. Command permissions can be constrained to specific arguments and working directories. For script-backed execution, OpenClaw can verify that the script being executed still matches what was originally reviewed.

                                      Sessions can operate under different permission levels, including read-only, guarded, workspace and full-access modes, with the highest level restricted to administrators.

                                      Organizations can also define operator roles that require sandboxed execution for sessions created by specific identities. OpenClaw says those requirements cannot be bypassed using elevated execution or host overrides; if the required sandbox cannot be provisioned, execution fails rather than silently falling back to the host.

                                      Credentials receive additional protection.

                                      OpenClaw’s team-scoped Secret Store distinguishes protected secrets from ordinary environment data available to the agent. For supported requests, a protected credential can be substituted into a Gateway-hosted HTTPS request without exposing that credential directly to the model.

                                      OpenClaw can also reference external systems including 1Password and Vault.

                                      Auditing has expanded around execution identity, approvals, session actions and outbound messages. Plugin installation can trigger capability reviews associated with the specific artifact being installed.

                                      Those controls address questions enterprises inevitably face when deploying agents: Who initiated an action? Which agent performed it? What resources could it access? Who approved the operation? And what happens to those permissions when work moves between people or machines?

                                      NanoClaw still takes a different approach to security

                                      OpenClaw’s changes also make the comparison with open source, enterprise-friendly rival NanoClaw more nuanced.

                                      NanoClaw is one of several subsequent projects to emerge around the idea that AI agents need stronger isolation and simpler security boundaries. Its architecture places operating-system-level containment at the center of the design.

                                      NanoClaw runs agents inside Docker containers, limits those containers to explicitly mounted filesystems and runs their processes as an unprivileged user. Sessions and agent groups can remain isolated rather than automatically sharing files and conversation history.

                                      Its credential architecture follows the same principle. Supported outbound requests can pass through OneCLI’s Agent Vault, allowing credentials to be injected by a gateway rather than placed inside the agent container itself. NanoClaw also provides an optional egress-lockdown mode that puts agents on an internal Docker network and routes supported external traffic through the gateway.

                                      OpenClaw 2.0 can now reproduce many elements of that hardened model. It supports Docker and Podman sandboxes, per-agent and per-session sandbox scopes, configurable read-only or read-write workspace access, role-enforced sandboxing, remote execution nodes and disposable cloud workers.

                                      The key difference is the starting posture. OpenClaw’s documentation explicitly says sandboxing and execution approvals are off by default. Its baseline configuration assumes a trusted single operator and permits host execution unless administrators configure stronger restrictions. NanoClaw makes isolation more fundamental to how agent execution is structured.

                                      So does OpenClaw 2.0 have security parity with NanoClaw?

                                      In terms of available controls, it is much closer than before. In terms of defaults and architectural philosophy, no. An enterprise can configure OpenClaw into a substantially hardened environment, but it has to make that decision deliberately.

                                      One Gateway is still one trust domain

                                      Another limitation is particularly important for larger organizations. OpenClaw says a Gateway should be treated as a single trust domain.

                                      Its new multi-user permissions are designed to govern collaboration among trusted users. They should not be treated as hard isolation between mutually untrusted tenants.

                                      For organizations requiring stronger separation — between business units, customers or other security domains, for example — OpenClaw recommends separate Gateway instances, described as “cells,” with separate state, credentials and workspaces.

                                      Fleet tooling for managing those cells remains experimental.

                                      That distinction could matter significantly for enterprises considering OpenClaw as a centrally operated service.

                                      Role-based access inside one Gateway may be sufficient for a trusted engineering department or internal team. It is a different proposition from a multi-tenant platform intended to isolate customers or users who should be assumed hostile to one another.

                                      NanoClaw has its own configuration requirements and limitations, and even its stronger outbound-network lockdown remains optional. But its smaller architecture and container-centric execution model may appeal to organizations that want a narrower security boundary that is easier to reason about.

                                      OpenClaw is optimizing for a broader problem.

                                      OpenClaw’s biggest advantage may be the control plane

                                      The tradeoff is product breadth.

                                      NanoClaw emphasizes a relatively small codebase, container isolation and customization through code and skills. Its second-generation architecture supports owner, administrator and member roles, and a separate monitoring dashboard can provide visibility into deployments.

                                      OpenClaw 2.0 is trying to build a much broader operational environment.

                                      Its Control UI combines employee interaction, live execution, files, approvals, terminals, code review, model-provider configuration, devices and shared sessions.

                                      That gives OpenClaw a potential advantage for enterprises that need not only secure agent execution but a usable control plane around it.

                                      Security teams care about isolation. Platform teams also need deployment, authentication, model configuration, auditing and policy enforcement. Employees need an interface they can actually use. Managers need a way to understand what is running. Developers need access to the underlying files and tools when something goes wrong.

                                      OpenClaw 2.0 increasingly tries to serve all of those constituencies through one system.

                                      What is OpenAI’s role?

                                      OpenClaw says 933 contributors, including 569 first-time contributors, participated in the release, which includes more than 16,000 pull requests — roughly half of all pull requests ever merged into the project.

                                      Interestingly, the release was not shared by Steinberger’s employer, OpenAI. Recall that the Austrian developer announced on Feb. 14, 2026 that he was joining OpenAI to work on bringing agents to a broader audience, a move OpenAI CEO Sam Altman publicly confirmed the following day.

                                      But OpenClaw was not folded into OpenAI. Steinberger said at the time that OpenClaw would move to a foundation and “stay open and independent,” while OpenAI would support the project. OpenClaw now says it is stewarded by the OpenClaw Foundation, an independent 501(c)(3), with OpenAI listed alongside Microsoft, GitHub, NVIDIA, Atlassian, Tencent and other organizations as partners.

                                      Based on the available public information, OpenClaw 2.0 should therefore be understood as an OpenClaw Foundation release, not an OpenAI product or OpenAI software release, despite Steinberger’s employment at OpenAI and OpenAI’s financial and organizational support for the project.

                                      Enterprise readiness now depends on configuration

                                      OpenClaw 2.0 does not eliminate the security risks associated with autonomous agents, and its own documentation identifies limitations.

                                      Secret Store values, for example, are not themselves encrypted at rest and rely on filesystem protections. Protected credential substitution does not cover every possible execution path, including some raw sockets, containers, remote nodes and provider-native harnessesIts multi-user permissions are collaboration controls, not hostile-tenant isolation.

                                      Those caveats should prevent enterprises from interpreting OpenClaw 2.0 as secure-by-default agent infrastructure.But they also illustrate how much the conversation around the project has changed. The relevant comparison is increasingly not simply OpenClaw versus NanoClaw. It is a container-first, constrained system such as NanoClaw versus a deliberately hardened OpenClaw deployment that provides a substantially broader employee and administrator experience.

                                      NanoClaw retains a strong proposition for organizations prioritizing a small attack surface, container-first execution and architectural simplicity.

                                      OpenClaw is making another bet: that enterprises ultimately need an agent platform to function as both runtime and workplace.

                                      OpenClaw 2.0 provides many of the primitives needed to build that environment — sandboxing, permissions, protected credentials, approvals, identity, auditing and isolated deployments — alongside a browser interface designed to make the system accessible to employees who will never configure an agent from a terminal.

                                      The remaining caveat is important: enterprises have to turn those primitives into policy. OpenClaw 2.0 doesn’t automatically make OpenClaw enterprise-ready, but it does make an enterprise-grade OpenClaw deployment far easier out-of-the-box.

                                      And as Steinberger’s description of OpenClaw’s own development process suggests, the long-term ambition may be larger still. Rather than giving every employee another AI assistant, OpenClaw is positioning the agent itself as shared infrastructure — a persistent layer where people, models and compute collaborate on the same work.

                                      Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado

                                      The viral fervor we saw earlier this year around OpenClaw, the open source AI harness that turns powerful language models into autonomous workers the user can message via their favorite channels (Telegram, iMessage, WhatsApp, Discord etc), has cooled off substantially from its peak in March 2026.

                                      But over the weekend, OpenClaw’s creator Peter Steinberger and current team of co-developers gave the world — especially enterprises — a reason to look at it again, announcing OpenClaw 2.0, billed as the most significant update to the harness and surrounding platform yet.

                                      OpenClaw 2.0 seeks to transform what began largely as a personal agent harness into something increasingly designed for teams, shared infrastructure and enterprise workflows.

                                      OpenClaw 2.0 introduces a rebuilt browser interface that brings conversations, files, approvals, configuration and live agent activity into a common workspace. It adds shared cloud sessions and multi-user collaboration. And it expands the security model with stronger sandboxing, role-based permissions, approval controls, secrets handling and auditing.

                                      Together, those additions move OpenClaw closer to being infrastructure that an organization could deploy for employees rather than simply a powerful agent an individual developer runs locally.

                                      They also sharpen a competitive question surrounding the project: whether OpenClaw has addressed the security and isolation concerns that helped inspire newer alternatives such as NanoClaw.

                                      The answer is increasingly yes at the capability level — but not necessarily by default.

                                      OpenClaw wants to become the shared agent layer

                                      Released under the official name of v2026.8.1, the update spans installation, messaging, memory, skills, models, automations, browser and native applications, plugins and security.

                                      Steinberger described the development of OpenClaw 2.0 as an exercise in using the product to build itself.

                                      “Two months ago, we started the mission to ‘build OpenClaw with OpenClaw,’” Steinberger wrote on X early on August 31.

                                      Over that period, he said, OpenClaw gradually moved its team away from individual local coding harnesses and toward team.openclaw.ai, a shared agent environment aware of what team members are working on.

                                      “Multiplayer coding + infinite compute with nodes and cloud sessions has been a game changer for how we build,” Steinberger wrote, adding that local harnesses now “feel like relics of the past.”

                                      That claim points toward one of the more important changes in OpenClaw’s enterprise proposition.

                                      The dominant model for AI coding agents has generally been individual: a developer runs an agent in a terminal, IDE or desktop application, gives it access to a repository and lets it execute work within that environment.

                                      OpenClaw 2.0 is pushing toward something different. Agent sessions can become persistent workspaces that outlive a single terminal or employee. They can be shared with colleagues, executed across other machines or cloud workers, and supervised through a browser.

                                      For enterprises, that potentially turns the agent from an employee-level productivity application into a shared operational layer.

                                      A new UI could broaden OpenClaw beyond developers

                                      New OpenClaw UI promotional screenshot. Credit: OpenClaw

                                      The redesigned Control UI is central to that strategy.

                                      OpenClaw has shifted away from an Overview-first web application and made conversations the primary interface. Threads sit in a sidebar, while the active conversation occupies the main workspace. Files, approvals, settings and ongoing agent activity remain accessible around it.

                                      The design deliberately brings OpenClaw closer to the interaction model employees already know from OpenAI’s ChatGPT, Anthropic’s Claude, Google’s Gemini and other conversational AI products.

                                      That lowers an important barrier to enterprise adoption. Open-source agent frameworks are often powerful precisely because they expose low-level configuration, terminals, tools and runtime controls. Those same characteristics can make them difficult to deploy beyond engineering organizations.

                                      OpenClaw 2.0 attempts to preserve the underlying control while putting a conversational interface on top of it. An employee can ask an agent to perform work without treating the terminal as the primary product interface. But OpenClaw does not hide what is happening underneath. The Control UI can surface session files, terminal activity, Git-backed changes, pull-request state, browser activity and interactive dashboards.

                                      The release also places more emphasis on observability during agent execution. Tool calls and results are paired more clearly, file changes can appear as focused diffs, command activity is easier to inspect, and long-running background tasks can remain visible alongside the conversation. That combination matters for enterprise use.

                                      Employees get a simpler interface for delegating work. Technical users retain access to the artifacts and execution state behind the conversation. Administrators gain a centralized place to configure and supervise the system.

                                      The redesigned Settings workspace now encompasses agents, memory, plugins, MCP servers, devices, communication channels and device pairing. OpenClaw also consolidates model-provider administration, including credential status and, where providers expose it, model availability, quota, account balance, budget and spending information.

                                      Limited-access browser users can request administrator privileges rather than automatically receiving them, with another administrator required to approve the escalation.

                                      These are not especially flashy agent features. For companies deploying AI systems to dozens or hundreds of employees, they may be among the most important additions in the release.

                                      Multiplayer sessions turn agent context into shared context

                                      OpenClaw 2.0 also expands the agent from a personal workspace into a collaborative one.

                                      Shared cloud sessions allow another employee to enter work already in progress without discarding the context accumulated by the agent.

                                      Multi-user Gateways — the service that connects users and agents to tools, files, credentials and other resources — can track who created a conversation and which prompts were submitted by identified participants.

                                      Owners and administrators can determine whether another user can read a session, suggest changes, work in draft mode or participate directly.

                                      The interface adds session ownership, participant attribution, presence and even typing indicators. For coding teams, that introduces a workflow closer to collaborative software development than traditional AI chat.

                                      A developer could initiate a task and allow an agent to work on it remotely. Another engineer could inspect the resulting changes. A senior engineer or administrator could approve an operation requiring additional privileges. The work does not have to remain attached to the laptop or terminal where it started.

                                      Sessions can also move execution to paired devices or cloud workers while maintaining the broader workspace.

                                      For enterprises experimenting with long-running agents, that is significant. Persistent agents need mechanisms for shift changes, escalation, supervision and ownership transfer. Otherwise, organizations simply create fleets of personal agents whose state disappears into individual user environments.

                                      OpenClaw is attempting to turn that state into collaborative infrastructure. Already, some teams outside the developers of the open source project are adopting it.

                                      Colin Johnson, CEO of marketing metrics software firm Solvely, described a similar shift in his own development workflow in a post on X.

                                      His team had already been using OpenClaw agents through Discord, where developers could assign tasks, run commands and interact with their development environment. But he said that model still felt like “messaging a bot”: developers could share access to an agent without actually sharing the agent’s working context.

                                      The new multiplayer WebUI changed that, he wrote, because two developers could open the same live session, see the same history and artifacts, and add information without first exporting or reconstructing what the agent had already done. “We were working inside the same context,” Colin wrote.

                                      In one example, another developer was taking over a project he had been working on; instead of preparing a traditional handoff document, Colin joined the developer’s existing agent thread and added the missing project context directly. “The session itself became the handoff document,” he wrote.

                                      For enterprise teams, that is a useful illustration of why persistent multiplayer sessions may matter beyond convenience: agent context can become a shared work artifact rather than information trapped inside one employee’s private conversation.

                                      Colin’s deployment also illustrates both the enterprise potential and the remaining security boundary. His team runs its OpenClaw Gateway on a development server reachable through GitHub authentication, Cloudflare Access and a Cloudflare Tunnel, with the Gateway itself listening only on the server’s loopback interface rather than an exposed public port.

                                      But he explicitly cautioned that this does not make the shared Gateway a multitenant environment. The developers already trust one another with the repositories, tools and agent capabilities behind it. As he put it, Cloudflare controls who can enter the workspace, while OpenClaw tracks who created, owns or contributed to the work; stronger separation still requires separate infrastructure.

                                      Security becomes much more enterprise-oriented

                                      That shift creates a corresponding security problem: a shared agent can potentially act with broader organizational authority than one running on a developer laptop.

                                      OpenClaw 2.0 responds with considerably more granular controls.

                                      Approvals can now be tied to a specific request, command, session and person. Command permissions can be constrained to specific arguments and working directories. For script-backed execution, OpenClaw can verify that the script being executed still matches what was originally reviewed.

                                      Sessions can operate under different permission levels, including read-only, guarded, workspace and full-access modes, with the highest level restricted to administrators.

                                      Organizations can also define operator roles that require sandboxed execution for sessions created by specific identities. OpenClaw says those requirements cannot be bypassed using elevated execution or host overrides; if the required sandbox cannot be provisioned, execution fails rather than silently falling back to the host.

                                      Credentials receive additional protection.

                                      OpenClaw’s team-scoped Secret Store distinguishes protected secrets from ordinary environment data available to the agent. For supported requests, a protected credential can be substituted into a Gateway-hosted HTTPS request without exposing that credential directly to the model.

                                      OpenClaw can also reference external systems including 1Password and Vault.

                                      Auditing has expanded around execution identity, approvals, session actions and outbound messages. Plugin installation can trigger capability reviews associated with the specific artifact being installed.

                                      Those controls address questions enterprises inevitably face when deploying agents: Who initiated an action? Which agent performed it? What resources could it access? Who approved the operation? And what happens to those permissions when work moves between people or machines?

                                      NanoClaw still takes a different approach to security

                                      OpenClaw’s changes also make the comparison with open source, enterprise-friendly rival NanoClaw more nuanced.

                                      NanoClaw is one of several subsequent projects to emerge around the idea that AI agents need stronger isolation and simpler security boundaries. Its architecture places operating-system-level containment at the center of the design.

                                      NanoClaw runs agents inside Docker containers, limits those containers to explicitly mounted filesystems and runs their processes as an unprivileged user. Sessions and agent groups can remain isolated rather than automatically sharing files and conversation history.

                                      Its credential architecture follows the same principle. Supported outbound requests can pass through OneCLI’s Agent Vault, allowing credentials to be injected by a gateway rather than placed inside the agent container itself. NanoClaw also provides an optional egress-lockdown mode that puts agents on an internal Docker network and routes supported external traffic through the gateway.

                                      OpenClaw 2.0 can now reproduce many elements of that hardened model. It supports Docker and Podman sandboxes, per-agent and per-session sandbox scopes, configurable read-only or read-write workspace access, role-enforced sandboxing, remote execution nodes and disposable cloud workers.

                                      The key difference is the starting posture. OpenClaw’s documentation explicitly says sandboxing and execution approvals are off by default. Its baseline configuration assumes a trusted single operator and permits host execution unless administrators configure stronger restrictions. NanoClaw makes isolation more fundamental to how agent execution is structured.

                                      So does OpenClaw 2.0 have security parity with NanoClaw?

                                      In terms of available controls, it is much closer than before. In terms of defaults and architectural philosophy, no. An enterprise can configure OpenClaw into a substantially hardened environment, but it has to make that decision deliberately.

                                      One Gateway is still one trust domain

                                      Another limitation is particularly important for larger organizations. OpenClaw says a Gateway should be treated as a single trust domain.

                                      Its new multi-user permissions are designed to govern collaboration among trusted users. They should not be treated as hard isolation between mutually untrusted tenants.

                                      For organizations requiring stronger separation — between business units, customers or other security domains, for example — OpenClaw recommends separate Gateway instances, described as “cells,” with separate state, credentials and workspaces.

                                      Fleet tooling for managing those cells remains experimental.

                                      That distinction could matter significantly for enterprises considering OpenClaw as a centrally operated service.

                                      Role-based access inside one Gateway may be sufficient for a trusted engineering department or internal team. It is a different proposition from a multi-tenant platform intended to isolate customers or users who should be assumed hostile to one another.

                                      NanoClaw has its own configuration requirements and limitations, and even its stronger outbound-network lockdown remains optional. But its smaller architecture and container-centric execution model may appeal to organizations that want a narrower security boundary that is easier to reason about.

                                      OpenClaw is optimizing for a broader problem.

                                      OpenClaw’s biggest advantage may be the control plane

                                      The tradeoff is product breadth.

                                      NanoClaw emphasizes a relatively small codebase, container isolation and customization through code and skills. Its second-generation architecture supports owner, administrator and member roles, and a separate monitoring dashboard can provide visibility into deployments.

                                      OpenClaw 2.0 is trying to build a much broader operational environment.

                                      Its Control UI combines employee interaction, live execution, files, approvals, terminals, code review, model-provider configuration, devices and shared sessions.

                                      That gives OpenClaw a potential advantage for enterprises that need not only secure agent execution but a usable control plane around it.

                                      Security teams care about isolation. Platform teams also need deployment, authentication, model configuration, auditing and policy enforcement. Employees need an interface they can actually use. Managers need a way to understand what is running. Developers need access to the underlying files and tools when something goes wrong.

                                      OpenClaw 2.0 increasingly tries to serve all of those constituencies through one system.

                                      What is OpenAI’s role?

                                      OpenClaw says 933 contributors, including 569 first-time contributors, participated in the release, which includes more than 16,000 pull requests — roughly half of all pull requests ever merged into the project.

                                      Interestingly, the release was not shared by Steinberger’s employer, OpenAI. Recall that the Austrian developer announced on Feb. 14, 2026 that he was joining OpenAI to work on bringing agents to a broader audience, a move OpenAI CEO Sam Altman publicly confirmed the following day.

                                      But OpenClaw was not folded into OpenAI. Steinberger said at the time that OpenClaw would move to a foundation and “stay open and independent,” while OpenAI would support the project. OpenClaw now says it is stewarded by the OpenClaw Foundation, an independent 501(c)(3), with OpenAI listed alongside Microsoft, GitHub, NVIDIA, Atlassian, Tencent and other organizations as partners.

                                      Based on the available public information, OpenClaw 2.0 should therefore be understood as an OpenClaw Foundation release, not an OpenAI product or OpenAI software release, despite Steinberger’s employment at OpenAI and OpenAI’s financial and organizational support for the project.

                                      Enterprise readiness now depends on configuration

                                      OpenClaw 2.0 does not eliminate the security risks associated with autonomous agents, and its own documentation identifies limitations.

                                      Secret Store values, for example, are not themselves encrypted at rest and rely on filesystem protections. Protected credential substitution does not cover every possible execution path, including some raw sockets, containers, remote nodes and provider-native harnessesIts multi-user permissions are collaboration controls, not hostile-tenant isolation.

                                      Those caveats should prevent enterprises from interpreting OpenClaw 2.0 as secure-by-default agent infrastructure.But they also illustrate how much the conversation around the project has changed. The relevant comparison is increasingly not simply OpenClaw versus NanoClaw. It is a container-first, constrained system such as NanoClaw versus a deliberately hardened OpenClaw deployment that provides a substantially broader employee and administrator experience.

                                      NanoClaw retains a strong proposition for organizations prioritizing a small attack surface, container-first execution and architectural simplicity.

                                      OpenClaw is making another bet: that enterprises ultimately need an agent platform to function as both runtime and workplace.

                                      OpenClaw 2.0 provides many of the primitives needed to build that environment — sandboxing, permissions, protected credentials, approvals, identity, auditing and isolated deployments — alongside a browser interface designed to make the system accessible to employees who will never configure an agent from a terminal.

                                      The remaining caveat is important: enterprises have to turn those primitives into policy. OpenClaw 2.0 doesn’t automatically make OpenClaw enterprise-ready, but it does make an enterprise-grade OpenClaw deployment far easier out-of-the-box.

                                      And as Steinberger’s description of OpenClaw’s own development process suggests, the long-term ambition may be larger still. Rather than giving every employee another AI assistant, OpenClaw is positioning the agent itself as shared infrastructure — a persistent layer where people, models and compute collaborate on the same work.

                                      ● Canal oficial · Gratis
                                      ¡Recibe las noticias antes que nadie!
                                      Únete a nuestro canal de WhatsApp y mantente informado al instante, sin spam.
                                      Unirme ahora →
                                      ● Noticias al instante ● Cobertura nacional ● Periodismo real Despertar Matinal
                                      — Redacción Despertar Matinal

                                      — Redacción Despertar Matinal

                                      Programa radial que te conecta con la información desde temprano en la mañana.

                                      Next Post
                                      Shein shares fall in long-awaited stock market debut

                                      Shein shares fall in long-awaited stock market debut

                                      Deja una respuesta Cancelar la respuesta

                                      Tu dirección de correo electrónico no será publicada. Los campos obligatorios están marcados con *

                                      Canal de WhatsApp

                                      WhatsApp logo WhatsApp

                                      Canal · Despertar Matinal

                                      Únete a nuestro
                                      Canal

                                      Seguir ahora

                                      El clima

                                      Canal de YouTube

                                      YouTube

                                      Canal · Despertar Matinal

                                      Mira nuestro
                                      Canal

                                      Ver ahora

                                      Escúchanos en Spotify

                                      Spotify

                                      Podcast · Despertar Matinal

                                      Escucha nuestro
                                      Podcast

                                      Escuchar ahora

                                      Noticias Populares

                                      • Dicen proyecto presidencial de Gonzalo Castillo impacta más de 40 territorios el fin de semana

                                        Dicen proyecto presidencial de Gonzalo Castillo impacta más de 40 territorios el fin de semana

                                        0 shares
                                        Share 0 Tweet 0
                                      • The jury’s options in Lindsay Clancy’s murder trial

                                        0 shares
                                        Share 0 Tweet 0
                                      • Man arrested after Swiss rave shooting that killed 22-year-old woman

                                        0 shares
                                        Share 0 Tweet 0
                                      • Advierte año escolar iniciará con problemas de fondo ante un…

                                        0 shares
                                        Share 0 Tweet 0
                                      • JKIA strike: Passengers stranded as strike disrupts flights at Kenya’s main airport

                                        0 shares
                                        Share 0 Tweet 0

                                      Medio digital independiente con análisis, opinión y periodismo responsable desde República Dominicana.

                                      Secciones populares

                                      • Política
                                      • Economía & Negocios
                                      • Justicia
                                      • Turismo
                                      • Tecnología
                                      • Entretenimiento
                                      • Mundo
                                      • Cine y Series
                                      • Música
                                      • Moda

                                      Contenido

                                      • Titulares del Día
                                      • Mundo
                                      • Nacionales
                                      • Política
                                      • Deportes
                                      • Economía & Negocios
                                      • Ciencia
                                      • Entretenimiento
                                      • Podcast
                                      • Opinión
                                      • Despertar Matinal TV
                                      • Editoriales

                                      Corporativo

                                      • Sobre nosotros
                                      • Publicidad
                                      • Sala de prensa
                                      • Contacto
                                      • Política de Privacidad
                                      • Eliminación de Datos

                                      Boletines

                                      Suscríbete a nuestro boletín
                                      Recibe las noticias más importantes cada mañana.

                                      • Nosotros
                                      • Publicidad
                                      • Trabaja con nosotros
                                      • Contactos

                                      © 2025 Despertar Matinal. Aviso Legal - comunícate con nuestra redacción y obtén más información sobre Despertar Matinal..

                                      No Result
                                      View All Result
                                      • Home

                                      © 2025 Despertar Matinal. Aviso Legal - comunícate con nuestra redacción y obtén más información sobre Despertar Matinal..

                                      Welcome Back!

                                      Login to your account below

                                      Forgotten Password?

                                      Retrieve your password

                                      Please enter your username or email address to reset your password.

                                      Log In

                                      Desarrollado por
                                      ►
                                      Las cookies necesarias habilitan funciones esenciales del sitio como inicios de sesión seguros y ajustes de preferencias de consentimiento. No almacenan datos personales.
                                      Ninguno
                                      ►
                                      Las cookies funcionales soportan funciones como compartir contenido en redes sociales, recopilar comentarios y habilitar herramientas de terceros.
                                      Ninguno
                                      ►
                                      Las cookies analíticas rastrean las interacciones de los visitantes, proporcionando información sobre métricas como el número de visitantes, la tasa de rebote y las fuentes de tráfico.
                                      Ninguno
                                      ►
                                      Las cookies de publicidad ofrecen anuncios personalizados basados en tus visitas anteriores y analizan la efectividad de las campañas publicitarias.
                                      Ninguno
                                      ►
                                      Las cookies no clasificadas son aquellas que estamos en proceso de clasificar, junto con los proveedores de cookies individuales.
                                      Ninguno
                                      Desarrollado por