OpenClaw Enterprise launches: an agent control plane started at OpenAI, built with Red Hat and NVIDIA
OpenClaw Enterprise launched September 29: an open-source agent control plane with hard multi-tenancy, started at OpenAI, co-developed with Red Hat and NVIDIA.

OpenClaw announced Enterprise (OCE) on September 29: an open-source, vendor-neutral enterprise control plane for persistent AI agents. The project started at OpenAI and was donated to the OpenClaw Foundation, co-developed with Red Hat and NVIDIA — both piloting it internally. The main openclaw/openclaw repo (391k stars) keeps its “no paid tier, no hosted service” personal-assistant positioning; Enterprise is its enterprise-side sibling.
Facts
- Core capabilities: hard multi-tenant boundaries (trusted/untrusted isolation), governance and full-lifecycle auditability, fine-grained permissions, LLM-based behavior reviews, and sandboxing as a first-class primitive.
- Swappable design: harness, model and sandbox components can each be replaced with third-party or in-house parts.
- Deployment: self-hosted via docker-compose or Kubernetes; “always free,” currently pre-1.0.
- Governance: named and started at OpenAI, then donated to the OpenClaw Foundation; Red Hat and NVIDIA co-developed.
- Sourcing note: consistent across the official blog, VentureBeat, The Register and Quartz; no SLA or support model announced.
Editorial take
What enterprises lack for agents has never been the model — it is the control plane: tenant isolation, audit trails and permissions that everyone currently builds in-house. Donating the project to a foundation and pulling in Red Hat and NVIDIA signals an industry-standard play, not a vendor lock — putting it in the same layer as Nvidia’s OpenShell and Google’s AX orchestrator. Evaluate three things first: how tenant boundaries are enforced, how complete the audit logs are, and what pre-1.0 means for API stability.## The competitive layer
Three players are racing for the “industry standard part” seat in agent infrastructure:
- Nvidia’s Open Agent Safety Platform: OpenShell sandbox plus DPU-based Sentry monitoring, coalition-style (our coverage).
- Google AX: a declarative orchestrator owning scheduling and lifecycle, Apache 2.0 (our coverage).
- OpenClaw Enterprise: owns the governance plane — tenants, permissions, audit — via foundation stewardship and multi-vendor co-development.
They are not mutually exclusive: one enterprise deployment could plausibly run OpenClaw Enterprise as the governance plane, AX for scheduling, OpenShell for sandboxing.
Three checkpoints for buyers
- How tenant boundaries are enforced: process, container, or kernel level? “Hard boundary” varies by an order of magnitude in cost.
- Audit completeness: do logs capture tool-call arguments and return values, or just event names?
- The pre-1.0 promise: how long is the API stability window, and how do breaking changes get voted under foundation governance?
Our take
What enterprises lack for agents has never been the model — it is the control plane: tenant isolation, audit trails and permissions that everyone currently builds in-house. Donating the project to a foundation and pulling in Red Hat and NVIDIA signals an industry-standard play, not a vendor lock; buyers should build evaluation checklists around the three checkpoints above.
Deployment reality and risks
- Deploy path: docker-compose suits single-team pilots, but real multi-tenant production will land on Kubernetes; “always free” says nothing about support or SLAs, so buyers should ask what commercial support channel the foundation offers.
- Relation to the main repo: openclaw proper (391k stars) stays a personal assistant with an explicit “no paid tier, no hosted service” stance; Enterprise is a separate code line sharing the brand but not the release cadence — main-repo velocity does not transfer automatically.
- Risk: at pre-1.0, multi-tenant isolation is most dangerous in its default configuration; Red Hat and NVIDIA’s internal pilots are positive signals, but neither the pilot scale nor the workloads have been disclosed.
Glossary
- Control plane: the software layer owning agent identity, permissions, audit and lifecycle — as opposed to the data plane that executes tasks.
- Hard multi-tenancy: isolation requiring that agents of different tenants can neither see nor invoke each other.
- OpenClaw Foundation: the governing entity of the main project; Enterprise joining the same foundation means its roadmap is set by committee, not a single company.