OpenClaw has released what it describes as the largest update in its history, introducing a system-wide overhaul spanning runtime behavior, plugins, and security controls, as enterprises increasingly evaluate how such agent-based systems operate across connected environments.
“This update touches every part of OpenClaw, including installation, messaging, memory, skills, models, automations, the browser and native apps, plugins, security, and a very long tail of fixes,” the company said in a release note for version 2026.8.1.
The project said that the scope of the release expanded during development, extending beyond initial usability changes.
“We started by simplifying installation and rebuilding the browser app… but doing that properly meant carrying the cleanup through the rest of OpenClaw until it became OpenClaw 2.0,” it said in a separate blog post describing the update.
According to the post, the update was built by ‘933 contributors, including 569 first-time contributors, and is composed of over 16,000 pull requests.’
The update comes as OpenClaw deployments have drawn scrutiny from security researchers and enterprises due to the level of access the platform requires to operate.
According to the release notes, the update includes improvements to secret handling aimed at reducing the risk of unintended data exposure during agent execution, along with updates to runtime behavior and isolation mechanisms.
It also includes changes to plugin lifecycle management and controls governing how agents interact with external tools and services. These areas, including runtime, memory, and integrations, are closely linked in agent-based systems, shaping how actions are executed and controlled.
Jaishiv Prakash, director analyst at Gartner, said the release reflects a broader challenge in securing such environments.
“OpenClaw’s latest release highlights that agent security cannot be addressed separately across runtime, memory and integrations,” Prakash said. “Because these components share identity, context and authority, a weakness in one layer can compromise the entire agent workflow.”
The OpenClaw team said the scope of the update expanded as initial improvements exposed dependencies across the system.
“The increased volume and pace of work outgrew both the foundation of OpenClaw and the process we used to ship it, so we reworked both at the same time,” the project said.
As a result, updates to installation and user-facing components extended into core systems such as messaging, memory, plugins, and security, the post added.
Prakash said enterprises evaluating such platforms need to assess how controls apply across these components.
“Enterprises must evaluate whether execution, memory, credentials and connectors are protected by enforceable trust boundaries, with each agent granted only the minimum permissions required for a specific task,” he said.
This includes assessing how permissions are assigned, how actions are authorized, and whether controls are consistently applied across integrations, he added.
The update includes modifications to plugins and automations, which define how agents extend functionality and interact with external systems.
It also introduces updates to monitoring and control mechanisms governing how these components operate over time, according to the project’s blog.
Prakash said this level of integration is driving new enterprise concerns around control boundaries and visibility.
“Organizations are asking where an agent’s authority begins and ends, how agents are isolated from users and other agents, and whether consequential actions can be intercepted, attributed and reversed,” he said.
The update comes as enterprises seek clearer ways to contain agent behavior and reduce unintended access.
“This is driving demand for isolation across identity, memory, data and runtime execution, including the use of sandbox technologies to contain agent actions,” Prakash added.
The OpenClaw update does not introduce a single feature as the focal point but reflects a broader restructuring of how the platform is deployed and operated. The blog post added that the changes were required to support continued development at scale and improve system consistency.