Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

OpenClaw and shadow enterprise AI: are NHI controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 2827
Topic starter  

TL;DR: OpenClaw-style agents collapse the boundary between personal AI experiments and enterprise infrastructure, aggregating emails, files, calendars, SaaS permissions, tokens, and cloud credentials into one always-on execution plane, according to Cyera's research. The security model fails when organizations treat these agents as convenience tools instead of high-privilege non-human identities with broad, persistent reach.

NHIMG editorial — based on content published by Cyera: The OpenClaw Security Saga: How AI Adoption Outpaced Security Boundaries

By the numbers:

Questions worth separating out

Q: What breaks when an AI assistant is connected to enterprise email and cloud systems without tight scope limits?

A: The agent stops being a convenience layer and becomes a privileged identity with the ability to read, move, or export data across multiple systems.

Q: Why do AI agents complicate least-privilege governance more than normal SaaS integrations?

A: Because the agent reuses delegated permissions automatically and can combine them across content, collaboration, and cloud services in ways that are hard to predict at provisioning time.

Q: What do security teams get wrong about AI skills and plugins?

A: They often treat skills and plugins as optional add-ons instead of part of the access model.

Practitioner guidance

What's in the full article

Cyera's full research covers the operational detail this post intentionally leaves for the source:

  • The full inventory of exposed OpenClaw-style instances and the infrastructure patterns behind them.
  • The detailed skill marketplace analysis, including specific privilege requests and malicious extension behaviour.
  • The vulnerability references, proof-of-concept context, and misconfiguration examples that support the attack chain.
  • The research team's observations on how community adoption and plugin growth changed the exposure profile over time.

👉 Read Cyera's research on OpenClaw and AI agent security boundaries →

OpenClaw and shadow enterprise AI: are NHI controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 weeks ago
Posts: 1125
 

OpenClaw is a non-human identity problem before it is an application problem. The article shows an agent that accumulates delegated access, secrets, and plugin authority across collaboration systems, which is exactly how NHI risk becomes operational rather than theoretical. OWASP NHI guidance and zero trust architecture both matter here because the boundary being crossed is identity authority, not just software functionality. Practitioners should classify these agents as privileged NHIs from the point of onboarding.

A few things that frame the scale:

  • 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job, according to The 2026 Infrastructure Identity Survey.
  • Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security.

A question worth separating out:

Q: How should organisations offboard a shadow AI tool that was connected to company systems?

A: They should revoke OAuth grants, remove app registrations, rotate exposed secrets, and verify that no forwarding rules, shared tokens, or plugin permissions remain in place. Offboarding has to cover both the tool and the identity bindings it accumulated, or the agent can keep acting long after the project is abandoned.

👉 Read our full editorial: OpenClaw shows how AI agents become high-privilege NHI actors



   
ReplyQuote
Share: