AI Engineer Europe 2026
State of the Claw — Peter Steinberger
Read the talk
State of the Claw: Building Open Agents Without Losing Control
Peter Steinberger explains how OpenClaw’s rapid growth exposes the operational realities of agent security, independent open-source governance, modular architecture, and engineering judgment.
From a talk by Peter Steinberger
At a glance
Ideas worth remembering
Independent governance and maintainers from multiple companies are intended to keep OpenClaw open, model-agnostic, and less dependent on a single organization. 16:04
Security triage requires context: severity scores do not establish exploitability without considering gateway exposure, permissions, deployment configuration, and real-world usage. 6:27
Agent safety depends on boundaries: restrict who can issue instructions, sandbox shared agents, minimize accessible secrets, and treat model choice as part of the threat model. 10:50
Personal-agent architecture emphasizes user-controlled data, adaptable model selection, and interfaces that can follow users across messaging tools, rooms, and devices. 21:56
Human judgment remains the bottleneck: iteration, taste, system design, and the ability to reject unnecessary features keep agent-generated software coherent and maintainable. 26:32
Growth creates an organizational problem before it creates a technical solution
Peter Steinberger describes OpenClaw as a five-month-old project growing at a pace that strains conventional open-source maintenance. His reported figures include approximately 30,000 commits, nearly 2,000 contributors, and close to 30,000 pull requests. The central implication is that popularity does not automatically translate into sustainable ownership: a project can accumulate enormous activity while still depending too heavily on a small number of people to make consequential decisions and land changes. 0:52
The organizational answer is the OpenClaw Foundation, which Steinberger portrays as a neutral structure rather than an extension of any single company. He says the project needs to remain open and compatible with different models, including local models, while drawing support from contributors across companies. His deliberate distribution of maintainers and collaborators is intended to improve the concentration of commit responsibility without creating the impression that OpenAI controls the project. 2:33
This arrangement introduces its own management constraints. Foundation leadership resembles operating a company without equivalent authority over volunteers, and Steinberger says the project ultimately needs full-time staff to maintain development speed, improve quality, and free maintainers to build. At the time described in the talk, establishing the foundation was nearly complete but still faced banking-related administrative delays. 2:33
Suggest correction
This note stays in this page until you copy or download it. Nothing is submitted; reloading clears the draft.
Security severity is not the same thing as practical exposure
Steinberger reports receiving 1,142 security advisories, averaging approximately 16.6 daily, including 99 marked critical; he says roughly 469 had been published and 60% closed. This volume reflects both genuine exposure and an ecosystem in which increasingly capable AI tools can generate vulnerability reports faster than maintainers can evaluate them. His example of testing NVIDIA’s Nemo Claw with Codex Security illustrates the broader point: a nominal security boundary may contain multiple escape routes that capable automated analysis can uncover quickly. 3:42
His criticism of CVSS severity is not that vulnerabilities should be ignored, but that numerical classifications can obscure whether an exploit matches deployed reality. He discusses a maximum-severity permission-escalation scenario involving a reduced-permission device model, then argues that most users either have gateway access or do not, and that the narrower configuration is not meaningfully used. A separate remote-execution scare depended on exposing a gateway token in ways that, according to Steinberger, conflict with the local-only or private-network setup recommended by default. 6:27
Other threats remain consequential even when they originate outside OpenClaw itself. Steinberger describes deceptive distribution through a similarly named package or misleading website, and a supply-chain dependency incident in which the project was affected through MS Teams or Slack despite not directly using Axios. The engineering distinction is between an alarming label, an exploitable configuration, a compromised dependency, and a malicious distribution channel: each demands a different response rather than a uniform interpretation of reported severity. 8:10
The operational bottleneck is trustworthy triage. Steinberger says many reports appear agent-generated, but maintainers still must inspect them carefully because automated systems cannot yet be trusted to settle every case. Reports rarely arrive with useful fixes, rushed remediation can break the product, and volunteers alone struggle to absorb the workload; he credits company-supported engineers, particularly from NVIDIA, with helping review reports and harden the codebase. 9:19
Affected dependency
A dependency used by integrations exposed OpenClaw despite the project not using Axios directly.
Suggest correction
This note stays in this page until you copy or download it. Nothing is submitted; reloading clears the draft.
Agent safety starts with access boundaries and realistic threat models
Steinberger identifies a structural risk common to powerful agents: combining access to private data, exposure to untrusted content, and the ability to communicate externally. The same capabilities that make an agent valuable can create a path for information exfiltration or unwanted actions. His argument is that this tradeoff is inherent to agentic systems, not unique to OpenClaw, and that users need to understand what authority their agents actually possess. 10:50
The recommended operating model follows directly from those boundaries. A personal agent should accept instructions only from its owner; an agent placed in a group chat should be sandboxed; and a team agent should know only information that the team is authorized to access. Steinberger disputes demonstrations that ignore these recommendations or deliberately expand privileges, arguing that security evaluations should disclose the configuration and access assumptions required to produce the observed behavior. 10:50
On prompt injection, Steinberger says stronger models have improved at handling isolated untrusted material from websites or email when that content is explicitly identified as untrusted. He also acknowledges that repeated, unrestricted interaction with an agent can still create opportunities for attack. Smaller models without meaningful defensive training present a separate concern when combined with browsing or email, which is why OpenClaw warns users about small-model configurations even while continuing to support different model choices. 35:55
The discussion also raises a trust-and-reputation approach in which privileges increase as trust is established over time, while suggesting that multiple-model defenses may be worth exploring. Neither idea is presented as a completed solution. The practical limitation remains that model capability, access controls, exposure to untrusted inputs, and user configuration all interact, so no single safeguard resolves every form of agent risk. 35:55
Suggest correction
This note stays in this page until you copy or download it. Nothing is submitted; reloading clears the draft.
Personal agents should preserve user control and adapt to their environment
A major motivation behind OpenClaw is data control. Steinberger contrasts a personal agent that keeps its user’s information under local control with hosted services that receive broad access through connectors such as Gmail. His preferred arrangement allows limited information to reach a higher-capability model when necessary, while preserving the possibility of local or alternative models and avoiding unnecessary dependence on a single provider. 19:40
He also argues that a user-operated agent can interact with services available to that user even when formal integrations are difficult for startups to obtain. This creates room for more flexible automation, but the transcript does not establish that such access is universally available, compliant with every service’s rules, or free of security tradeoffs. What Steinberger does establish is his preference for software that operates from the user’s existing access rather than requiring every useful workflow to depend on an enterprise connector. 23:03
The longer-term product vision is ubiquitous, context-aware interaction rather than a chatbot confined to a phone. Steinberger describes speaking to an agent from any room, allowing it to identify a nearby display and use the Canvas feature when a visual response would help, and eventually interacting through devices such as glasses. He further imagines separate personal and workplace agents communicating under arrangements acceptable to both the individual and the employer, leaving the concrete trust and authorization mechanisms as future work. 33:27
Personalization matters because an agent participates in social environments rather than merely returning search results. Steinberger says an early WhatsApp integration felt wrong because its responses were too verbose and stylistically unlike messages from friends. That mismatch led him to iterate on personality and writing style, illustrating that the appropriate behavior of an agent depends on the communication channel and the expectations of the person using it. 29:00
Suggest correction
This note stays in this page until you copy or download it. Nothing is submitted; reloading clears the draft.
Automation increases the importance of taste, iteration, and system design
Steinberger describes running as many as roughly ten coding-agent sessions when model responses were slower, later reducing that to approximately five or six as execution improved. He frames this parallel-agent workflow as a response to waiting time rather than an ideal permanent way to build software: faster model output should reduce the need to keep many independent loops active simultaneously. Productivity here comes from shortening feedback cycles, not simply maximizing the number of agents. 24:03
He rejects the strongest version of a dark factory approach when it assumes that a complete product can be specified upfront and then built without continued human involvement. His preferred process is iterative: build part of the system, use it, notice what feels wrong, and revise the next prompt accordingly. Automated pipelines can help with bounded tasks, but automatically accepting contributions risks pulling a product in conflicting directions because an agent does not reliably understand which changes serve the project’s broader vision. 26:32
For Steinberger, taste begins with recognizing generic, impersonal, or obviously machine-produced writing and interface patterns, then extends to small product details that create a more distinctive experience. He connects that judgment to playful behavior in OpenClaw and to the careful adaptation of agent personality for messaging contexts. As more implementation work becomes automatable, the human contribution shifts toward identifying subtle quality differences and deciding which details are worth preserving. 27:48
The architectural counterpart is a move from a sprawling codebase toward extensions and plugins. Steinberger says memory, a wiki, Dreaming, and other capabilities can be installed or replaced independently rather than forcing every experiment into the overloaded core contribution process. He describes Dreaming as an early attempt to reconcile session logs and memories, while emphasizing that system design, asking the right questions, and declining unnecessary features remain essential because individually plausible changes can combine into an incoherent, difficult-to-maintain system. 37:58
Implement part of the product
Product decisions improve through repeated building, evaluation, discovery, and prompt revision.
Suggest correction
This note stays in this page until you copy or download it. Nothing is submitted; reloading clears the draft.
Further Sections
The above paragraph also cites the full architecture and maintainability context. 39:56
Generated transcript labels and wording have not received a full line-by-line editorial review, so technical claims should be interpreted in the context of the supplied discussion and its stated limitations. 3:42
Suggest correction
This note stays in this page until you copy or download it. Nothing is submitted; reloading clears the draft.
Read the complete timestamped transcript
- 0:00
[upbeat music] Our next presenter is the creator of OpenClaw, the world's fastest-growing open source AI.
- 0:22
He recently joined OpenAI to work on bringing agents to everyone. Please join me in welcoming to the stage Peter Steinberger. [upbeat music] [audience cheering] [audience applauding]
- 0:52
Good morning, everyone. [cheering] [applauding] So Swyx asked me to do a state of the Claw.
- 1:01
Who here is running OpenClaw? Give me some hands.
- 1:05
Oh, it's like thirty, forty percent. Very good. Um, yeah.
- 1:12
It's been quite a we- few months. Um, the project is now five months old.
- 1:20
I think it's fair to say by now that we are the fastest-growing project in GitHub's history. Uh, if you've seen the, the graph, usually it's some, some projects look like a hockey stick, but ours was just like a straight line, and a friend called it stripper pole.
- 1:35
Gross. [laughing] And that comes with its own challenges. So we have--
- 1:41
I think by now we are the, the largest number on GitHub stars. There's a few that are bigger, but they're basically an educational target. No other software project is that big.
- 1:51
It's around thirty thousand commits. It-- we're closing in two thousand contributors.
- 1:58
Soon to be thirty thousand PRs. Um, let's see. And we're not slowing down. So you see that it-it's a ramp, but you know, it's, we only have April nine, so, um,
- 2:15
velocity keeps, keeps being good. And at the same time,
- 2:23
it hasn't been easy. You know, I, I had two roads when I, when I decided what I wanna do, and I, I did the whole company thing. I was like, "I don't wanna do this again."
- 2:33
And then I joined OpenAI, but then we also created the OpenClaw Foundation, and now I kinda have two jobs. And running the foundation is like a co-- running a company on hard mode 'cause you have, like, all the, all the things that you need to take care of, but also you have a lot of volunteers that you
- 2:49
can't really direct. So one of my goals has been working on the, on the bus factor, like who does commits. Um, and you see that it's slowly improving.
- 3:04
Vincent's actually talking after me. But we're still not, we're still not there.
- 3:10
Um, in the last months, I, I talked to a lot of companies.
- 3:16
So we now have people from NVIDIA on board. We have someone from Microsoft on board to, like, help with MS Teams with, like, a Windows app. Uh, we have someone from Red Hat who's really helping us, um, with security and dockerization.
- 3:30
We work with a lot of [REDACTED:origin] companies. We have people from, from Tencent and ByteDance. Um, they're actually much larger users than any other continent.
- 3:42
And we have people from pretty much around the world. But, like, the main thing I, I wanna, like, talk a little bit about is about OpenClaw is so insecure.
- 3:50
You know, you've, you've seen the, you've seen the memes of, like, OpenClaw invites the bad guys. [laughing]
- 3:59
And you've probably also seen companies like NVIDIA doing NemoClaw and, like, everyone is the lobsters.
- 4:13
So you also noticed that, like, in the last two, three months, there's been a lot of releases where things broke. I've basically been, been DDoS-ed by security advisories, so that's what I did, um, what I focused on.
- 4:31
So far, we got one thousand one hundred and forty-two advisories. That's around sixteen point six a day. Ninety-nine are critical. Um, we published around four hundred and sixty-nine, and we closed sixty percent of them.
- 4:47
So these numbers sound, like, absolutely terrifying. If you compare it, for example, to, like, other large projects, like the Linux kernel gets, like, eight or nine a day. We get, like, twice as much.
- 4:59
And curl so far has six hundred reports. We have, like, twice as much as curl.
- 5:07
So every time I, I get a security incident, the rule is the higher, the higher they are screaming how critical they are, the more likely it's slop.
- 5:20
Like, we, we are-- I mean, you've probably also seen the news. Like, we're, we are, we are very fast moving into a world where
- 5:29
we have to change how we build software because all these AI tools are getting so good at identifying
- 5:37
even the most weird multi-chained exploits and, like, we're gonna, gonna break all the software that exists. I'll give you an example. Like,
- 5:46
uh, NVIDIA, they, they launched NemoClaw, and NemoClaw is a, a plugin and a security layer for OpenClaw. You're saying to put it in, in a sandbox.
- 5:57
Uh, the keynote was on Monday. They invited me on Sunday to, like, work with them. I hooked it up to Codex Security. It found like five different ways how to break out of the, of their secure sandbox within half an hour.
- 6:11
Uh, and that's because, like, if you use that product, you get access to the un-nerfed model that is quite a bit smarter in terms of cyber than what the public has access, exactly because it's dangerous.
- 6:27
But yeah, um, also this whole industry, those people, for them it's like credits, right? The more, the more issues they find, the more they are seen. So like OpenClaw was like the insecure product that everybody tried to break, so literally like hundreds of people firing up their Clankers trying to break OpenClaw.
- 6:49
Um, the typical attack surface is like remote code execution, bypass approval, code injection, path traversal.
- 7:04
Uh, again, s- sounds all very dangerous. And I give you, I give you one, one concrete example. Um,
- 7:14
GHSA4JJP. This is about a... This has a CVSS of 10, so it's like the scariest thing that you can possibly do.
- 7:25
It is an issue where if you, uh, sync, for example, the iPhone app that we haven't even shipped yet but is in progress, and you give it only read permission, then you could like break the system to also get write permission.
- 7:43
So this, this one was so critical that the... Oh, no, this one's actually a different one.
- 7:50
In all, in all practical ways, it is not even an incident because the, the, the typical use case is you install it on your machine,
- 8:01
either in a cloud or if you have to, on a Mac mini. I s- I stopped fighting this. I'm just letting people have fun now.
- 8:10
But in 99%, 99% of cases, you either have access to your gateway or you have not access to the gateway. In, in, in my defense, this was my mistake that I tried to create a, a more permissive model.
- 8:24
For example, if you have devices that would target speech and then would only like read certain things, so there's like some use case where you could like have a, a reduced permission system would make sense.
- 8:36
Um, but nobody's even using that. But this doesn't matter because the rules of the, of those s- how you create the CVSS numbers don't contribute to that at all, and I try to play by the rules, so it is a 10 out of 10, and the world's going crazy over incidents that in all practical ways will not
- 8:56
affect people. There are some other stuff that does affect people. Uh, we have nation states trying to like hack people. There was like [REDACTED:username], which is like from, likely from North Korea, which is basically confusing people with a different NBN package, and if you, if you go to a wrong website and you try to download it, you
- 9:17
get like a, a, a rootkit. Um, that's outside of our control. This happens to other people as well. Um,
- 9:25
also there's the Axios thing, which funny enough, we are not using Axios, but we are using MS Teams or Slack as a dependency, and they're using Axios, and they didn't pin it.
- 9:39
And of course, uh, because that's how supply chain attacks work, we were also affected.
- 9:48
Yeah. How do you survive 1,142? I'm sure by now it's 1,150. Uh, for a while I, I, I tried to handle it all by myself, and which is absolutely impossible.
- 10:01
So, so the fastest way to get help was like getting, getting help from companies. Um, and NVIDIA has been really amazing to like give us some people that basically work full-time going through the slop a- a- and hardening the code base.
- 10:22
Oh, yeah, uh, there's also, uh, uh, one that is...
- 10:28
Okay. That, um, this is one of the angles. The other angle is like there's a lot of companies that do fear-mongering, and it's not just companies, it's also universities.
- 10:43
I don't know if you've seen it. There was like this, um,
- 10:47
paper who made the rounds, Agents of Chaos. And they say, "Oh, it's, it's about agents in general," but then there's four pages that explain the OpenClaw architecture in utmost detail.
- 10:59
But you know which page they didn't even mention?
- 11:02
The security page where we explain how you should install it, because then it wouldn't be fun. Then it wouldn't be... It would be hard to make a good story.
- 11:11
So what they instead did is they ignored
- 11:15
all of the recommendations we do on security. Recommendation is it's your personal agent. Don't put it in a group chat. If you put it in a group chat, turn on sandboxing, because if anyone can talk to your agent, they can exfiltrate anything that the agent can do, right?
- 11:32
So if it's a team agent, it should only know what the team can know and not any secret data, and you probably wanna like have it restricted. If it's your personal agent, you should be the only one being able to talk to it.
- 11:43
But if you don't play by these rules, you can get some really fun interactions like, "Hey, I can talk to your agent, and it can break your system." And then because I wa- I was p- I was grilling them a little bit because I had some questions how they do things.
- 11:55
They told me, "Oh yeah, no, we run it in sudo mode because we wanted the agent to be like maximum powerful." So they actually fought the setup. It's actually not easy to run it in sudo mode.
- 12:05
You have to change code. Um- But they didn't mention it in the report because, again, that wouldn't give them clout.
- 12:18
So yeah, um, my current frustration is, like, there's, like, a whole industry that tried to put the product in a negative light. It's a nightmare. It's insecure by default.
- 12:30
It's unacceptable. Um, and meanwhile, a lot of people love it, uh, and people who actually
- 12:38
read the security docs, understand it, can use it just fine. One, one example that I found particularly great is, uh, we had one remote-- one RCE that panicked Belgium.
- 12:50
So the Belgium cybersecurity did a release, uh, about a remote execution environment.
- 13:00
And the whole bug was a feature where a malicious website could create a link
- 13:11
that would trigger the gateway and then forward your gateway token. Now, if you use the setup that is the default and that is recommended, the gateway token is local only, or if you have to, it's in your private network.
- 13:28
No external website can actually access it. If you
- 13:33
actively fight the setup, for example, you use Claude Code to set it up without reading, you might be able to get this setup working. But again,
- 13:43
that's not anything what's, what's said on the website.
- 13:49
So to be very honest, yes, there's absolutely,
- 13:54
uh, risk. The, the, the big risk is the, the,
- 14:02
basically the lethal trifecta. You know, any, any agentic system that has access to your data,
- 14:10
has access to untrusted content, and the ability to communicate is something that's potentially at risk. That's not anything special to OpenClaw. That's like any, any agent, any powerful agent system has that problem.
- 14:25
The more, the more powerful you make it, the more it can do for you, but the more you also have to understand what it does. So this is, like, the, the main issue. [laughing]
- 14:40
But people not talking about this. Yeah, and then also,
- 14:44
um, some part about maintaining. So the problem is, like, if you get all those security advisories,
- 14:57
you know that most of them are created with agents, but you still have to use your brain to actually read it because we're not yet at the point where you can fully trust.
- 15:06
Or I, I'm not at the point where I, I c- I can just fully trust that the agent will figure it out. So it is a huge burden on, on time, and you never kn- I mean, sometimes you can, you can often guess.
- 15:17
You know, anytime the report is too nice or, like, someone apologizes, that's very likely AI because usually people in security don't apologize. [laughing]
- 15:28
Um, but it is a huge problem, and it's something that I see more and more open source projects complaining about or, like, breaking. Um,
- 15:37
some are very public about it, like FFmpeg.
- 15:41
Usually, you get the report. It's very rare that you actually get a report and a fix. If you get the report and a fix, it's usually a very bad fix.
- 15:51
If you rush it, as I sometimes did in the beginning because there was a lot, you will very certainly break your product.
- 16:05
Yeah. So this is something that's just very difficult to pull up only with volunteers. So we-- So
- 16:12
what I've been working on. Number one is
- 16:17
I-- Why people say, like, OpenAI bought OpenClaw, that's not the truth. They might bought my soul, though, indeed. Um, but they very much understand that in order for... What the world needs is, like, more people that play with AI to, like, understand what AI can do, to both understand the risk and also the possibilities.
- 16:39
They understand that if you are, like, someone who never played with, never used AI, suddenly is at home and uses OpenClaw, they'll come to work, and they will ask, "Why don't we have AI at work?"
- 16:52
So they very much understand that, like, supporting this project is very useful, and in order for that project to be successful, it cannot be under one company. Therefore, I'm kind of building Switzerland with the OpenClaw Foundation.
- 17:05
And I have Dave who's helping me with it. Um, it's almost done. The last thing that's keeping us going is, like, the [REDACTED:origin] bank system. It's just a little bit slow and very confused when you're not [REDACTED:origin].
- 17:16
Um, it's inspired by what Ghostty did, and this will actually then help us to hire full-time people to
- 17:25
both keep up the pace, improve the quality, and free up some of my time that I can work on, on cool stuff again.
- 17:37
And that's my little update on state of the Claw. I'll be around later for, like, a Q&A. Thank you for listening. [applauding] [cheering]
- 17:46
Okay. Great. Thank you for the whoop. Love the whoop. Um, so excellent. Okay, you've chosen the Claw, uh, track to get started on for our, our breakouts, and, uh, uh, it's gonna be great, I think.
- 18:00
I think it's gonna be, it's gonna be a good session. Um, we are gonna be hearing about a bunch of different things, uh, related to, uh, OpenClaw and just personal AI assistants in general.
- 18:11
There's some, uh, OpenClaw contributors, OpenClaw maintainers, uh, um, uh, OpenClaw competitors, uh, and OpenClaw creators. Uh, gonna be here on the stage. Um, we're actually going to, uh, be taking this through until the lunch break.
- 18:26
Um, oh, there we go. We can see up there. So it's about, uh, an hour and a half of, uh, of, of sessions. Slightly shorter sessions than, uh, than earlier, I think.
- 18:34
Um, but we're gonna be starting with, uh, an AMA. I mean, you saw Peter earlier on, but you're gonna get a chance to ask questions, and there's gonna be a bit of a conversation, uh, with Peter and Swyx.
- 18:43
So I think to get us started, I will simply, uh, invite Swyx up, who will kick things off. So, uh, please welcome him to the stage. Swyx, come on up.
- 18:52
Swyx. [audience applauding]
- 18:57
All right. Actually, we can just go out together.
- 18:59
You can come out together.
- 19:00
Yeah.
- 19:00
There's no secret.
- 19:01
Hi.
- 19:01
Peter, welcome.
- 19:02
Peter Steinberger, everybody.
- 19:02
Okay.
- 19:03
There he is. [laughs]
- 19:07
Okay. So the deal for this is meant to be an AMA. Uh, the, the main idea is that I've run six of these AI Engineers, and whenever we have some big maintainer, big VIP, we only give them a talk.
- 19:20
But actually, you guys have questions that you want to ask. Uh, so, uh, we wanted to sort of create that opportunity. So you can, you can submit there. I'm gonna moderate, uh, and, and all that.
- 19:28
Uh, the spicy one I'm just gonna start off with. Pete just quote, uh, quote tweeted, uh, me and saying, "Send all your questions about Closed Claw," right? Uh. [laughs]
- 19:39
Closed Claw.
- 19:40
Uh, I think, uh, people have a lot of questions about, um, the future of OpenClaw at OpenAI. Uh, and uh, I wanted to give you the space. What, what is the-- what are people saying about Closed Claw, and then what is your response?
- 19:53
I didn't even think about it. It was like it came up when, when
- 19:58
I decided to go to O- to OpenAI. And
- 20:02
I think, I think people have a point that
- 20:06
OpenAI wasn't always amazing with open source. And I th- I think a, a lot changed, like Codex is open source now. They released Symphony, which is a really cool orchestration layer.
- 20:16
So like, like they're really leaning in and understanding open source now. They understand that OpenClaw needs to stay open, work with any model, be it, be it one of the, the, the big companies or being a local model.
- 20:31
Um, everybody in the industry wins if more people spend time with AI. You know, if, if I'm-- if I think AI is something scary, and then suddenly I, I, I play with OpenClaw and suddenly it's like fun and weird, and then I come to work and there's no-- like, I don't have AI tools at work, I'm gonna
- 20:51
get to my boss and say, "Why the F do we not have AI at work?" And, and then like, those companies will probably not run OpenClaw, but will run something that's like hosted and managed.
- 21:02
And, and then somebody can, can make a sale. So they, they're like very much on board. They provide me with resources. Um, actually it's, it's me. Like, I could get a lot more people from OpenAI to help with the project, but that would just make a picture that they could have taken over the project, and I don't
- 21:20
want that. So I, I, I brought in people from NVIDIA. We have someone from Microsoft, someone from Telegram, someone from Salesforce of all the companies. So, so shout out.
- 21:29
Actually, there's cool people at Slack. Uh, so we have someone that maintains the Slack plugin now. I brought Tencent on board, ByteDance. We talked to Alibaba, MiniMax, Kimi, like all the, all the model providers.
- 21:42
They're like very much on board. Um, NVIDIA has been immensely helpful. They...
- 21:50
I think are one of the coolest companies in terms of here are some engineers who actually like just high agency and just do things.
- 21:56
Yeah.
- 21:56
Uh, and now that I have all the other companies, I'm also bringing a few people in from OpenAI to, to help maintain the project. 'Cause it's-- I mean, software is just like changing.
- 22:06
The, the, the pace at which this project operates is, is insane. [laughs] You kind of like, you need an army. Um, and I'm working on that.
- 22:16
You have an army, uh, in, but, but you know, even the contributor chart that you showed, uh, shows that it's hard to get quality contributors to stick around. People keep hiring your maintainers, and then you have to find new ones. [laughs]
- 22:28
Um, so there's a lot of questions about local models and open models. Uh, you know, like not every part of the stack is open. There's many models where you don't have access to the models and, and, you know, there's sort of weird restrictions.
- 22:41
Um, how important is open and local models to the future of OpenClaw?
- 22:46
I mean, part of, part of what, what motivated me to build OpenClaw is you see all these large companies, and then they have connectors to my Gmail, and then my, my email is hosted somewhere, then this company has full access to my email, and then I can get a little bit done there.
- 23:03
Like, it's much more exciting to me if I have all my data actually under my control and I-- and like a little bit of it goes up there if I need the top-tier token.
- 23:13
Yeah.
- 23:13
Um-
- 23:14
Like a second kind of hierarchy of, uh, fallback models.
- 23:17
Yeah. You wanna, you-- I mean, I'm, I'm [REDACTED:origin] at heart. You wanna own your data, you know? So, so, so... And nobody built it. So for me, that was very attractive.
- 23:24
And also the, the fact that, you know, if, if you're a startup and you wanna connect to Gmail, it takes like half a year, and it's like a very, very difficult process.
- 23:35
But if I'm a consumer, my Clanker, I can click on any website, and it happily clicks on "I'm not a bot." Uh, y- if-- you have to give me the data somehow.
- 23:44
If you can-- if you give me the data, my, my agent is able to get the data. So you can work around a lot of those, those silos those big companies are building.
- 23:53
And ultimately, you can do much cooler automation use cases that large companies can never do.
- 23:58
Yeah.
- 23:58
So it's, it's like, it's a little bit the, the hacker way.
- 24:03
Yeah. And, um, uh, any indications from the OpenAI team on gpt-oss? Uh, is, is that continuing, continuing to be a s- stream of work that, uh, will be aligned with OpenClaw, or, uh, or is that like separate?
- 24:18
I'm not, I'm not in a position to give-
- 24:20
Yeah
- 24:20
... give you insights on that. Just that-
- 24:23
Um, part of it Open, OpenClaw triggered is that like more people in the company are getting excited about open source. Um, and I, I love that, that OpenAI is moving more into the open direction again.
- 24:38
If you compare it to some other top-tier labs that start with an A, uh, that very much will sue you if you, if you leak any of their source- [laughs]
- 24:48
... um, or block you if you are too successful.
- 24:52
I, I, I think OpenAI is in a, on a good direction.
- 24:54
Yeah. Okay, I want to highlight this question. Um, people love hearing about your coding workflow. I think r- by now your idea of, um, uh, the prompt request rather than the pull request is, is very well socialized.
- 25:09
And also you've been shocking people with just how you're spending tokens at OpenAI. [laughs]
- 25:14
Uh, so basically, uh, the, uh, people wanna know how you ship, and what do you do about agent waiting times. Like why is, you know, you, you're spinning up so many agents.
- 25:24
It can-
- 25:24
I, I, I know. Like I, I never imagined that this one picture of me would blow up so much.
- 25:29
Yeah.
- 25:29
Actually-
- 25:30
Uh, give, give some numbers just, just to align people
- 25:32
... I, I think, um, and there's times where I, I was running almost 10 sessions at the same time. [laughs] Especially when I used Codex with 5.0, 5.1. It was quite slow.
- 25:44
I think ... Now I have to say we. It's so weird. We, uh, made improvements to both make it faster, and then there's also fast mode. So by now my typical workflow is
- 25:57
maybe half of that, maybe five, six windows instead of double, just because each loop is faster and like the
- 26:04
area of work I sync in in Workers is pretty much the same. So I, I don't have to use split screen so much anymore. And I think we're gonna move into a future where,
- 26:14
um, token will be, will be faster and faster. So at, at some point ... Like, like this is not natural that you work on, on, on six things at the same time.
- 26:24
Um, but it, it's basically a workaround until, until tokens are faster.
- 26:32
Yeah. Uh, one of my, uh, interesting things of putting you next to Ryan was to see how the two of you kind of approach, uh, token maxing basically. I'm curious what you think about the, the complete dark factory approach, right?
- 26:46
That, uh, you don't even review code that goes in.
- 26:53
I think that's more and more doable, but also, you know, when I, when I
- 27:00
... Dark factory in a way also means I come up with everything I wanna build in the beginning, and I just don't think you can build good software in that way.
- 27:09
Like, the way to the mountain is usually never a straight line. It is, it is, it is very curved. Sometimes you go a little bit off track, and then you, you see something new that inspires you.
- 27:20
You find like shortcuts. Um, once you're at the top, you, you, you can find the optimal path, but you never walk like this. So at the same time, you will ...
- 27:30
The first idea that you have about a project is very unlikely gonna be the final project. But if I, if I suddenly use the waterfall model again, that will be the final project.
- 27:41
For me, that doesn't work for me. Like, I, I build steps. I play with it. I see how it feels. I get new ideas. My prompts change. So to me, it's a very iterative approach, so I don't see how you could fully automate that.
- 27:54
You can definitely build pipelines for certain things.
- 27:57
Yeah.
- 27:58
But e- even, even for PRs, you don't just wanna build a pipeline that just merges PRs, because a lot of them just don't make sense. You know? Like, people, people will pull your product into all kind of directions.
- 28:09
But if you automate that, the AI will very unlikely know what's the right direction. You can guide it. I have like a vision document that I tried some of that, but
- 28:21
the bottleneck is still thinking. And like having taste. [laughs]
- 28:27
Yeah, taste is very important. Uh, how do you define taste? This is something that in my conversations with people everyone understands taste is the moat, but nobody agrees on what taste, good taste is.
- 28:38
So I'm just curious to hear yours.
- 28:40
I think in this day and age it's like
- 28:43
the very low level of taste is if it doesn't stink like AI. And you know exactly what I mean. You know if, if something is just-
- 28:50
So writing style, personality?
- 28:52
Also, also, also UI. By now you've seen so many, so much agentic built UI that you immediately know if it's AI.
- 29:00
Yeah, yeah. If it has the, the color border on the left, right?
- 29:03
Yeah, yeah. I mean, for a while it was like the purple gradient. But, uh, uh, much more so I, I feel it's,
- 29:09
it's like a feeling. Uh, the same that as you can identify AI written slop right away.
- 29:16
Yeah.
- 29:17
Um, that's why I say it's a smell. Like even if you can't pinpoint it, you will know. So, so that's probably the lowest, the lowest characterization of taste. And then, and then going higher up, because now so much of software is, is automatable, there's actually much more time you can spend on like the little details.
- 29:36
I know. You know, like, like just when you, when you, when you, when you run OpenClaw you get like a little message, uh, that sometimes roasts people. [laughs] That, that, those are like the delightful details I think-
- 29:48
Yeah
- 29:48
... that you'll just not get if you prompt in a high level.
- 29:52
Yeah. One, one of my favorite tastes of yours is how you, you, uh, really put a lot of work into your soul, SOUL.md, and you, uh, you know, open sourced your approach.
- 30:01
And I don't think people worked on enough soul until, until you came along. So I think that's really interesting. Uh, my ... I, I have a podcast I haven't done yet, I haven't released yet, with, uh, Mikhail Parakhin who is the CTO of Shopify now.
- 30:14
But he was the, uh, [REDACTED:gender] leading Bing where Sydney was, uh, the original sort of unaligned chatbot [laughs] that emerged. Uh, but I, I think people really have fun when, when your Sol, your chatbot has personality.
- 30:27
Your, your Clanker, uh, you know, has different obsessions.
- 30:31
Well, it was because it, the world changed, right? We had, we had ChatGPT in 2023 and '4, and it was basically
- 30:43
us having AI without understanding what AI can do, so we rebuilt a Google. So you have like a search field, and like you get a response. And you, you don't expect Google to have a personality.
- 30:54
Yeah.
- 30:54
But now that we moved more towards agents. Like if, if I ... I didn't think about in the beginning about WhatsApp Relay, and I just hooked it up to Claude Code.
- 31:05
Um, and then I, when I was on WhatsApp, I noticed that it doesn't feel quite right. Like even, even though like Claude Code already has some personality, it didn't really fit how people would write to you on WhatsApp.
- 31:18
So that, that's how my whole iteration started, was like, uh, this ... A- a- again, it's about taste, right? It doesn't feel quite right. It's like too wordy. It uses too many dots.
- 31:26
It, it, it ... My friends text different, and th- that's how I started working. They say, "No, this isn't..." Like, try to write more like a human. [laughs]
- 31:36
Uh, yeah. I, I actually run a writing, uh-
- 31:38
Like a lobster
- 31:39
... uh, like a lobster, yes. Um, uh, uh, uh, you know, the, one of my favorite quotes of yours is, uh, "Madness with a touch of sci- science fiction."
- 31:48
Yeah.
- 31:49
Right? Like that this is how you run, um, uh, AI projects. And I think-
- 31:54
N- not all AI projects, but specifically something like OpenClaw would have never been able ... It would not have come out of an [REDACTED:origin] company just because it would have been killed in legal long before it would have been released.
- 32:08
'Cause it just has some problems that we haven't really solved as an industry yet.
- 32:13
Yeah.
- 32:13
But now we, we have some mitigations and it's getting better. The models are getting a lot better. But I don't see
- 32:21
how any of the big labs could have released that. You know, there would be too much pushback, uh, a- and like not enough market proof that this is what people want.
- 32:30
Yeah.
- 32:30
So like it had to be done with someone-
- 32:35
Like you
- 32:36
... outside.
- 32:36
Yeah.
- 32:36
Yeah. That, that, that-
- 32:38
Sitting in your house
- 32:38
... like literally like when I, when I built it in the very beginning, I was like, oh, what's the worst that can happen? Like it could exfiltrate my token,
- 32:47
my emails. Yeah, nothing is, nothing, nothing's in there that would like completely kill me. It could like upload some of my pictures. I was like, uh, I guess the worst already online if you use Grindr.
- 32:58
Um- [laughs] So it was like, it was like,
- 33:03
okay, I, I can live with that risk. It would be uncomfortable, but it's like i- i- it's manageable.
- 33:07
Yeah.
- 33:08
Uh, if you're a company, it's very different. It, it requires a little different approach.
- 33:12
Yeah. By the way, uh, his Instagram account, good follow. Under- under-followed. [laughs]
- 33:18
It's also, it also has some good stuff. Um, okay, uh, you were talking about WhatsApp, talking about Telegram, a lo- a lot of these text apps. Um, uh, text apps are good.
- 33:27
People are also looking for like the next form factor. People want like the, maybe the, the glasses, the earbuds. What, what is your sort of wish list in terms of having agents in your life?
- 33:42
I started on that actually already, but then I was just getting bogged down by
- 33:48
all the people using it and just like
- 33:53
the daily grind. But if you're at home, I wanna be in any room. And you know at Star Trek when you can, when, when you say, "Computer," ping. I, I, I want, I wanna like talk to my agent where- wherever I am, and it should just be able to like respond to me.
- 34:10
It should know where I am. I have like little iPads in every room and, and my agent can use the canvas feature and project stuff on those iPads. So like if I ask a question that, that is like easier to be, to be answered by also showing me something, like it could use like the nearest display because
- 34:27
it's aware of where I am. So the phone is just a very convenient input point, but I kinda wanna like talk to it from anywhere.
- 34:36
Yeah.
- 34:36
Like, yeah, if I'm around and I have glasses, I should just like be able to like listen in and like project something on me. Um-
- 34:43
But just ubiquitous follow you everywhere.
- 34:45
I think, uh, yeah, o- once we have-
- 34:47
It's fully smart home. Yeah
- 34:49
... like agents on your phone, but really you want ubiquitous agents. And then you want maybe you will have your, your, your uppercase OpenClaw, your private agent. At work, you might have your, I don't know, lowercase openai claw.
- 35:07
And then that claw should be able to like talk to your personal claw, uh, in a way that both your company and you are comfortable with. So that's kinda like the future where we need to work out.
- 35:22
Yeah. Uh, one of ... Uh, I just did a podcast with Marc Andreessen, who's a huge fan, uh, and, and also, uh, have conversations with Andrej Karpathy. Both of these guys are running OpenClaw to run their house.
- 35:32
And I think OpenClaw for homes is like a kind of underrated, but like people are really discovering it. And my funniest sort of irony is that it's, it's only possible because the internet of shit means that most smart devices are terrible in security, which means OpenClaw can run them. [laughs]
- 35:49
Oh, it's gonna be able to be, work so much better- [laughs] ... in, in a few months when the models are getting really bad. [laughs]
- 35:55
Yeah, it's ... They're, they're very good. Um, okay, one security question, uh, uh, about prompt injection. How do you want to solve prompt injection? Or, uh, what, what, uh, ways in which, uh, have you been thinking about the prompt injection problem?
- 36:12
Probably not enough yet. Uh, on the other hand, like the, the, the frontier models are really quite good at detecting all the,
- 36:22
all the cases where like just stuff randomly comes in from a website or an email is usually not a problem anymore. You mark as untrusted content, very hard to exfiltrate data from that.
- 36:34
If- If I have unlimited access to your claw, I can bombard it with stuff, then there is still a chance-
- 36:42
You're gonna find a way. Yeah
- 36:43
... then, then there's still a chance. But like for one-off things, it's no longer the biggest problem. If you use ... That's also why, why ... You know, the, this is probably the angle where like some people say, "Oh, Peter doesn't like local models."
- 36:54
But then I see like people running like a 20, uh, billion parameter model that just does whatever you tell it and, and is not trained to have any defenses at all.
- 37:05
That's still problematic. If you run that and then you use a web browser or email, um, would worry me. That's why, that's why OpenClaw warns you if you use a small model.
- 37:17
Uh, and I know people spin a whole thing like, "He hates small model." I lo- I love, I love, I love that it, we support everything, but like you have to
- 37:26
steer the, the regular user a little bit into a direction to make it harder for them to shoot themselves in the foot.
- 37:33
Mm.
- 37:34
Um, yeah, there, there is some ideas for prompt injections. It's,
- 37:42
it's still a little bit away.
- 37:44
Yeah.
- 37:44
I have not announced it.
- 37:45
Uh, I think Simon Willison has been working a lot on, on this. I mean, he coined the term prompt injection, and the sort of dual LLM approach seems smart.
- 37:53
Uh, but and I, I'm, I'm not smart enough to figure out all the ways that, uh, which it can be attacked. Like at, at some point, trust has, has to be a thing, right?
- 38:01
Um, and uh, and I pro- There's something interesting I found out from talking with Vincent, who is speaking next, is that you guys had to implement the same trust system that Tobi Lütke had to implement, which is, uh, you build reputation over time, and things with more trust, uh, uh, gets more privileged access, right?
- 38:19
And I think that, that makes sense. [laughs]
- 38:23
That's, that's part of the story.
- 38:24
Yeah. Yeah, yeah. Um, okay. So, uh, what are some more broader questions. What cool projects would you like to work on once you have more free time?
- 38:33
I mean, I wanted to work on dreaming, and now like my maintainers worked on dreaming while I, I'm there like-
- 38:38
While you were dreaming. [laughs]
- 38:39
Uh, so like that-
- 38:40
You just shipped it, right?
- 38:41
Yes.
- 38:41
Yes.
- 38:41
Yeah.
- 38:42
What, what is dreaming?
- 38:43
Uh, it's like a way to reconcile memories a- and like kind of create a little bit like, like a dream log. Goes through like your session logs. Um, like-
- 38:53
We found, we found out from the Anthropic source code leak that they're also working on dreaming, right?
- 38:58
Oh, yeah, yeah. I mean, there's ... I'm pretty sure there's like more companies working on that. But think a little bit like how do we learn as humans? You, you experience a lot of things during the day, and then you sleep.
- 39:10
And, and in sleep your, your brain does like a, a garbage collect.
- 39:14
Converts some memo- some local, locally stored memories into long-term storage and like drops others. Uh, and that, that's similar ideas that I think could also be very useful for agents.
- 39:28
Um, and then like what we shipped on dreaming is like a first little step in that direction.
- 39:31
Yeah.
- 39:32
I mean-
- 39:32
And it's related to the wiki, uh, thing that Andrej has been talking about, where you sort of collect everything into a-
- 39:38
Wiki is, is more memory, but like everything kind of blends a little bit together. Um, the, the beauty, the beauty of OpenClaw is that we can just try stuff, you know?
- 39:47
Like, like everything ... What we worked on for the last month or so is that i-
- 39:53
in the beginning it was a big spaghetti code base mess, and now like everything, everything is an extension, a plugin. So you can replace memory, you can add the wiki, you can add dreaming, you can add, I don't know, your, your, your, your whatever crazy idea you have and just make it your own.
- 40:10
You don't have to send everything to a pull request because we are still completely overloaded on those. You ... but it's, it's more like Linux where you just can install your own parts.
- 40:20
Yeah. Yeah. Uh, and uh, you are building what a lot of people think, uh, is the most consequential open source since Linux, which ... I don't know, how do you deal with that?
- 40:30
Uh, how do you deal with the, the, the, the fame? What is a day in your life, uh, a- as, as the BDFL effectively of something like this?
- 40:40
What's my ... Well, there's, there's still a lot of coding. There's also a lot of-
- 40:44
By the way, in be, in between sessions he was coding. [laughs]
- 40:48
Back there.
- 40:49
Yeah, the token anxiety, you have to like ... Something has to be running.
- 40:51
You have to push the agents, right?
- 40:53
Yeah. Um, well, it shifted a little bit. Now it's a lot more, a lot more talking and
- 41:02
steering people in the right direction. You know, like because, uh, there's a lot of things that we already learned at OpenClaw. So like part of my role at OpenAI is like to like help them not make the same mistakes again.
- 41:13
Um, and then, and then at OpenClaw it's like try out new things that seem exciting, and some might work and some might don't work. Enable, enable companies to like build their own claw without having to fork away by like making everything more, more customizable.
- 41:30
Um, yeah, and sometimes I sleep.
- 41:32
Sometimes you sleep. Okay, great. Uh, I think that maybe this is our last ... Good co- closing questions. Uh, what skills do you want humans and engineers in particular to focus on developing in the age of AI?
- 41:48
Taste was a big one, but I already mentioned that.
- 41:53
System design is still very important.
- 41:56
Yes, you ... we talked about this in-
- 41:57
'Cause-
- 41:58
... San Francisco. Yeah
- 42:00
... if you don't think about that, you will eventually slide yourself into a corner, right? Just by defining the boundaries. Like, the funny thing is like everything is in the Clanker, but you still need to ask the right questions, otherwise ...
- 42:16
Th- that makes this the difference of like good code that comes out or like really bad code that comes out. And that's still where like all the knowledge you have of like how you build software, you can apply to steer the agent into, into something that is not slop.
- 42:31
Yeah.
- 42:31
And then I think, I think a skill that is becoming more and more important is saying no. [laughs]
- 42:38
And, and, and that's something I had to learn as well because
- 42:43
even the wildest idea is just, just a prompt away.
- 42:47
And usually this one idea is never the problem, but like this idea and this idea and this idea and this idea, and then how all of that fits together, that's the problem.
- 42:57
Yes.
- 42:57
So like I think we're still bottlenecked on thinking and about like big picture thinking.
- 43:04
Yeah.
- 43:04
Because im- imagine the world from your Clanker. Like you're being thrown into a code base. You might have an outdated AGENTS.md file, but you basically don't know what the F this is.
- 43:15
And you like ... Then like I- you tell me, "Hey, add user profiles." And you like somehow add user profiles and connect it to the two things you see, but you didn't see the whole system, right?
- 43:26
And that, that's where a lot of those localized solution comes, where like the project has like warts and, and it's our job to like help the agent do its best work by like providing them with like hints.
- 43:37
"Hey, you wanna consider this? You wanna look there? How would this interplay with this?"
- 43:41
Yeah.
- 43:41
And then, and then ultimately you get like a much ... a, a system that actually is maintainable.
- 43:46
Yeah. Um, well, thank you for maintaining one of the most important software of, of all time, and thank you for spending time with us.
- 43:52
Thanks for having me.
- 43:53
Yeah. [clapping] Hopefully you stick around to answer questions. Thank you. All right. [outro music]