OpenClaw Enterprise Is Free and Open Source, but It's for Pilots Only. What Works Today, and What the Docs Say Is Unfinished
The OpenClaw Foundation, with Red Hat and Nvidia, is pitching a self-hosted control plane for running persistent agents under IT's rules. The code is on GitHub now; the 1.0 release is months away.
TL;DR
On September 29, 2026 the OpenClaw Foundation announced OpenClaw Enterprise (OCE), an open source, vendor-neutral control plane for managing persistent AI agents in sensitive environments. It started at OpenAI, was donated to the Foundation, and has been developed with Red Hat and NVIDIA; OpenAI and Red Hat are piloting it internally. You can self-host it today with Docker Compose for local work or Kubernetes for internal deployment, but the Foundation calls it suitable for internal pilots only, with 1.0 due later this year. The project's own architecture docs list several pieces as still unfinished.
The problem OpenClaw Enterprise targets is a simple one, and the project states it plainly: "The default stance of IT in most organizations is to ban agentic platforms like OpenClaw altogether." An agent with access to code, credentials, and messaging channels is useful and risky in equal measure, and most IT teams have no common way to govern it.
What OCE is
- An enterprise control plane built on the original OpenClaw agent platform.
- Multi-tenancy, hard security boundaries, and standardized agent primitives, with governance and auditability across the agent lifecycle.
- Swappable core parts: the harness, the model, and the sandbox can each be replaced by third-party or internal versions.
- At its centre, per The New Stack, the OpenClaw Control Plane (OCC), where administrators deploy agents, separate them into isolated namespaces, manage configuration and credentials, set permissions, and keep a record of changes.
- Security approach: hard boundaries between trusted and untrusted workloads, sandboxing, LLM-based reviews, and fine-grained permissions. A reference architecture showing how they fit together is promised in the coming weeks.
Who's behind it
OCE began at OpenAI and was donated to the OpenClaw Foundation, where it is now an independent project developed with Red Hat and NVIDIA. OpenAI and Red Hat are piloting it internally. The blog post quotes OpenAI's RJ Marsan describing an internal OpenClaw agent, Androidclaw, that can find the pull request behind a broken build and fix it, and trace a streaming glitch, publish a pull request with video evidence, and merge it. That is one team's account of one internal agent. For context, The New Stack notes OpenClaw was created by Austrian developer Peter Steinberger in late 2025 and had passed 100,000 GitHub stars by February, when OpenAI hired him.
What works today, and what doesn't
| Area | Status | Source |
|---|---|---|
| Overall readiness | Internal pilot workloads only; 1.0 later this year | OpenClaw blog |
| Getting it | Clone the repo and follow the getting started guide; free for any organization, runs on your own infrastructure | OpenClaw blog |
| Kubernetes | Full local development environment runs the control plane, PostgreSQL, and agent workloads in a Kubernetes cluster; you can install into Kubernetes you already run | The New Stack |
| Docker or Podman Compose | Available, but limited to a control-plane preview and can't deploy agents through OCC | The New Stack |
| Implemented per the architecture docs | API, console, persistent worker, PostgreSQL backend, Kubernetes packaging | The New Stack |
| Unfinished per the architecture docs | External gateway admission, workload authentication back to OCC, and some approaches to model authentication | The New Stack |
| Reference architecture | Promised "in the coming weeks" | OpenClaw blog |
The Foundation's own documentation compares the project to Kubernetes for agents, and the blog's author, OpenAI's Kevin Lin, wrote that the goal is for OCE to become the standard for deploying agents the way Kubernetes did for containers. That is an ambition, not a current state.
What this means if you're evaluating agent platforms
If your security team has blocked agent tools, OCE is worth reading before you re-argue the ban: it's free, open source, and vendor-neutral, so you can inspect the code and run a contained pilot on your own Kubernetes. Don't plan production on it yet. The missing gateway admission and workload authentication are exactly the controls a cautious IT team will ask about, and the reference architecture hasn't been published. If you'd rather use a hosted agent product, OpenAI's Dots launched the same week, with its own permission rules.
Sources
- OpenClaw Blog: OpenClaw Enterprise - The Open Agent Platform (Sep 29, 2026)
- The New Stack: "Think of it as Kubernetes for agents": OpenClaw lands in the enterprise with OpenAI, Nvidia and Red Hat on board
- Complete AI Training: OpenClaw Foundation launches OpenClaw Enterprise for managing agents in sensitive environments
AI Industry Reporter
Priya covers model releases, industry announcements, and the gap between what labs claim and what independent evaluators actually find. She reads the primary source - the paper, the system card, the benchmark org's own statement - before writing a word.
More on AI Automation & Agents
OpenAI's Dots Are Always-On Agents With Their Own Cloud Computer. Here's What They Can Do, What They Hand Back to You, and What Isn't Clear Yet
Priya Nair · 6 min
H Company's Holo4 Scores 61.7% on OSWorld 2.0 With a 27B Model. The Weights Are Not Free for Commercial Use.
Priya Nair · 5 min
Manus 2.0 Launches Cascade, Studio, and Cue, an App That Gives Personal Agents Their Own Phone Numbers and Wallets
Priya Nair · 5 min