The popular open source AI agentic framework OpenClaw is now targeting the enterprise with OpenClaw Enterprise, or OCE, a new, vendor-neutral, MIT Licensed platform designed to allow companies to deploy persistent AI agents while retaining centralized control over security, permissions, auditing and infrastructure.

The project adds multi-tenancy, hard security boundaries, lifecycle governance and auditing around agents while allowing companies to swap in their own models, harnesses and sandboxes.

The software is particularly notable for its provenance. OpenClaw says the project originated inside OpenAI before being donated to the OpenClaw Foundation, where it now operates as an independent open-source project developed with contributions from Red Hat and Nvidia. OpenAI and Red Hat are already piloting it internally.

For enterprise technology leaders, the release reflects a broader shift in the agent market: the hard problem is increasingly not whether an AI model can execute a task, but whether a company can safely let hundreds or thousands of persistent agents touch production systems, internal repositories, credentials, APIs and enterprise data.

OpenClaw argues that this governance gap is currently preventing broader deployment. The Foundation says some IT organizations have responded to autonomous agent platforms by simply banning them because existing systems do not provide sufficient security and governance controls.

OCE is an attempt to build the layer between those two extremes.

A new control plane

OpenClaw describes OCE as an enterprise-grade control plane layered around agents rather than a new model or standalone assistant.

The architecture introduces multi-tenant administration, fine-grained permissions, workload isolation, sandboxing and auditing, along with mechanisms for reviewing agent actions using language models. The underlying components remain replaceable: companies can bring different models, agent harnesses or sandbox implementations rather than committing to a vertically integrated stack.

The project Github repo makes the ambition more explicit, describing OCE as effectively "Kubernetes for agents" — infrastructure for deploying and managing them across an organization rather than defining how an individual agent thinks or behaves.

That infrastructure orientation also shapes how OCE is deployed.

Companies can self-host the platform today. OpenClaw supports Docker Compose for local development and Kubernetes for internal deployments, allowing businesses to run the control plane on infrastructure they already operate rather than send all agent activity through a third-party SaaS service.

The repository includes a dedicated OpenClaw Control Plane, or OCC, covering agent deployment and lifecycle management. Local installations can run against Kubernetes, while production environments can deploy into existing Kubernetes clusters.

As previously alluded to, OCE itself is free and open source under the enterprise-friendly MIT License — available for download on Github here — although enterprises would still pay for their underlying compute, models, storage and operational infrastructure. OpenClaw says the platform will remain free for organizations to use.

OpenAI is already letting an OpenClaw agent touch its code

One of the most revealing parts of the announcement is how OpenAI itself is using the technology.

OpenClaw says OpenAI is running persistent OpenClaw agents with access to its codebases and plugins. RJ Marsan, a member of OpenAI's technical staff, described an internal enterprise agent called Androidclaw that operates across company context, Git, GitHub and logging systems.

According to Marsan, the agent can investigate broken builds, identify the relevant pull request, trace product problems back to incidents and in some cases prepare and merge fixes.

Marsan said Androidclaw has been "well-adopted" internally and called its ability to trace issues and publish fixes "Kinda game changing."

That example illustrates both the attraction and the risk behind persistent enterprise agents: the more useful an agent becomes, the more privileged access it often needs.

A chatbot that summarizes a document may require little more than read access. An agent that diagnoses a production outage or repairs a broken build could require access to repositories, logs, cloud infrastructure, CI systems, credentials and deployment tools.

OCE is designed around controlling that broader attack surface.

Red Hat and Nvidia are building around the same problem

OpenClaw's partners have already been attacking agent security from adjacent layers.

Red Hat has spent much of 2026 exploring how OpenClaw and other agents can run safely on shared enterprise infrastructure. Its OpenShift work isolates agents from sensitive credentials using separate namespaces, restricted access controls and credential proxies, while treating the agent process itself as untrusted.

Red Hat also joined the OpenClaw Foundation as a founding member and said it intends to bring the project's requirements into its broader AI platform, including multi-tenant execution, identity-based tool filtering and OpenShell-based isolation across Kubernetes environments.

Nvidia, meanwhile, has developed OpenShell, an open-source runtime that places autonomous agents inside isolated environments with deny-by-default permissions, policy enforcement and audit trails. Nvidia's broader Open Agent Safety Platform also introduces independent monitoring intended to contain agents that behave outside policy.

OCE effectively sits above those kinds of runtime protections, providing the organizational control plane for deploying and governing agents at scale.

How OCE differs from NanoClaw

The name invites comparison with NanoClaw, but the two projects attack substantially different problems.

NanoClaw is primarily a lightweight alternative to OpenClaw itself: a smaller personal-agent runtime designed to be easy to inspect, modify and self-host. Its current architecture runs individual agents inside containers and gives each agent its own workspace, memory and explicitly mounted resources. It supports channels including Slack, Discord, Telegram and email and can run scheduled jobs while using container isolation to keep agents separated.

NanoClaw therefore competes more directly with the agent runtime layer beneath OCE. Its design philosophy is simplicity and isolation. NanoClaw's developers contrast its relatively compact TypeScript implementation and OS-level container boundaries with OpenClaw's much larger application-level runtime.

OCE addresses a different organizational problem: managing many agents, users and workloads centrally. Rather than asking "How do I safely run this agent?", OCE is closer to asking "How does an enterprise operate an entire fleet of agents with common identity, permissions, governance, audit and infrastructure policies?"

The distinction matters because OCE is explicitly designed so that underlying components can be replaced. In principle, a lightweight runtime such as NanoClaw occupies the kind of architectural layer that an enterprise control plane can sit above, although the currently published materials do not document a specific OCE-NanoClaw integration.

RunLayer is a closer enterprise competitor

A closer conceptual competitor is Runlayer, which has also positioned itself as an enterprise AI control plane.

Runlayer provides centralized policy, agent identity, runtime security, observability and audit capabilities across AI systems including Claude Code, Cursor, ChatGPT, Codex and enterprise MCP servers. The company also operates an MCP gateway and its own hosted agent runtime, while detecting unsanctioned "shadow AI" tooling inside organizations.

Its platform can inspect tool requests, enforce identity-aware policies, monitor agent activity and track adoption and costs. Runlayer also integrates with enterprise identity systems through SSO and SCIM and supports customer-hosted deployments.

That makes Runlayer and OCE substantially more alike than OCE and NanoClaw, but their business and architectural models differ.

Runlayer is a commercial enterprise platform intended to govern not only agents created on its infrastructure but also an organization's wider AI ecosystem — including MCP servers, third-party clients, reusable skills and unsanctioned AI usage. It describes its goal as providing a single "golden path" for employees adopting tools such as Claude, Cursor, ChatGPT and Codex.

OCE, by contrast, is an open-source infrastructure project centered more tightly on deploying and managing persistent agents themselves. It does not currently present the same broad product suite around shadow-AI discovery, ROI analysis or enterprise MCP catalog management.

Runlayer has also built a conventional venture-backed enterprise software business around the category. The company raised a $30 million Series A in June 2026 from Felicis and Khosla Ventures, bringing its total funding to $42 million, and says customers include Instacart, Gusto, Opendoor, dbt Labs and other enterprises.

OpenClaw is instead betting that a neutral, permissively licensed control plane can become shared infrastructure underneath competing agent runtimes, models and security products.

How OCE differs from OpenAI Dots and ChatGPT Space

The timing also makes OpenClaw Enterprise an interesting counterpart to two other products OpenAI announced earlier today at its annual DevDay event: Dots and ChatGPT Space.

Dots are persistent AI coworkers that can continue working after a user closes a chat session. Each receives its own cloud computer and browser, can connect to thousands of applications through OpenAI's plugin ecosystem and can communicate through ChatGPT, Slack and Microsoft Teams. ChatGPT Space provides the shared collaboration layer around those agents, giving employees, ChatGPT, Codex and Dots common access to Pages, files, presentations, spreadsheets and project context.

That makes Dots and Space much closer to the application and user-experience layer of enterprise agents. Employees delegate work to Dots and collaborate with them inside Space; OpenAI handles much of the underlying execution environment, permissions and agent infrastructure.

OCE approaches the same emerging agent workforce from the opposite direction. It is not primarily an employee-facing assistant or collaborative workspace. Instead, it provides the underlying control plane that an IT or platform team can use to deploy and govern persistent agents across infrastructure it controls.

The distinction becomes clearer with OpenAI's planned specialist Dots. OpenAI says those agents can receive their own organizational identities, credentials and business responsibilities, with pilots covering areas such as procurement, invoice processing, customer support and contracting. Those machine identities create exactly the kinds of lifecycle, authorization and auditing problems that enterprise control planes such as OCE and Runlayer are designed to address.

In other words, Dots are workers; Space is where those workers collaborate with people; OCE is infrastructure for governing the broader agent fleet.

There is also an important architectural difference. Dots and Space are OpenAI products built around ChatGPT, OpenAI's models and its cloud services. OCE is explicitly vendor-neutral and self-hostable, with replaceable models, harnesses and sandboxes. That likely makes it more enticing to enterprises that want persistent agents without relying on a single model provider.

The products are therefore more complementary than directly competitive. OpenAI could theoretically use infrastructure like OCE underneath internal or specialist agents while exposing Dots and Space as the employee-facing experience — and OpenClaw's announcement already says OpenAI is piloting OCE internally.

Still a pilot, not a finished enterprise platform

Despite the "Enterprise" name, OpenClaw is not presenting OCE as finished production infrastructure yet.

The Foundation currently recommends it for internal pilot workloads and says it intentionally released the source early so developers and organizations can shape the platform ahead of a planned 1.0 release later this year.

Some important security details also remain forthcoming. OpenClaw says it plans to publish a reference architecture explaining how workload boundaries, sandboxing, LLM-based reviews and permissions operate together.

That leaves enterprises with a familiar tradeoff: Persistent agents are becoming capable enough to touch increasingly sensitive workflows, but the operational infrastructure surrounding those agents remains immature compared with the systems enterprises already use to manage human identities, cloud workloads and conventional applications.

OCE, NanoClaw and Runlayer illustrate three emerging layers of the response: lightweight isolated agent runtimes, commercial cross-platform governance systems, and now an open-source enterprise control plane intended to orchestrate persistent agents across company infrastructure.

If OpenClaw's bet succeeds, the next phase of the agent market may be determined less by which model produces the smartest response and more by which infrastructure companies trust enough to let those models act.