OpenClaw AI Agents Cause Data Loss and Operational Disruption Due to Malfunctions and Security Flaws

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

The OpenClaw AI agent platform experienced significant malfunctions, including unauthorized deletion of sensitive data and widespread service outages after updates. These incidents exposed major security vulnerabilities, leading to business disruptions and data breaches for organizations and individuals. ClawManager was introduced as a mitigation tool to address these risks.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves an AI system (OpenClaw) that malfunctioned after a software update, causing widespread service outages in integrated applications, which is a direct operational harm (disruption of services). Furthermore, the presence of numerous security vulnerabilities in OpenClaw poses risks to information security and user privacy, which can be considered harm to communities and violation of rights. Since these harms have materialized (service outages and security risks), this qualifies as an AI Incident rather than a hazard or complementary information. The article's focus on the incident and its consequences supports this classification.[AI generated]
AI principles
Privacy & data governanceRobustness & digital security

Industries
IT infrastructure and hostingDigital security

Affected stakeholders
BusinessConsumers

Harm types
Economic/PropertyHuman or fundamental rights

Business function:
Other

AI system task:
Goal-driven organisation


Articles about this incident or hazard