AI to ROI Big Story: Beyond OpenClaw - The Rise of Personal Agents
OpenClaw proved that millions of people want an always-on AI assistant running on their computer. The harder question is whether they will be allowed to use their agent at work?
The Promise & Peril of Personal AI Agents at Work
The OpenClaw Phenomenon
In November 2025, Peter Steinberger, a superstar Austrian software developer, built the first version of OpenClaw in about an hour. He called it Clawdbot. Within two months, he had renamed it twice, and there were 1.5 million active agents running on the platform. Keeping OpenClaw running was costing Steinberger up to $10,000 a month. Sam Altman called him a genius. By February 15, 2026, Steinberger had joined OpenAI to drive the next generation of personal agents.
What is OpenClaw?
OpenClaw is a self-hosted personal AI agent that runs on your Mac, Windows, or Linux machine, connects to any major AI model, and takes commands through the messaging apps you already use: WhatsApp, Telegram, iMessage, Slack, and 20 others. It runs continuously, executing shell commands, browsing the web, reading and writing files, and scheduling tasks using agents that work when you’re not there.
OpenClaw is like nothing that came before.
The Tech World Goes Bonkers – China Leads the Way
OpenClaw’s uptake was both rapid and global. Apple experienced a Mac Mini sales boomlet as techies bought dedicated machines to run it. Techies waxed poetic about the productivity gains OpenClaw could deliver. Enthusiasts in China led the way:
Baidu planned to embed OpenClaw into its main smartphone app.
Tencent hosted setup sessions in Shenzhen that drew retirees, students, and tech workers.
The Chinese market developed so much momentum that, as Steinberger told Bloomberg, the dynamic was stark: “In the US, I feel that at some companies, you get fired if you use OpenClaw. And in China, there are many companies where you get fired when you do not use OpenClaw.”
Soon after launch, it became clear that OpenClaw wasn’t built with personal or enterprise security in mind. By March 2026, the Chinese government restricted state agencies from running it on office computers. The security concerns were real.
OpenClaw Security Concerns
Security researchers sounded the alarm:
Cisco’s AI security team found a third-party skill performing data exfiltration and prompt injection without user awareness.
A Northeastern University study found agents could be manipulated into disabling their own functionality.
One of OpenClaw’s own maintainers warned that it is far too dangerous for non-technical users.
The lesson:
OpenClaw is an autonomous agent with unconstrained access to a live machine, which is simultaneously the product’s best feature and a massive built-in security risk.
The Dawn of a New Market: Personal AI Agents
OpenClaw birthed a whole new AI market segment: Personal AI Agents, also known in techie circles as “claws.”
A Personal AI Agent is not a chatbot with better UX. It runs continuously on a device, connects to an AI model, and executes multi-step tasks without waiting for human initiation. The model it connects to is the brain. The instructions around it determine what the agent can touch, remember, and do.
There are a plethora of early use cases:
Developers remotely delegate coding tasks, push commits, and resolve pull requests from their phones. Knowledge workers triage email, summarize documents, and manage calendar logistics.
Consumers use OpenClaw to order groceries, book travel, and manage household admin.
One user documented in Every.to had his agent managing nanny hours and booking date nights via iMessage.
Another runs 50 scheduled marketing analysis tasks daily at 6 AM.
In theory, the enterprise oppotunity Personal AI Agents is obvious:
An always-on agent that reduces context-switching, automates knowledge-worker repetition, and communicates across every channel in a company’s stack could deliver measurable productivity gains.
Jensen Huang said at GTC that every enterprise and software company needs an OpenClaw strategy. Note that NVIDIA announced a secure version of OpenClaw at its recent GTC 2026 conference, so, of course, he would say that.
Harrison Chase, founder of LangChain, put it more bluntly: “I guarantee that every enterprise developer out there wants to put a safe version of OpenClaw onto their computer.”
The Vendor Landscape
OpenClaw isn’t the only option when it comes to Personal AI Agents. Every major AI player has or will soon release a Personal AI Agent product. Here’s what the major AI players are up to:
NVIDIA’s NemoClaw
What it is: NemoClaw is an enterprise security wrapper around OpenClaw. It installs in a single command, adding the OpenShell runtime (kernel-level sandboxing, YAML-based policy controls, a privacy router), NVIDIA Nemotron local models, and a governance layer that defines what an agent can access, execute, and send to the cloud. Box and Cisco are launch partners:
Box uses it to enable agent workflows within enterprise file systems with human-matching permission controls.
Cisco has demonstrated a claw that autonomously responds to a zero-day vulnerability advisory in under an hour, producing a full audit trail.
Enterprise deployment: NemoClaw runs on NVIDIA RTX PCs, DGX Spark, and DGX Station. It is model agnostic but optimized for NVIDIA hardware. It became available in early preview on March 16, 2026, and is not yet production-ready.
Likely evolution: NVIDIA will push NemoClaw as the infrastructure standard beneath enterprise claws, monetizing it through hardware and inference microservices. The Nemotron Coalition, which includes Mistral AI, Perplexity, Cursor, and LangChain, is likely to build a model ecosystem around the stack.
Why it could succeed: NVIDIA is the only vendor that delivers technical elite products that serve all four enterprise AI layers simultaneously: silicon, runtime, model, and security policy. It also has a formidable partner ecosystem, including Box, Cisco, Atlassian, Salesforce, SAP, Adobe, and CrowdStrike.
Biggest blocker: OpenShell’s YAML-based policy model will require a level of operational maturity that most enterprises are still building. The head of AI governance at i-GENTIC AI told CIO magazine that NemoClaw still lacks the observability, rollback, and audit trails enterprise developers actually need. And the concentration of the stack in one vendor’s ecosystem carries platform risk.
Perplexity: Computer and Personal Computer
What it is: Perplexity has built two distinct agent products, plus an AI-native browser:
Perplexity Computer is a cloud-based multi-model orchestration system that can run more than 19 AI models simultaneously to execute long-horizon tasks.
Personal Computer runs on a dedicated Mac with 24/7 local file access, bridging cloud intelligence with local context.
Comet Enterprise is a secure, AI-native browser that acts as an automated assistant for researching, summarizing, and completing tasks across multiple web applications.
CEO Aravind Srinivas summed up the philosophy:
“A traditional operating system takes instructions; an AI operating system takes objectives.”
Enterprise deployment: Comet Enterprise provides enterprise-grade features that make deploying Personal AI Agents safer and more productive in an enterprise environment. These features include MDM deployment, admin-controlled action policies, per-domain permission controls, full audit logs, and a CrowdStrike security partnership. Computer for Enterprise is available; Personal Computer is Mac-only and in a limited preview. Pricing for Computer starts at $200 per month for Max subscribers; enterprise pricing is not publicly disclosed.
Likely evolution: Perplexity is positioning the computer not as a product but as an operating environment that orchestrates any model for any task. Its four developer APIs (Search, Agent, Embeddings, Sandbox) suggest a platform play:
Let third parties build on the same infrastructure that powers Computer.
Here’s an early example:
Samsung has given Perplexity OS-level access to power Bixby, the AI agent that runs on its new flagship phone, the Galaxy S26.
Why it could succeed: Perplexity’s offerings are model agnostic and offer real-time search, providing agents with cited, verified information that pure LLM-based agents cannot match. That’s a big differentiator.
Biggest blocker: Perplexity is valued at $21 billion, has cash in the bank, and great technology; however, it is competing against Microsoft, OpenAI, Google, and Anthropic for enterprise sales, where brand trust and existing relationships matter enormously.
Anthropic: Claude, Claude Code, and Claude Cowork
What it is: Anthropic is not building a standalone Personal AI Agent product. It is embedding agentic capability into existing products. Claude Code connects to messaging apps, including Telegram and iMessage, letting users direct coding and task automation through third-party channels. Cowork gives Claude direct control of a Mac: clicking, scrolling, navigating, and operating apps as a human would. By default, Cowork asks permission before editing files and runs in a virtual machine, reducing the attack surface for bad actors.
Enterprise deployment: The Information reported that Claude is gaining ground in enterprises because it offers comparable agentic features to OpenClaw, but with dramatically lower setup friction and better security protections. Users also report that OpenClaw usage can drive up costs through autonomous API consumption; a Claude subscription looks like a bargain by comparison. Pricing starts at $20 per month for Claude Pro and scales to $200 per month for Max. Enterprise API contracts are custom.
Likely evolution: Anthropic will continue to gain enterprise customers through direct sales and partnership relationships. Anthropic also recently signed a partnership with Microsoft to integrate Cowork into the new Microsoft 365 Copilot Wave 3 offering. Claude Cowork serves as the multi-step reasoning engine powering Copilot’s new Cowork feature (Side note: Microsoft should have tried harder on the branding – it’s very confusing). Microsoft gains access to Anthropic’s models, which provide unmatched reasoning and safety, while Anthropic gains access to Microsoft’s global customer base.
Why it could succeed: Anthropic’s approach is both low-friction and high-performance. It has built a high-trust relationship with mid-to-large-sized enterprises, and Microsoft’s distribution channel multiplies its reach at a low cost of sales.
Biggest blocker: Claude Cowork is still a “research preview” and has corrupted files in testing. Vals AI testing found it still unpredictable for sensitive tasks. Rapid enterprise adoption depends partly on Microsoft’s ability to build momentum for Copilot.
Meta / Manus and Microsoft Copilot
Meta’s Manus launched a desktop app in March 2026, targeting consumers and creators with a simpler setup than OpenClaw. Meta also acquired Moltbook, the AI social network built on OpenClaw, in March 2026, signaling its intent to build agent-to-agent infrastructure. Manus’s likely evolution is toward agent-native social experiences rather than enterprise productivity. Its biggest blocker is Meta’s persistent brand trust deficit in data handling.
Microsoft Copilot is an enterprise bet:
Maximum enterprise integration with limited user flexibility.
Here’s how it works:
Wave 3 of Microsoft 365 Copilot embeds agentic capabilities directly into Word, Excel, PowerPoint, and Outlook.
Agent 365 provides a unified governance and monitoring layer.
Copilot Studio lets non-technical employees build custom agents using natural language.
Every action inherits Microsoft 365 compliance controls, sensitivity labels, and DLP rules automatically.
Microsoft’s biggest blockers are pricing complexity and the perception that Copilot is merely a personal assistant rather than a genuine Personal AI Agent.
OpenAI Is a Wild Card
OpenAI does not yet have a flagship Personal AI Agent product, but it does have Peter Steinberger, the creator of OpenClaw, working on it. Its Codex now supports 1.6 million weekly active users, and OpenAI has publicly stated its intention to make Codex the standard agent beyond coding. Thibault Sottiaux, Codex’s product head, told Fortune that:
“There’s very little that is specific to coding” in the Codex harness.
The implication is that Codex will eventually expand beyond software engineering into general knowledge work automation.
Steinberger told Bloomberg that OpenAI’s vision is not one personal agent but a “network of collaborative specialized agents”:
A work agent and a personal claw that communicate, with policy controls governing what crosses between them.
That’s the right approach for enterprise customers. The bigger question is, when will OpenAI enter the Personal AI Agent race?
Will Personal AI Agents Ever Actually Land in the Enterprise at Scale?
The honest answer is not yet, and not as currently designed:
Security infrastructure comes first, not last. OpenClaw provides an open skill repository with no vetting. That’s a non-starter for any enterprise with a security team. NVIDIA’s NemoClaw’s OpenShell is a move in the right direction. But SDxCentral reported that most enterprises deploying Personal AI Agents today lack both behavioral baselines and adequate observability to support them. Governance must precede deployment, not follow it.
The setup needs to be simpler. OpenClaw setup requires the ability to use a Command Line Interface. Even NemoClaw requires technical expertise. Microsoft Copilot and Claude Cowork are the closest to zero-friction deployment, and they are still research previews in their most capable forms.
Data management and governance present a conundrum. The local-first architecture that makes OpenClaw appealing for privacy means data lives on individual machines, outside enterprise data management systems. The cloud-first approach that makes Copilot governable means that data leaves the device and enters the vendor's infrastructure. There is no clean solution that preserves both local-first privacy and enterprise-grade auditability. NemoClaw’s privacy router is the most credible current attempt to thread that needle.
Human-in-the-loop is essential. The Personal AI Agent model should be simple and unambiguous: Let the agent draft anything and then require human approval before it takes irreversible actions. That architecture works for individuals. Deploying it reliably across thousands of enterprise workers is a much harder product design problem.
Here’s the most likely scenario:
Personal AI Agents will become managed local tools with capabilities defined by IT policy, action permissions set by business unit leaders, model selection governed by procurement, and audit trails owned by compliance.
Think of it this way:
Your email used to be personal. Your calendar used to be personal. At first, your Slack communications seemed personal. All are now part of your enterprise’s managed infrastructure. Personal AI Agents will follow the same arc.
OpenClaw is a pioneering product. A genius built it because he saw both a personal and market need. The enterprise version of Personal AI Agents will resemble OpenClaw conceptually but deliver strong governance, security, data management, observability, and auditability features.
OpenClaw made the promise of Personal AI Agents real. Enterprise-focused AI providers - like Anthropic, Google (not in the market yet), and Microsoft - are likely to reap the rewards, proving out the old adage:
Pioneers get the arrows, and settlers get the land.
The AI to ROI Podcast
If you want to listen to the latest news in AI with more detail and analysis, Ray and Peter break down the big story of the week on the AI to ROI podcast. We also interview leaders at AI companies and in mid- to large-sized enterprises about their challenges and successes in deploying AI projects. Click here to listen or subscribe using your favorite podcasting app.










