Enterprise Adoption2 min read

OpenClaw 2.0 Lets Teams Share One AI Agent

By , Senior AI ConsultantPublished

OpenClaw, the free AI agent already blocked on work computers at Meta, Google, Microsoft, and Amazon over security worries, shipped its biggest update yet, adding a feature that lets several people share and hand off the same AI agent even though the company's own setup notes say that sharing feature does not actually keep each person's access separate or secure.

OpenClaw just shipped the largest update in its short history. The project calls it OpenClaw 2.0, and it was built by more than 900 contributors, including many who had never worked on it before, over nearly two months when the team had been used to shipping updates almost every day.

If you have not heard of OpenClaw, here is the short version. It is a free, open source AI assistant that you install on your own computer or server. You connect it to your email, your messaging apps, your files, and your existing ChatGPT or Claude account, and it acts on your behalf, reading your inbox, sending messages, and completing tasks without you opening five different apps.

That idea caught fire. The project has been renamed several times since it launched last November, and by early this year it had become the fastest growing project in the history of GitHub, the platform where most open source software lives, at one point passing React, one of the most widely used pieces of software on the internet, in total popularity.

Its creator, Peter Steinberger, was hired by OpenAI earlier this year, and the project was moved into an independent foundation that OpenAI now backs.

Popularity came with a cost. Security researchers have repeatedly found the software running exposed on the open internet with no password protection, and attackers have used its plugin marketplace to sneak in hundreds of tools that quietly steal passwords and account keys from people's computers.

The research firm Gartner called it an unacceptable security risk. Meta, Google, Microsoft, and Amazon have all reportedly told staff not to run it on company devices, and China has restricted its use inside government agencies and state banks.

OpenClaw 2.0 does not fix that reputation, it builds on top of it. The headline new feature is called shared cloud sessions, and it lets more than one person work inside the same AI agent at the same time, handing tasks to each other without losing the history of what the agent has already done.

That is exactly the kind of feature a team or a small business would want if it planned to use this tool together instead of one person at a time. Here is the catch: the project's own setup notes say plainly that these sharing controls are not a real security boundary, meaning they do not guarantee that one person's access is properly walled off from another's.

For a business, that gap matters more than it sounds. Surveys of IT teams have found that a meaningful share of companies already have employees running this tool on their own, without approval from anyone managing security.

Adding an easy team feature on top of a tool with this safety record makes it more likely that sensitive company information ends up flowing through a system nobody signed off on. If your organization has not yet decided whether staff can use OpenClaw, this update is a good reason to decide now rather than find out after the fact.


STAY INFORMED

Get AI intelligence like this delivered to your inbox.

Free forever · Unsubscribe anytime


You May Also Find Valuable