OpenClaw

OpenClaw Foundation

Formerly Clawd, Clawdbot, Moltbot

Open Source

Self-hosted personal AI agent that runs on your own machine and acts for you through WhatsApp, Telegram, Slack, Teams and 20+ chat apps.

Curated by Tiberiu ArvaVerified

MITVersion 2026.9.7Released 2026-09-30

Strengths

  • Gateway bridges 20+ messaging channels
  • Built-in `openclaw security audit` command
  • Foundation-stewarded, no paid tier

Practitioner note

Treat it as privileged software with access to your accounts: keep the gateway on loopback, stay on current releases, allowlist DM senders and vet third-party ClawHub skills. The docs state one trust boundary per gateway, so it is not built for hostile multi-tenant use.

Warning

OpenClaw: Security history: CVE-2026-25253 (1-click RCE via gateway token exfiltration, CVSS 8.8) affected versions <= 2026.1.28 and was fixed in 2026.1.29; all ClawHub skills have been scanned with VirusTotal since 2026-02-07.

Governance posture

Reviewed 2026-09-30
YesData residency

Runs on the operator's own machine; prompts still go to whichever model provider is configured.

Source
YesDeployment model

Self-hosted on macOS, Windows or Linux; no hosted tier offered. (self-hosted)

Source
PartialAudit logging

`openclaw security audit` reports configuration drift by severity; no documented activity/audit log for agent actions.

Source
N/ASOC 2

Self-hosted open-source agent runtime; SOC 2 applies to the operator's infrastructure, not the package.

N/AISO 27001

Self-hosted open-source agent runtime; ISO 27001 applies to the operator's ISMS, not the package.

N/AISO 42001

Self-hosted open-source agent runtime; ISO 42001 applies to the deploying organisation.

N/AEU AI Act

Self-hosted open-source agent runtime, not an AI system placed on the market by the maintainer; obligations rest with the deployer. (role: not-applicable)

YesLicense risk

MIT (Copyright OpenClaw Foundation) — permissive, OSI-approved. (low)

Source

EU AI Act obligations

Risk tier: Not applicable · as of 2026-08-23

Source-backed information mapped from OpenClaw's tracked risk tier — not legal advice. Obligations depend on how your organisation deploys the system; see the full obligation reference and timeline.

This record's EU AI Act risk tier is marked not applicable, so no tier-specific obligations attach. Deployers embedding it in an AI system in scope of the Act should assess that system's own tier.

Explore the category

Compare this tool against the rest of its category and the cloud platform foundation layer.