OpenClaw’s rapid rise exposes ‘shadow AI’ risks in Singapore firms
The tool’s intrusive nature makes it unsuitable for use at an enterprise level, industry experts say
[SINGAPORE] Freelance software engineer Aayush Mathur was scrolling through X (formerly Twitter) when he stumbled upon OpenClaw, a new open-source artificial intelligence (AI) tool.
Curious, he put it to work by scraping Reddit for market research on an app he was building. What used to take hours – digesting documents and even podcasts – shrank into minutes. Today, about 40 per cent of his workflow runs through OpenClaw.
He told The Business Times that it has “completely changed” how he works.
Mathur is part of a growing wave of developers turning to agentic AI to boost productivity.
But the same capabilities are raising alarms.
Industry watchers warn that the rapid adoption of OpenClaw is exposing corporate networks to significant security risks, especially when deployed without clear enterprise controls.
Despite the promising productivity gains, they pointed out that the intrusive nature of OpenClaw makes it unsuitable for use at an enterprise level as it could leave firms vulnerable to malicious attacks and operational failures – especially without proper cybersecurity infrastructure.
OpenClaw, a locally run AI assistant capable of executing multi-step commands – from writing code to executing financial transactions – with minimal human oversight, was first released in November 2025 by Austrian developer Peter Steinberger.
A KPMG report noted that such autonomous AI tools could increase workforce efficiency by up to 30 per cent, and reduce operational costs by up to 25 per cent by 2027.
However, a February report by cybersecurity firm Koi Security found that there are 824 malicious “skills” found in ClawHub, the marketplace for programmes used with OpenClaw. This underscores the vulnerabilities tied to its open ecosystem.
Associate Professor Ooi Wei Tsang from the National University of Singapore’s School of Computing likened deploying OpenClaw without controls to “hiring an intern who blindly obeys instructions, but still giving the intern deep access to enterprise systems, and allowing external parties to send instructions directly”.
He noted that such malicious programmes could instruct the agent to download and install malware on computer systems.
Unlike traditional software, OpenClaw executes instructions provided by large language models or by external sources – both of which can be unreliable.
“Large language models can hallucinate and give incorrect instructions, causing OpenClaw to execute unintended or potentially destructive actions,” added Prof Ooi.
The infiltration of shadow AI
Despite the security risks associated with open-source AI agents, experts said that adoption of OpenClaw is accelerating – though driven largely by individual experimentation rather than formal corporate IT integration.
Gerry Chng, head of cyber at KPMG in Singapore, described this phenomenon as “shadow AI”, where pockets of AI usage appear outside established IT governance.
While not ill-intentioned, the adoption of such unregulated AI tools introduces blind spots in security and oversight, he said.
Anastasia Tikhonova, global threat research lead at cybersecurity firm Group-IB, noted that this mirrors past tech cycles, where adoption outpaced governance.
It seems that agentic tools are once again being adopted more quickly than enterprise security and governance models can adapt, she said.
IT operations most vulnerable
Analysts warn that enterprise IT and software development teams are the most exposed, as agentic AI tools are already being used in coding and operational workflows.
“(OpenClaw) will likely reshape knowledge work across every department, but software development and IT operations are seeing the most immediate changes,” said Gunasekharan Chellappan, co-chair of the AI, cloud and data chapter at SGTech, a trade association for Singapore’s tech industry.
Tikhonova added that while the productivity upside is real, the risks can scale quickly.
With agentic AI, review rigour might be reduced and more machine-generated output could be pushed into production pipelines with minimal validation, she said. This raises the risks of errors and vulnerabilities being deployed at scale.
To mitigate such threats, analysts recommend running AI agents in strict sandboxes, so that they operate in a separate environment away from sensitive data.
Adopting zero-trust identity architecture, where the system distinguishes between the agent and a valid user, could also help by limiting access.
To safeguard his data, Mathur runs OpenClaw on a cloud server, limiting its access to his personal device.
He also restricts the tool to read-only permissions, allowing it to access documents without making any changes.
However, Prof Ooi cautioned that such industry standards may be insufficient.
Additional safeguards – such as “preventing malicious instructions from reaching the agent, requiring human approval for high-risk actions, and validating outputs before they are used or exposed externally” – to tackle the complex security issues pertaining to agentic AI will be critical, he said.
Still, industry players expect adoption to continue among organisations, albeit in a more structured form.
For such models to scale in the long-term, Chng of KPMG said that agentic AI models will require solutions that are “secure by design”, rather than rely on security patches layered on top of open-source tools such as OpenClaw.
“As the ecosystem evolves, we expect more mature offerings to emerge – combining agentic functionality with enterprise‐grade governance, reliability and security,” he added.