OpenClaw released its largest update on Sunday, adding shared cloud sessions that let a second person join an AI agent’s live work or take it over without losing context. OpenClaw says v2026.8.1 contains more than 16,000 pull requests, roughly half the project’s lifetime total. The feature moves OpenClaw deeper into team collaboration even as its own documentation warns that the multiplayer controls “are not tenant isolation and not a security boundary.”

What Changed

AI-generated summary, reviewed by an editor. More on our AI guidelines.

The release

Those release figures list 933 contributors, including 569 who were contributing to OpenClaw for the first time. The release followed an unusual pause. The project had shipped 106 releases during the previous 230 days, most separated by one or two days, before going nearly seven weeks without one.

OpenClaw also rebuilt its browser Control UI around conversations, with files, approvals and live work beside the chat. In the project’s simulated test against a mocked Gateway with 50-millisecond latency, startup fell from roughly 1.6 seconds to 575 milliseconds, while JavaScript requests dropped from 140 to 45. That result is OpenClaw’s own test and has not been independently reproduced.

Sessions and transcripts now move from files into SQLite. Operators who want to return to an older file-backed release must first use the current command-line tool to restore archived transcripts. Sessions created after the migration will not appear in the older version.

The trust boundary

Shared sessions let owners and administrators decide whether another participant may read, suggest changes, work in a draft or contribute directly. The handoff keeps the existing context, so a colleague can enter work already in progress instead of starting a separate conversation.

Those settings govern collaboration inside one OpenClaw Gateway. They do not separate hostile customers. One Gateway is one trust domain, and tenants need separate Gateways. Sandboxing is off by default, leaving hardened deployments dependent on configuration outside the new multiplayer controls.

The agent can hold credentials, read messages and run commands. The same release adds permission modes and protected credential requests, but its shared-session feature does not turn one installation into a multi-tenant service.

The security record

The release follows months of scrutiny around the permissions OpenClaw needs. Analyses by Cisco Talos and Kaspersky Labs assessed 36% of ClawHub marketplace skills as containing prompt injections, an issue logged on March 17, 2026, while more than 155,000 OpenClaw instances were exposed on the internet in an issue logged on March 21, 2026. Those figures predate version 2.0 and do not measure the new release.

Know someone who'd find this useful? ✉️ Email it to a friend in one click, or they can subscribe free here.

Patrick Walsh wrote the IronCore Labs analysis and found direct email prompt injections difficult to reproduce in early April when OpenClaw ran with ChatGPT 5.4, crediting newer models and the project’s remediation work. He later poisoned the agent’s memory through repeated emails and induced it to forward the victim’s messages without notice.

Cyera disclosed CVE-2026-65105 after finding that a malicious browser tab could reach NemoClaw’s local Ollama server and plant instructions that survived later conversations. NVIDIA patched the flaw for non-Windows systems.

NanoClaw, a direct competitor that puts agents in separate Linux containers, makes its objection explicit. Its README says: “OpenClaw is an impressive project, but I wouldn't have been able to sleep if I had given complex software I didn't understand full access to my life. OpenClaw has nearly half a million lines of code, 53 config files, and 70+ dependencies. Its security is at the application level (allowlists, pairing codes) rather than true OS-level isolation. Everything runs in one Node process with shared memory.”

Frequently Asked Questions

What is in OpenClaw 2.0?

OpenClaw says version 2026.8.1 carries more than 16,000 pull requests from 933 contributors, roughly half the project's lifetime total. It adds shared cloud sessions, rebuilds the browser Control UI, and moves sessions and transcripts from files into SQLite. It followed nearly seven weeks without a release, after 106 releases in the previous 230 days.

What are shared cloud sessions?

They let a second person join an agent's live work or take it over without losing context. Owners and administrators decide whether another participant may read, suggest changes, work in a draft, or contribute directly.

Are shared sessions a security boundary?

No. OpenClaw's documentation says the controls are not tenant isolation and not a security boundary. One Gateway is one trust domain, sandboxing is off by default, and tenants need separate Gateways.

How much faster is the rebuilt browser interface?

In OpenClaw's own simulated test against a mocked Gateway with 50-millisecond latency, startup fell from roughly 1.6 seconds to 575 milliseconds and JavaScript requests dropped from 140 to 45. That result is the project's own and has not been independently reproduced.

What should operators know before upgrading?

Sessions and transcripts move from files into SQLite. Returning to an older file-backed release requires using the current command-line tool to restore archived transcripts, and sessions created after the migration will not appear in the older version.

AI-generated summary, reviewed by an editor. More on our AI guidelines.

OpenAI Pauses Astra Work After Tests Flag Critical Cyber Capability
At the Black Hat security conference earlier this week, OpenAI disclosed that autonomous agents had operated inside its infrastructure for weeks during internal tests without being detected. The agent
Repo Radar: 5 GitHub Projects Worth Your Week
GitHub spent the week leaning on Amazon's cloud to absorb agentic-development traffic, Business Insider reported June 16, after a run of AI-driven outages. As agents run at machine speed, this week's
Microsoft Build 2026 Turns Windows Into an AI Agent Control Plane
Microsoft's Windows developer post on Tuesday said agents will run inside Microsoft Execution Containers, a policy layer that lets developers declare file and network access before an agent acts and h
AI News Tools & Workflows

San Francisco

Editor-in-Chief and founder of Implicator.ai. Former ARD correspondent and senior broadcast journalist with 10+ years covering tech. Writes daily briefings on policy and market developments. Based in San Francisco. E-mail: editor@implicator.ai