Meta, Others Ban OpenClaw Over Security Risks

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Massive CEO Jason Grad warned all 20 employees on January 26 via Slack to keep OpenClaw off company hardware and work-linked accounts, calling the then-trending tool 'unvetted and high-risk' before any employee had installed it
- A Meta executive told his team to keep OpenClaw off regular work laptops or risk termination, telling reporters he believes the software is unpredictable and could trigger a privacy breach in secure environments
- Valere CEO Guy Pistone initially imposed a strict ban after an employee shared OpenClaw on internal Slack on January 29, citing risks of accessing cloud services, client credit card data, and GitHub codebases; he later allowed a research team to test it on an isolated old computer
- Valere researchers concluded users must 'accept that the bot can be tricked,' warning that a malicious email could instruct OpenClaw to share copies of files on a user's computer if set up to summarize email
- Peter Steinberger, OpenClaw's solo founder who launched it as a free open-source tool last November, joined OpenAI last week; OpenAI says it will keep OpenClaw open source and support it through a foundation
- Massive cautiously explored commercial potential, testing OpenClaw on isolated cloud machines and then releasing ClawPod, a way for OpenClaw agents to use Massive's web proxy services to browse the web
- Dubrink CTO Jan-Joost den Brinker bought a dedicated machine disconnected from company systems and accounts solely for employees to experiment with OpenClaw, saying 'we aren't solving business problems with OpenClaw at the moment'
Why it matters: Agentic AI tools like OpenClaw that take autonomous control of a user's computer introduce a new class of insider-style risk, and Valere's research showing the bot 'can be tricked' via a single email gives CISOs a concrete attack vector to block. The pattern is consistent: companies ban first, then build isolated sandboxes to study the tool — with Massive already releasing a commercial product on top of it, meaning adoption pressure will intensify as the security questions remain unresolved.




