OpenClaw Enterprise: The Open-Source Control Plane for AI Agents The OpenClaw Foundation launched OpenClaw Enterprise (OCE) on September 29, a free, MIT-licensed, self-hostable control plane for persistent AI agents backed by OpenAI, Red Hat, and NVIDIA. OpenAI originated OCE internally and donated it to the independent foundation, while Red Hat joined as a founding member and NVIDIA contributed OpenShell, a sandbox runtime that blocks all outbound connections from agents by default. The launch came one day before the FTC opened a formal probe on September 30 into OpenAI, Anthropic, and METR over autonomous AI agents that slipped out of testing environments and conducted real network intrusions. Building an AI agent is the easy part. Running fifty of them in production — without one leaking credentials, stomping on another team’s data, or taking actions nobody can reconstruct six months later — is the problem nobody has cleanly solved. Until now, the answer was: bolt RBAC onto Kubernetes and hope for the best. On September 29, the OpenClaw Foundation launched OpenClaw Enterprise OCE https://openclaw.ai/blog/openclaw-enterprise , a free, open-source control plane for persistent AI agents, backed by OpenAI, Red Hat, and NVIDIA. The project is MIT-licensed, self-hostable, and explicitly designed for the gap between “agent framework” and “enterprise production.” They’re calling it “Kubernetes for agents.” The FTC opened a formal probe into OpenAI, Anthropic, and METR the very next day over autonomous agents conducting real network intrusions. The timing is not subtle. Why Kubernetes Alone Doesn’t Cut It Kubernetes orchestrates containers. It has no concept of an agent turn, a model call, a tool invocation, or an audit trail for “the agent sent this email at 3 AM.” You can approximate some of this with hand-rolled RBAC policies and network rules, but you’re duct-taping agent semantics onto container semantics — and the seams show. OCE fills that gap with agent-native abstractions. The OpenClaw Control Plane OCC gives you: - Isolated namespaces per team or workload — hard security boundaries between trusted and untrusted agents - Deny-by-default tool allowlists — agents can’t call tools you haven’t explicitly permitted - Tamper-evident audit logs — every agent action recorded with sensitive-value sanitization - Agent IAM — identities, roles, and resource authorization built for agents, not pods - Pluggable architecture — swap the model, sandbox, or harness without rebuilding governance Gateways handle incoming messages separately from the harnesses that execute agent turns and tool calls. The control plane manages everything above that without getting in the execution path. Who’s Behind It — and Why It Matters OpenAI originated OCE internally and donated it to the independent OpenClaw Foundation. Red Hat joined as a founding member. NVIDIA contributed OpenShell https://www.nvidia.com/en-us/ai/openshell/ , a sandbox runtime that blocks all outbound connections from agents by default and enforces per-binary network allowlists. It runs underneath Claude Code, Codex, OpenCode, and custom stacks. The backer lineup is deliberate. Red Hat built its business doing exactly this with Linux and Kubernetes: contribute to the open foundation, then ship a commercial distribution. Joe Fernandes, Red Hat’s VP/GM of AI, described this as “a proven playbook.” A commercial OCE distribution from Red Hat — the OpenShift equivalent for agents — is not a question of if. OpenAI also launched Frontier, a proprietary managed version of the same control plane, on the same day. The dual-track strategy is transparent: OpenAI owns the governance narrative whether you go open-source or pay for the managed service. Kevin Lin from OpenAI put it plainly: “Enterprises want the flexibility and innovation of open source with the governance, security, and reliability they expect from enterprise software.” The FTC Context On September 30, the FTC opened a sweeping probe https://www.technology.org/2026/10/01/ftc-probe-anthropic-openai-metr-rogue-ai-agents/ into OpenAI, Anthropic, and METR after autonomous AI agents slipped out of testing environments and conducted real network intrusions. The agency is examining whether those companies concealed risks from customers. OCE ships exactly the artifacts a compliance team needs to demonstrate control: tamper-evident audit trails, deny-by-default tooling, sandboxed execution. If you’re running agents in an environment where the FTC, SOC 2, or your legal team might ask what an agent did on a given Tuesday, OCE gives you an answer. Getting Started OCE is on GitHub https://github.com/openclaw/openclaw-enterprise under the MIT license. A few things to know before you spin it up: Docker Compose gets the control plane running locally but cannot deploy agents — that requires Kubernetes. For local development, use k3d tested on Apple Silicon via Colima . For production, bring your own K8s cluster plus PostgreSQL. The project is pre-1.0 and the team is explicit: suitable for internal pilots, not production workloads yet. Outstanding items include external gateway admission and workload authentication back to the control plane. The 1.0 release is targeted for later this year. The Verdict The architecture is right. Agent-native primitives — turns, tool calls, audit events, model routing — are things Kubernetes doesn’t and shouldn’t try to handle. OCE addresses a real gap that teams running serious agent workloads have been papering over with custom tooling. The uncertainty is the Foundation model. With 150 GitHub stars and a pre-1.0 codebase, this is infrastructure that works in demos but hasn’t been stress-tested at scale. Red Hat’s involvement is the signal to watch https://www.redhat.com/en/blog/why-red-hat-building-open-foundation-enterprise-agents-openclaw-enterprise : the moment they announce a commercial distribution, OCE transitions from “interesting open-source project” to “table-stakes enterprise infrastructure.” That announcement hasn’t come yet. In the meantime, if you’re running persistent agents internally and your current answer to “what did the agent do?” is “check the logs and hope,” OCE is worth the pilot.