AX Insight

What are AI Agent Security Risks? From OpenClaw to Domestic and International Corporate Cases

HANCOM
🧑‍💻 Summary:

This article examines the concept of 'OpenClaw,' an open-source autonomous AI agent, and the security risks posed by its administrator-level privileges. It then highlights cases where NVIDIA (NemoClaw), Genspark (Genspark Claw), and Perplexity (Personal Computer) have enhanced autonomous AI agent security features through their respective methods (execution space isolation, dedicated cloud, dedicated local device). Finally, based on Hancom's experience successfully leading AI Transformation in security-sensitive sectors like public and finance, we introduce 'Hancom Agentic OS,' which supports on-premise and closed network environments while protecting data sovereignty.

‘Raising Lobsters’

In March 2026, over 1,000 people, including developers, students, and homemakers, lined up in front of Tencent’s headquarters in Shenzhen, China, to install the AI agent ‘OpenClaw’ for free. Due to its red lobster-shaped icon, the craze for installing and using OpenClaw was called ‘Raising Lobsters’ and gained immense popularity in China.

However, just a few days later, the Chinese government raised security concerns about OpenClaw, and even paid services emerged to ‘completely delete’ OpenClaw. The ‘Raising Lobsters’ craze quickly turned into ‘Erasing Lobsters.’

What made everyone who eagerly installed OpenClaw turn their backs on it so quickly?

In this article, we will explore what OpenClaw is as a representative example of an open-source autonomous AI agent, what security control risks it posed, and how global big tech companies and Hancom are responding to these issues.

What is OpenClaw?

OpenClaw is an open-source autonomous AI agent released in November 2025 by Austrian developer Peter Steinberger, operating in an on-device manner, running directly on the user's machine.
OpenClaw Concept Explanation Image

Autonomous AI Agent: Administrator-Level Access

OpenClaw is an AI agent that observes, judges, and acts autonomously to achieve specific goals, performing tasks with administrator-level access.

While existing generative AI (chatbots) merely answered questions, OpenClaw directly handles tasks such as writing emails, scheduling appointments, editing files, and running code without constant human intervention. Like its name, which means ‘claw,’ OpenClaw directly manipulates the computer with administrator-level privileges, freely accessing the entire system.

On-Device Method: Local Processing Instead of Cloud

OpenClaw was designed using an on-device method, allowing Large Language Models (LLMs) to go beyond simple text generation and directly control the local computer environment.

It is designed to reduce reliance on external clouds and operate independently on local devices, performing core functions even in environments with unstable internet connections. This allows users to have greater control over their data by processing it directly within their personal devices without transmitting it to external clouds.

Open-Source Release: An Accessible Ecosystem for Everyone

OpenClaw was released as open-source, allowing anyone to freely use, modify, and redistribute its source code.

Anyone can install it for free, and it can be used immediately without specialized development knowledge, quickly securing a large user base, as seen in China’s ‘Raising Lobsters’ craze. It has also received significant attention from the open-source community, with its official GitHub metrics continuously increasing.

OpenClaw’s Security Risk: Uncontrolled Autonomous Execution

The structure that grants agents system access and autonomy maximizes productivity and automation but simultaneously creates security risks of a different magnitude than existing software. This is because the authority to perform tasks without approval or arbitrarily change security settings—that is, the expanded scope of execution—also increases points of exposure to external data leaks or attacks.

Indeed, when a research team led by Natalie Shapira at Northeastern University in the U.S. instructed OpenClaw to perform 16 routine tasks, such as email management and scheduling, unexpected behavior occurred in 11 cases. Errors included sharing files containing medical records and account numbers externally without approval, or resetting the entire email system in response to a request to delete a single email.

As uncontrolled autonomous execution can lead to unexpected incidents even in simple tasks, the importance of a controllable security system is emerging, especially in areas handling sensitive data such as public services, finance, and healthcare.

Autonomous Agents with Enhanced Security Technology from Overseas Big Tech Companies

In response to OpenClaw’s security concerns, the AI industry has successively introduced autonomous AI agent technologies with enhanced security features.

Notably, OpenAI made a bold move by directly recruiting Peter Steinberger, the creator of OpenClaw. Peter Steinberger, who joined OpenAI, set his next goal as “an agent even my mother can use,” and OpenAI expects to resolve security issues and advance technology through this recruitment.

NVIDIA: NemoClaw, Execution Space Isolation Based on OpenShell

At GTC 2026, NVIDIA unveiled ‘NemoClaw,’ which supports the safe use of open-source AI agents like OpenClaw in enterprise environments. The core is ‘OpenShell’ technology, which separates the agent’s execution space from the rest of the system, preventing damage from spreading to other systems even if malfunctions or attacks occur. This allows enterprises to adopt autonomous AI agents for their work while reducing security burdens.

Genspark: Genspark Claw, User-Specific Dedicated Cloud Isolation

Genspark launched ‘Genspark Claw,’ a cloud-based AI assistant. Instead of directly accessing the local environment like OpenClaw, it operates in a dedicated cloud environment called ‘Genspark Cloud Computer.’ Users are granted their own independent cloud space, allowing them to safely execute tasks isolated from other users’ data.

Perplexity: Personal Computer, Dedicated Local Device Isolation for Mac Mini

Perplexity introduced ‘Personal Computer,’ an AI agent that runs on the user’s local device, a dedicated Mac Mini. It utilizes the Mac Mini as a physical hub for AI, linking with the user’s local files and apps, and securely processing sensitive tasks in an isolated environment. This prevents the risk of personal information leakage while maximizing the benefits of the local environment and ensuring a secure setting.

Hancom: Hancom Agentic OS,
Achieving Data Sovereignty with Public and Financial AI Transformation References

As the autonomy and execution scope of AI agents expand, it becomes crucial for enterprises and governments to establish governance and security systems that can safely control them. In this trend, Hancom is preparing ‘Hancom Agentic OS,’ a platform that perfectly protects data sovereignty while safely operating and controlling multiple AI agents.

For the past 36 years, Hancom has focused on business in public and financial sectors requiring strong security, and is now recognized for its proven capability in building security control systems that guarantee thorough ‘data sovereignty.’

Just as clinical trials are essential for new drug development, Hancom conducted a three-phase clinical validation for its AI Transformation business. Phase 1 verified its unstructured data processing capabilities and technology accumulated over 36 years through the launch of commercial solutions. Phase 2 involved internal clinical trials with over 750 AI adoption cases within Hancom. Finally, Phase 3 completed validation by successively deriving AI Transformation cases in various industries, including BGF Group (large enterprise), Korea Western Power (public enterprise), and the National Assembly (government agency), satisfying diverse requirements for security, document accuracy, and internal data linkage.

Thus, Hancom has accumulated rich internal and external AI Transformation success stories by going through all stages: technology verification (Phase 1), internal clinical trials (Phase 2), and external validation (Phase 3). As a result, it has been recognized for its competitiveness even in public networks, where security and accuracy are most stringent, establishing itself as a trusted AI Transformation partner for businesses.

The Core of the AI Agent Era: Secure Control and Security System

The proliferation of autonomous AI agents, as demonstrated by OpenClaw, shows that AI is expanding beyond a mere tool to become an active executor. Simultaneously, as the scope of execution expands, there is a growing demand for more sophisticated governance and security systems that can safely control it.

Just as NVIDIA, Genspark, and Perplexity have introduced autonomous AI agent technologies with enhanced security features in their own ways, Hancom is also preparing the ‘Hancom Agentic OS’ platform to provide a secure AI agent operating environment. Based on AI Transformation (AX) cases accumulated in sectors requiring high security, such as public service and finance, and a security framework that supports on-premise and closed-network environments, Hancom aims to launch the platform in September 2026.

Competitiveness in the AI agent era is not merely about creating smarter models. The ability to establish a structure that can safely control autonomy and integrate it into actual work in a trustworthy manner will be key.

Today’s Summary Q&A

Q1. What is OpenClaw, and why is it vulnerable to security threats?

OpenClaw is an open-source autonomous AI agent released in November 2025 by Austrian developer Peter Steinberger, operating in an on-device manner. It doesn’t just answer questions like a chatbot but directly handles tasks such as email writing, scheduling, file editing, and code execution without human intervention. However, these administrator-level privileges increase the risk of external data leaks and exposure to attacks as the scope of execution widens.

Q2. After the OpenClaw incident, how are overseas big tech companies enhancing security?

OpenAI directly recruited OpenClaw creator Peter Steinberger. NVIDIA applied ‘OpenShell’ technology for execution space isolation in ‘NemoClaw,’ while Genspark launched ‘Genspark Claw,’ which operates in a user-specific isolated cloud environment. Perplexity prevented external leakage risks with ‘Personal Computer,’ which runs on a dedicated local device (Mac Mini).

Q3. In the era of AI agents, with the growing importance of security risks, how is Hancom responding?

Hancom possesses validated AX references across various industries, including BGF Group, Korea Western Power, and the National Assembly, and is recognized for its capability in building security control systems in public and financial sectors that demand strong security. Based on this competitiveness, Hancom is preparing ‘Hancom Agentic OS,’ an AI work platform that reduces reliance on external clouds and can be built and operated in on-premise and closed network environments, with a planned release in September 2026. For more details, you can check the official Hancom Agentic OS page.

📄 References

  • Dong-A Ilbo, “‘My Personal Secretary,’ but… Paid Service to Delete Security-Threatening ‘OpenClaw’ Appears,” March 22, 2026
  • Hancom Official Blog, “What is an AI Agent? From Concept to Domestic and International Corporate Cases,” June 19, 2026
  • Hancom Tech, “2026 Agentic AI Technology Trends: A Look at OpenClaw and MoltBook,” March 9, 2026
  • Hancom Official Blog, “What is Open Source AI? From Concept to Domestic and International Corporate Cases,” June 26, 2026
  • OpenClaw, Official GitHub
  • Dong-A Ilbo, “Beware of AI’s ‘Flattery’ and ‘Insolence’,” March 30, 2026
  • NVIDIA, NemoClaw Official Page
  • Genspark, Genspark Claw Official Page
  • Perplexity, Personal Computer Official Page

👀 Recommended Content

  • [HAI Newsletter] 👋 Doing Well Alone, Autonomous AI Agent
  • [Hancom Official Press Release] 36 Years of ‘Hancom Office’ History… Hancom Reborn as an ‘Agentic OS Company’
  • [Hancom Blog] [On-site Sketch] Hancom Declares Transition to ‘Sovereign Agentic OS Company’ — HANCOM: THE SHIFT Into Agentic OS Press Conference
  • [Hancom Agentic OS Website] As a platform connecting an organization’s data, systems, and AI, it provides an AI Transformation experience optimized for enterprise environments without the burden of replacing existing infrastructure.