news.mlab.sh
Back to the feed
threat-intel

For Enterprises, Security Remains Agentic AI's Biggest Challenge

High
Summary

This article discusses the rapid adoption of OpenClaw, an agentic AI assistant, and the significant security challenges it presents to enterprises. Despite its popularity and endorsement from Nvidia, the software has been plagued by vulnerabilities and instability, leading Gartner to recommend blocking it. The creator, Peter Steingberger, is developing a more secure enterprise version, NemoClaw, which incorporates sandboxing and governance controls to address these concerns. The speed of OpenClaw's spread, often without proper security oversight, highlights the urgent need for robust security architectures around agentic AI.

The story centers around OpenClaw, an agentic AI assistant that gained significant traction quickly after its release. Driven by its open-source nature and endorsement from Nvidia CEO Jensen Huang, thousands of users downloaded the software, leading to a massive GitHub star count. However, this rapid adoption was accompanied by serious security concerns. Gartner issued a recommendation to block OpenClaw due to its insecure default operation and the discovery of numerous vulnerabilities, totaling over 450 according to the National Vulnerability Database. The software's instability, including agent slowdowns and installation issues, further exacerbated the situation, prompting apologies from its creator.

To address these issues, Peter Steingberger is developing NemoClaw, an enterprise-grade version of OpenClaw. NemoClaw incorporates features like agent registration, governance controls, and an open-source orchestration layer, utilizing OpenShell for sandboxing and Nemotron-3 AI models. A demonstration highlighted the speed at which OpenClaw could be exploited, showcasing its potential for data exfiltration and manipulation. This underscores the critical need for new security architectures designed specifically for agentic AI systems.

The article also touches on broader trends, including OpenAI and Anthropic's development of agentic capabilities and the challenges of managing rapidly evolving AI agents. It emphasizes the pressure on business leaders to adopt agentic AI for productivity gains while acknowledging the inherent risks and the importance of visibility and governance.

Read the full article at Dark Reading