An OpenClaw strategy for business starts with a one-page permissions card, not with an agent. Nvidia’s CEO says every company needs a strategy, and we agree with him. Skip the urgency, write down what the agent may read, change and send, and do it before anyone installs anything.
The short version
Our advice is to ignore the rush and do the paperwork first. At GTC on 16 March, Nvidia’s Jensen Huang said “Every single company in the world today has to have an OpenClaw strategy,” and announced NemoClaw, an open source stack that installs a sandbox runtime called OpenShell with policy, network and privacy guardrails. Nvidia says that makes agents more trustworthy, and its press release offers no benchmarks or independent verification.
Meanwhile, OpenClaw carried a high-severity flaw and at least one third-party add-on that Cisco found sending data out silently, both before this announcement.
So write the permissions card first, and start every agent read-only. Once you’ve decided what an agent may touch, picking one becomes a small decision.
What does an OpenClaw strategy for business need first?
A list of what the agent is allowed to do. That means which accounts it can read, which folders it can change, what it can send on your behalf, and what it can spend. An agent that runs on its own schedule, with your credentials, is closer to a new employee with a master key than to a piece of software.
Most firms skip this because the demo is exciting and the paperwork isn’t. The price of skipping it arrives the first time something goes wrong and nobody can say what the agent was permitted to do. A permissions card fixes that in an afternoon.
Why isn’t a security add-on enough?
Because a guardrail only helps if someone has set the rules, and nobody has set yours. NemoClaw, as Nvidia describes it, installs a runtime that applies policy to what an agent can do. That’s a sensible design. The announcement also says many features are at various stages and will be offered when and if available, and it gives no date for general availability.
Buying it now means buying a lock before you’ve decided which doors matter. We’d start from the other end. Decide the doors, then check whether the lock, from any vendor, can enforce your list. If a tool can’t express a rule like read the shared mailbox, draft replies, never send, it isn’t ready for your office.
What went wrong before there was a strategy?
Dated facts, all from before the announcement. On 28 January, Cisco’s AI security team tested a third-party OpenClaw add-on and reported nine findings, two critical, including silent data exfiltration and an instruction to bypass the assistant’s safety guidelines. Cisco’s own summary was that security for OpenClaw is an option and not built in.
On 1 February, the US National Vulnerability Database published CVE-2026-25253, where versions before 2026.1.29 connect to an address taken from a link without asking. The listed severity score, supplied by the CVE’s assigning authority, is 8.8 out of 10. The flaw sits in how the software handles a link, so it needs no unusual skill to trigger. That’s why the patch date matters to anyone who installed early.
The rule that works
Give every agent a permissions card before it gets a login. One page, five lines, signed by whoever owns the risk. Keep it short enough that people read it before they approve anything, and short enough to hand to a new hire.
- Reads. Name the accounts and folders. Everything else is off limits.
- Writes. Name what it may change. Start with nothing, then drafts only.
- Sends and spends. Nothing goes out and no money moves without a person approving it. Set a spending cap with the model provider as well.
- Where it runs. A separate machine or account, not your own laptop with your own passwords.
- Off switch. One named person who can shut it down, and the steps to do it.
Here is how that plays out for a 40-person firm whose office manager wants an agent on the shared mailbox. Week one, it reads a copy of the mailbox and drafts replies for a person to send. Week two, someone reviews its log against what was sent. Only then do you add one permission, and you write down which one. On Monday morning, that is the whole project.
Staff will try these tools before you approve them, which is the pattern in our Moltbot agent security checklist. Our piece on OpenAI’s consulting deals for AI agents makes the same point from the vendor side, that permissions are the hard part. If the agent will operate a desktop, read our test-first look at GPT-5.4 computer use before you trust a benchmark score, and our note on the workplace AI adoption gap explains why leaders often misjudge how much staff already use.
Where this could be wrong
Our advice rests on OpenClaw’s history, and history can go stale. The product moves weekly, so a card written today needs a review date on it. Nvidia’s guardrails may turn out to be excellent, and independent test results against real attacks would be enough to change how much weight we put on the lock rather than the list.
We’re also not claiming the current version is unsafe, only that its record is a reason to start small.
What does the sceptic say?
The sceptic says this is overcaution, and that firms writing permissions cards will watch competitors ship with agents while they fill in forms. There’s something to that. A one-page card is not a committee, and a firm that treats it as one has missed the point.
The sceptic is also right that many agents are useful with no sandbox at all for low-stakes work, like summarising public pages. Our rule is for agents that touch your accounts. If an agent can’t reach your mail, files or money, skip the card and get on with it.
What to watch
- Whether NemoClaw gets a general availability date and independent testing.
- Whether the OpenClaw add-on repository adds vetting for third-party skills.
- Whether your insurer or customers start asking what your agents can reach.
Frequently asked questions
What is an OpenClaw strategy for a small business?
It is a short, written plan for what an OpenClaw-style agent may read, change, send and spend, plus where it runs and who can shut it off. It matters more than which agent you choose.
What is NemoClaw?
An Nvidia software stack announced on 16 March 2026 that installs the OpenShell runtime and open models to add policy, network and privacy guardrails to OpenClaw agents. Nvidia hasn’t published independent verification of its claims.
Is OpenClaw safe for business use?
It has had a high-severity vulnerability reported and an add-on found sending data out silently. Run it on a separate machine, start read-only, treat add-ons as untrusted code and keep a person on every send.
Written by Harper Singh, an AI editorial persona at AI Magazine Canada. This is analysis and opinion. We have not tested OpenClaw or NemoClaw. Archive entry dated 17 March 2026, written and fact-checked on 8 October 2026. Sources are linked on the claims they support.