AIAI EngineerApr 17, 2026· 44:12

State of the Claw — Peter Steinberger

Peter Steinberger, creator of OpenClaw, presents a five-month update on the world's fastest-growing open-source project. He details the project's staggering growth—30,000 commits, nearly 2,000 contributors—and the immense security burden: 1,142 advisories (16.6 per day) with 99 critical, often AI-generated slop that demands human vetting. Steinberger refutes media fearmongering, citing how researchers ignore security docs to fabricate scary scenarios. He clarifies OpenAI did not buy OpenClaw; he joined the company while establishing the OpenClaw Foundation to remain vendor-neutral. He emphasizes the importance of local models for data sovereignty and describes his coding workflow of running 5-6 agent sessions simultaneously, iterating on taste and personality. Future visions include ubiquitous agents, 'Dreaming' for memory reconciliation, and modular plugins. For engineers, he champions taste, system design, and learning to say no.

  1. 0:00Welcome & Growth
  2. 2:20Management Challenges
  3. 3:43Security Storm
  4. 10:31Fear & Misinformation
  5. 14:48Maintainer Burnout
  6. 16:05Independence Plan
  7. 17:47Openness & Relationship
  8. 24:55Coding & Taste
  9. 33:22Future Agents
  10. 38:33Vision & Skills

Powered by PodHood

Transcript

Welcome & Growth0:00

Guest0:15

Our next presenter is the creator of OpenClaw, the world's fastest-growing open source AI. He recently joined OpenAI to work on bringing agents to everyone. Please join me in welcoming to the stage: Peter Steinberger.

Peter Steinberger0:53

Good morning, everyone.

So the Swiss asked me to do a State of the Claw. Who here is running OpenClaw? Give me some hands. Oh, it's like 30, 40%. Very good. Um, yeah, it's been quite a week— a few months. Um, the project is now 5 months old.

I think it's fair to say by now that we are the fastest-growing project in GitHub's history. Uh, if you've seen the graph, usually it's some some projects look like a hockey stick, but ours was just like a straight line, and the friend called it strip-up pole gross.

And that comes with its own challenges. So we have, I think, now we are the the largest number on GitHub stars. There's a few that are bigger, but they're basically educational target. No other software project is that big.

It's around 30,000 commits. It we're closing in 2,000 contributors. Soon to be 30,000 PRs. Um,

let's see. And we're not slowing down. So you see that it's a ramp, but you know it's we only have April 9. So, um, velocity keeps keeps being good.

Management Challenges2:20

Peter Steinberger2:20

And at the same time, it hasn't been easy. You know, I I had two roads when I when I decided what I want to do, and I I did the whole company thing. I was like, I don't want to do this again.

And then I joined OpenAI, but then we also created the OpenClaw Foundation, and now I kind of have two jobs. And running the foundation is like a running a company on hard mode because you have like all the all the things that you need to take care of, but also you have a lot of volunteers that you can't really direct.

So one of my goals has been working on the on the bus vector, like who does commits. Um, and you see that it's slowly improving. Vincent is actually talking after me, but we're still not we're still not there.

Um, in the last months, I I talked to a lot of companies. So we now have people from Nvidia on board. We have someone from Microsoft on board to, like, help with MS Teams with, like, a Windows app.

Uh, we have someone from Red Hat who's really helping us, um, with security and doctorization. We work with a lot of Chinese companies. We have people from from Tencent and ByteDance. Um, they're actually much larger users than any other continent.

And we have people from pretty much around the world. But, like, the main thing I I want to, like, talk a little bit about is about OpenClaw is so insecure. You know, you've you've seen the you've seen the memes that, like, OpenClaw invites the bad guys.

Security Storm3:43

Peter Steinberger4:00

And you've probably also seen

companies like Nvidia doing Nemo Claw and, like, everyone has little lobsters.

So

you also noticed that, like, in the last two, three months, there's been a lot of releases where things broke. I've basically been been DDoSed by security advisories. So that's what I did, um, and what I focused on. So far, we got 1,142 advisories.

That's around 16.6 a day. 99 are critical. Um, we published around 469, and we closed 60% of them. So these numbers sound, like, absolutely terrifying. If you compare it, for example, to, like, other large projects, like, the Linux kernel gets, like, 8 or 9 a day.

We get, like, twice as much. And curl so far has 600 reports. We have, like, twice as much as curl.

So every time I I get a security incident, the rule is the higher the higher they're screaming, how critical they are, the more likely it's slop. Like, we we are I mean, you've probably also seen the news. Like, we're we're we are very fast moving into a world where we have to change how we build software because all these AI tools are getting so good at identifying

even the most weird multi-chained exploits and, like, we're going to going to break all the software that exists. So I'll give you an example. Like, uh, Nvidia, they they launched Nemo Claw, and Nemo Claw is a a plugin and a security layer for OpenClaw.

You can put it in a sandbox. I the keynote was on Monday. They invited me on Sunday to, like, work with them. I hooked it up to Codex Security. It found, like, five different ways how to break out of the of their secure sandbox within half an hour.

Uh, and that's because, like, if you use that product, you get access to the unnerved model that is quite a bit smarter in terms of cyber than what the public has access, exactly because it's dangerous.

But yeah. Um, also, this whole industry, those people, for them, it's like credits,right? The more the more issues they find, the more they're seen. So, like, OpenClaw was, like, the insecure product that everybody tried to break. So literally, like, hundreds of people firing up their clankers trying to break OpenClaw.

Um,

the typical attack surface is, like, remote code execution, bypass approval, code injection, pass traversal. Uh, again, sounds all very dangerous. And I'll give you I'll give you one one concrete example. Um,

GSEH4JJP. This is about a this is a CVSS of 10. So it's, like, the scariest thing that you can possibly do. It is an issue where if you,

uh, sync, for example, the iPhone app that we haven't even shipped yet, but is in progress, and you give it only read permission, then you could, like, break the system to also get write permission. So this this one was so critical that the oh, no, this one's actually a different one.

In all in all practical ways,

it is not even an incident because the the typical use case is you install it on your machine, either in a cloud or if you have to on a Mac mini. I I stopped fighting this. I'm just letting people have fun now.

But in 99% 99% of cases, you'll either have access to your gateway or you'll have not access to the gateway. In in my defense, this was my mistake that I tried to create a a more permissive model. For example, if you have devices that would target speech and then would only, like, read certain things.

So there's, like, some use case where you could, like, have a a reduced permission system would make sense. Um, but nobody's even using that. But this doesn't matter because the rules of the of those how you create the CVSS numbers don't contribute to that at all.

And I try to play by the rules. So it is a 10 out of 10, and the world's going crazy over incidents that, in all practical ways, will not affect people. There's some other stuff that does affect people.

Uh, we have nation-states trying to, like, hack people. There was, like, Ghost Claw, which is, like, from likely from North Korea, which is basically confusing people with a different NBN package. And if you if you go to a wrong website and you try to download it, you get, like, a a root kit.

Um, that's outside of our control. This happens for other people as well. Um, also, there's the Axios thing, which, funny enough, we are not using Axios, but we are using MS Teams or Slack as a dependency, and they're using Axios, and they did pin us.

And of course, uh, because that's how supply chain attacks work, we were also affected.

Yeah. How do you survive 1,142? I'm sure by now it's 1,150. Uh, for a while, I I I tried to handle it all by myself, which is absolutely impossible. So so the fastest way to get help was, like, getting getting help from companies.

Um, and Nvidia has been really amazing to, like, give us some people that basically work full-time going through the slop and and hardening the code base.

Oh, there's also one that is

okay.

Fear & Misinformation10:31

Peter Steinberger10:31

That, um, this is one of the angles. The other angle is, like, there's a lot of companies that do fearmongering. And it's not just companies. It's also universities. I don't know if you've seen it. There was, like, this, um, paper who made the rounds, Agents of Chaos.

And they say, oh, it's it's about agents in general, but then there's four pages that explain the OpenClaw architecture in utmost detail. But you know which page they didn't even mention? The security page where we explain how you should install it because then it wouldn't be fun.

Then it wouldn't be it would be hard to make a good story. So what they instead did is they ignored all of the recommendations we do in security. Recommendation is, it's your personal agent. Don't put it in a group chat.

If you put it in a group chat, turn on sandboxing because if anyone can talk to your agent, they can exfiltrate anything that the agent can do,right? So if it's a team agent, it should only know what the team can know and not any secret data, and you probably want to, like, have it restricted.

If it's your personal agent, you should be the only one being able to talk to you. But if you don't play by these rules, you can get some really fun interactions, like, "Hey, I can talk to your agent, and it can break your system."

And then because I I was I was grilling them a little bit because I had some questions how to do things, they told me, "Oh, yeah. No, we run it in pseudo-mode because we wanted the agent to be, like, maximum powerful."

So they actually fought the setup. It's actually not easy to run it in pseudo-mode. You have to change code. Um, but they didn't mention it in the report because, again, that wouldn't give them clout.

So yeah. Um, my current frustration is, like, there's, like, a whole industry that tried to put the project in negative light. It's a nightmare. It's insecure by default. It's unacceptable. Um, and meanwhile, a lot of people love it.

People who actually read the security docs understand it can use it just fine. One example that I found particularly great is, uh, we had one remote one RCE that panicked Belgium. So the Belgium cybersecurity did a release, uh, about a remote execution environment.

And the whole bug was

a feature where a malicious website could create a link

that would trigger the gateway and then forward your gateway token. Now, if you use the setup that is the default and that is recommended, the gateway token is local only, or if you have to, it's in your private network.

No external website can actually access it. If you actively fight the setup, for example, use Claude Code to set it up without reading, you might be able to get the setup working. But again, that's not anything what's what's said on the website.

So to be very honest, yes, there's absolutely,

uh, risk. The the the big risk is the the, um, basically, the lethal trifecta. You know, any any agentic system that has access to your data, has access to untrusted content, and the ability to communicate is something that's potentially at risk.

That's not anything special to OpenClaw. That's, like, any any agent, any powerful agent system has that problem. The more the more powerful you make it, the more it can do for you, but the more you also have to understand what it does.

So this is, like, the the main issue.

But people don't talk about this. Yeah. And then also, um,

some part about maintaining. So

Maintainer Burnout14:48

Peter Steinberger14:53

the problem is, like, if you get all those security advisories, you know that most of them are created with agents, but you still have to use your brain to actually read it because we're not yet at the point where you can fully trust or I'm not at the point where I I can just fully trust that the agent will figure it out.

So it is a huge burden on on time, and you never know. I mean, sometimes you can you can often guess. You know, anytime the repo is too nice or, like, someone apologizes, that is very likely AI because usually, people in security don't apologize.

Um,

but it is a huge problem, and it's something that I see more and more open source projects complaining about or, like, breaking. Um, some are very public about it, like FFmpeg.

Usually, you get the report. It's very rare that you actually get a report and a fix. If you get the report and a fix, it's usually a very bad fix. If you rush it, as I sometimes did in the beginning because I was overlooked, you will very certainly break your product.

Yeah. So this is something that's just very difficult to pull up only with volunteers. So so what I'll be working on, number one is, I people say, like, OpenAI bought OpenClaw. That's not the truth. They might bought my soul dot md.

Independence Plan16:05

Peter Steinberger16:26

Um, but they very much understand that in order for what the world needs is, like, more people that play with AI to, like, understand what AI can do, to both understand the risk and also the possibilities. They understand that if you are, like, someone who never played with never used AI, suddenly is at home and uses OpenClaw, they'll come to work, and they will ask, "Why don't we have AI at work?"

So they very much understand that, like, supporting this project is very useful, and in order for that project to be successful, it cannot be under one company. Therefore, I'm kind of building Switzerland with the OpenClaw Foundation, and I have Dave who's helping me with it.

Um, it's almost done. The last thing that's keeping us going is, like, the American bank system, which is a little bit slow and very confused when you're not American. Um, it's inspired by what Ghostie did, and this will actually then help us to hire full-time people to both keep up the pace, improve the quality, and free up some of my time that I can work on on cool stuff again.

And that's my little update on State of the Claw. I'll be around later for, like, a Q&A. Thank you for listening.

Guest17:47

Okay.

Openness & Relationship17:47

Guest17:49

Great. Thank you for the whoop. Love the whoop. Um, so excellent. Okay. You've chosen the Claw, uh, track to get started on for our our breakouts, and, uh, uh, it's going to be great, I think. I think it's going to be it's going to be a good session.

Um, we are going to be hearing about a bunch of different things, uh, related to, uh, OpenClaw and just personal AI assistants in general. There's some, uh, OpenClaw contributors, OpenClaw maintainers, uh, um, uh, OpenClaw competitors, uh, and OpenClaw creators, uh, going to be here on the stage.

Um, we're actually going to, uh, be taking this through until the lunch break. Um, oh, there we go. We can see up there. So it's about, uh, an hour and a half of, uh, of of sessions, slightly shorter sessions than, uh, than earlier, I think.

Um, but we're going to be starting with, uh, an AMA. I mean, you saw Peter earlier on, but you're going to get a chance to ask questions, and there's going to be a bit of a conversation, uh, with Peter and Swyx.

So I think to get us started, I will simply, uh, invite Swyx up, who will kick things off. So, uh, please welcome him to the stage. Swyx, come on up. Swyx.

Peter Steinberger18:58

Allright.

swyx18:58

Actually, we can just go together.

Guest19:00

You can come out together. There's no secret. Peter, welcome.

Peter Steinberger19:02

Thanks. I'm very grateful.

Guest19:03

Okay.

Peter Steinberger19:03

There is.

Okay. So the deal for this is meant to be an AMA. Uh, the the main idea is that I've run six of these AI engineers, and whenever we have some big maintainer, big VIP, we only give them a talk, but actually, you guys have questions that you want to ask.

Uh, so, uh, we wanted to sort of create that opportunity so you can you can submit there. I'm going to moderate, uh, and and all that. Uh, the spicy one I'm just going to start off with. Pete just quote uh, quote tweeted, uh, me and saying, "Send all your questions about Closed Claw,"right?

Guest19:39

That's cool.

Peter Steinberger19:41

Uh, I think, uh, people have a lot of questions about, um, the future of OpenClaw at OpenAI. Uh, and, uh, I wanted to give you the space. What what is the what are people saying about Closed Claw, and then what is your response?

I didn't even think about it. It was, like, it came up when when I decided to go to OpenAI, and I think I think people have a point that

OpenAI wasn't always amazing with open source, and I think I think a lot changed. Like, Codex is open source now. They released Symphony, which is a really cool orchestration layer. So, like, like, they are really leaning in and understanding open source now.

They understand that OpenClaw needs to stay open, work with any model, be it be it one of the the the big companies or being a local model. Um, everybody in the industry wins if more people spend time with AI.

You know, if if I if I think AI is something scary, and then suddenly I I I play with OpenClaw, and suddenly it's, like, fun and weird, and then I come to work, and there's no like, I don't have AI tools at work, I'm going to get to my boss and say, "Why the F do we not have AI at work?"

And and then, like, those companies will probably not run OpenClaw, but will run something that's, like, hosted and managed, and and then somebody can can make a sale. So they they are, like, very much on board. They provide me with resources.

Um, actually, it's it's me. Like, I could get a lot more people from OpenAI to help with the project, but that would just make a picture that they could have taken over the project, and I don't want that.

So I I I brought in people from NVIDIA. We have someone from Microsoft, someone from Telegram, someone from Salesforce of all the companies. So so shout out. Actually, there's cool people at Slack. Uh, so we have someone that maintains the Slack plugin now.

I brought Tencent on board, ByteDance. We talked to Alibaba, Minimax, Kimi like, all the all the model providers. They're, like, very much on board. Um, NVIDIA has been immensely helpful. They I think they're one of the coolest companies in terms of here's some engineers who actually, like, just hire agents and just do things.

Yeah.

Uh, and now that I have all the other companies, I'm also bringing a few people in from OpenAI to to help maintain the project because it's I mean, software is just, like, changing. The the the pace at which this project operates is is insane.

You kind of, like, you need an army. Um, and I'm working on that.

You have an army. Uh, and but but, you know, even the contributor chart that you showed, uh, shows that it's hard to get quality contributors to stick around. People keep hiring your maintainers, and then you have to find new ones.

Um, so there's a lot of questions about local models and open models. Uh, you know, like, not every part of the stack is open. There's many models where you don't have access to the models, and and, you know, there's sort of weird restrictions.

Um, how important is open and local models to the future OpenClaw?

I mean, part of part of what what motivated me to build OpenClaw is you see all these large companies, and then they have connectors to my Gmail, and then my my email is hosted somewhere, then this company has full access to my email, and then I could get a little bit down there.

Like, it's much more exciting to me if I have all my data actually under my control, and I and, like, a little bit of it goes up there if I need the top-tier token.

Yeah.

And.

Like, a second kind of hierarchy of, uh, fallback models.

Yeah. You want to I mean, I'm I'm European at heart. You want to own your data. You know, so so so and nobody built it. So for me, that was very attractive. And also the the fact that, you know, if if you're a startup and you want to connect to Gmail, it takes, like, half a year, and it's, like, a very very difficult process.

But if I'm a consumer, my client, I can click on any website, and it happily clicks on I'm not a bot. Uh, if you have to give me the data somehow, if you can if you give me the data, my my agent is able to get the data.

So you can work around a lot of those those silos those big companies are building, and ultimately, you can do much cooler automation use cases that large companies can never do.

Yeah.

So it's it's, like, it's a little bit the the hacker way.

Yeah. And, um, uh, any indications from the OpenAI team on GPT-oss? Uh, is that continuing continuing to be a stream of work that, uh, will be aligned with OpenClaw, or, uh, or is that, like, separate?

I'm not I'm not in the position to give.

Yeah.

Give you insights on that. Just that, um, part of what Open OpenClaw triggered is that, like, more people in the company are getting excited about open source. Um, and I I love that that OpenAI is moving more into the open direction again.

If you compare it to some other top-tier labs that start with an A, uh, that very much will sue you if you if you leak any of their source, um, or block you if you are too successful. I I I think OpenAI is in a good direction.

Yeah. Okay. I want to highlight this question. Um, people love hearing about your coding workflow. I thinkright by now, your idea of, um, uh, the prompt requests rather than the pull requests is is very well socialized. And also, you've been shocking people with just how you're spending tokens at OpenAI.

Coding & Taste24:55

Peter Steinberger25:14

Uh, so basically, uh, they people want to know how you ship and what do you do about agent waiting times. Like, why is, you know, you're spinning up so many agents. It can be.

I I know. Like, I I never imagined that this one picture of me would blow up so much.

Yeah.

Actually.

Uh, give give some numbers just just to align people.

I I think I'm and there's times where I was running almost 10 sessions at the same time, especially when I used Codex with 5.0, 5.1. It was quite slow. I think now I have to say we. It's still weird.

We, uh, made improvements. They both make it faster, and then there's also fast mode. So by now, my typical workflow is maybe half of that, maybe five, six windows instead of double, just because each loop is faster, and, like, the area of work I sink in and work is is pretty much the same.

So I I don't have to use split screen so much anymore. And I think we're going to move into a future where, um, token will be will be faster and faster. So at some point, like, this is not natural that you work on on six things at the same time.

Um, but it it's basically a workaround until until tokens are faster.

Yeah. Uh, one of my, uh, interesting things of putting you next to Ryan was to see how the two of you kind of approach, uh, token maxing, basically. I'm curious what you think about the the complete dark factory approach,right, that, uh, you don't even review code that goes in.

I think that's more and more doable, but also, you know, when I when I dark factory in a way also means I come up with everything I want to build in the beginning, and I just don't think you can build good software in that way.

Like, the way to the mountain is usually never a straight line. It is it is it is very curved. Sometimes you go a little bit off track, and then you you see something new that inspires you. You find, like, shortcuts.

Um, once you're at the top, you you you can find the optimal path, but you never walk like this. So at the same time, you will the first idea that you have about your project is very unlikely going to be the final project.

But if I if I suddenly use the waterfall model again, that will be the final project. For me, that doesn't work for me. Like, I I build steps. I play with it. I see how it feels. I get new ideas.

My prompts change. So to me, it's a very iterative approach. So I don't see how you could fully automate that. You can definitely build pipelines for certain things.

Yeah.

But even even even for PRs, you don't just want to build a pipeline that just merges PRs because a lot of them just don't make sense. You know, like, people people will pull your product into all kind of directions, but if you automate that, the AI will very unlikely know what's theright direction.

You can guide it. I have, like, a vision document that I tried some of that, but

the bottleneck is still sinking and, like, having taste.

Yeah. Taste is very important. Uh, how do you define taste? This is something that in my conversations with people, everyone understands taste is the moat, but nobody agrees on what taste good taste is. So I'm just curious to hear yours.

I think in this day and age, it's like the very low level of taste is if it doesn't stink like AI. And you know exactly what I mean. You know, if if something is just.

So writing style, personality?

Also, also, also UI. By now, you've seen so many so much agentic-built UI that you immediately know if it's AI.

Yeah. Yeah. If it has the the color border on the left,right?

Yeah. Yeah. I mean, for a while, it was, like, the purple gradient, but it it much more. So I I feel it's it's like a feeling. The same day as you can identify AI-written slopright away.

Yeah.

Um, that's why I say it's a smell. Like, even if you can pinpoint this, you will know. So so that's probably the lowest the lowest characterization of taste. And then and then going higher up, because now so much of software is is automatable, there's actually much more time you can spend on, like, the little details.

I don't know. You know, like, like, just when you when you when you when you run OpenClaw, you get, like, a little message, uh, that sometimes roasts people. Those are, like, the delightful details, I think, that you'll just not get if you prompt in a high level.

Yeah. One one of my favorite teas of yours is how you you, uh, really put a lot of work into your soul soul MD, and you, uh, you know, open sourced your approach. And I don't think people worked on enough soul until until you came along.

So I think that's really interesting. Uh, my I I have a podcast I haven't done yet. I haven't released yet with, uh, Mikhail Parakian, who is the CTO of Shopify now, but he was the, uh, guy leading Bing, where Sydney was, uh, the original sort of unaligned chatbot that emerged.

Uh, but I think people really have fun when when your soul your chatbot has personality. Your your clanker, uh, you know, has different obsessions.

Well, it's also because the world changed,right? We had we had ChatGPT in 2023 and '04, and it was basically

us having AI without understanding what AI can do. So we rebuilt a Google. So you have, like, a search field, and, like, you get a response, and you you don't expect Google to have a personality.

Yeah.

But now that we moved more towards agents. Like, if if I I didn't think about in the beginning of WhatsApp Relay, and I just hooked it up to Claude Code. Um, and then I when I was on WhatsApp, I noticed that it doesn't feel quiteright.

Like, even even though, like, Claude Code already has some personality, it didn't really fit how people would write to you on WhatsApp. So that that's how my whole iteration started was like, uh, this again, it's about taste,right? It doesn't feel quiteright.

It's, like, too wordy. It uses too many dots. It it it my friends text different, and then that's how I started working. They say, "No, this isn't " like, try to write more like a human.

Uh, yeah. I I actually run a writing.

Like a lobster.

Uh, like a lobster. Yes. Um, uh, uh, uh, you know, the one of my favorite quotes of yours is, uh, "Madness with a touch of sci science fiction."

Yeah.

Right? Like, that this is how you run, um, uh, AI projects. And I think.

Not not all AI projects, but specifically something like OpenClaw would have never been able to it would not have come out of an American company just because it would have been killed in legal long before it would have been released because it just has some problems that we haven't really solved as an industry yet.

Yeah.

But now we we have some mitigations, and it's getting better. The models are getting a lot better, but I don't see

how any of the big labs could have released that. You know, it would be too much pushback, uh, and, like, not enough market proof that this is what people want.

Yeah.

So, like, it had to be done with someone.

Like you.

Outside.

Yeah.

Yeah. That that that.

Sitting in your house.

Like, literally, like, when I when I built it in the very beginning, I was like, "Oh, what's the worst that can happen?" Like, it could exfiltrate my token, my emails. Uh, nothing is nothing nothing's in there that would, like, completely kill me.

It could, like, upload some of my pictures. I was like, "Uh, I guess the worst already online if you use Grindr." Um, so it was like it was like, "Okay. I can I can live with that risk. It would be uncomfortable, but it's like it it's manageable."

Yeah.

Uh, if your company is very different, it it requires a little different approach.

Yeah. By the way, uh, his Instagram account, good follow, under underfollowed. It's also it also has some good stuff. Um, okay. Uh, you were talking about WhatsApp, talking about Telegram, a lot a lot of these text apps. Um, uh, text apps are good.

Future Agents33:22

Peter Steinberger33:28

People are also looking for, like, the next form factor. People want, like, the maybe the the glasses, the earbuds. What what is your sort of wish list in terms of having agents in your life?

I started on that, actually, already, but then I was just getting bogged down by

all the people using it and just, like,

the daily grind. But if you're at home, I want to be in any room. And you know, it's Star Trek when you can when you say, "Computer, cream." I I I want I want to, like, talk to my agent wherever I am, and it should just be able to, like, respond to me.

It should know where I am. I have, like, little iPads in every room, and and my agent can use the Canvas feature and project stuff on those iPads. So, like, if I ask a question that that is, like, easier to be to be answered by also showing me something, like, it could use, like, the nearest display because it's aware of where I am.

So the phone is just a very convenient input point, but I kind of want to, like, talk to it from anywhere.

Yeah.

Like, yeah, if I'm around and I have glasses, I should just, like, be able to, like, listen in and, like, project something on me. Um.

But just ubiquitous follow you.

I I say, uh, yeah, once we have.

It's really smart home. Yeah.

Like, agents on your phone, but really you want ubiquitous agents, and then you want maybe you will have your your your uppercase OpenClaw, your private agent. At work, you might have your, I don't know, lowercase OpenAI Claw, and then

that Claw should be able to, like, talk to your personal Claw, uh, in a way that both your company and you are comfortable with. So that's kind of, like, the future where we need to work on.

Yeah. Uh, one of uh, I just did a podcast with Mark Andreessen. I was a huge fan, uh, and and also, uh, have conversations with Andrej Karpathy. Both of these guys are running OpenClaw to run their house. And I think OpenClaw for Homes is, like, a kind of underrated, but, like, people are really discovering it.

And my funniest sort of irony is that it's it's only possible because the internet of shit means that most smart devices are terrible in security, which means OpenClaw can run them.

Oh, it's going to be able to work so much better in in a few months when the models are getting really bad.

Yeah. It's they're they're very good. Um, okay. One security question, uh, uh, about prompt injection. How do you want to solve prompt injection? Or, uh, what what, uh, ways in which, uh, have you been thinking about the prompt injection problem?

Probably not enough yet. Uh, on the other hand, like, the the the front-end models are really quite good at detecting all the all the cases where, like, just stuff randomly comes in from a website or an email is usually not a problem anymore.

You mark as untrusted content. Very hard to exfiltrate you from that.

Yeah.

If if I have unlimited access to your Claw and I can bombard it with stuff, then there is still a chance.

You're going to find a way.

Then then there's still a chance. But, like, for one of things, it's no longer the biggest problem. If you use that's also why why you know, this is probably the angle where, like, some people say, "Oh, Peter doesn't like local models."

But then I see, like, people running, like, a 20, uh, billion parameter model that just does whatever you tell it and and is not trained to have any defenses at all. That's still problematic. If you run that and then you use a web browser or email, um, would worry me.

That's why that's why OpenClaw warns you if you use a small model. And I know people spin a whole thing, like, "We hate small model." I I love I love I love that it we support everything, but, like, you have to

steer the the regular user a little bit into a direction to make it harder for them to shoot themselves in the foot.

Hmm.

Um, yeah. There there is some ideas for prompt injection. It's

it's still a little bit away. I have more to announce there.

Yeah. Uh, I think Simon Willison has been working a lot on on this. I mean, he coined the term prompt injection, and the sort of dual LLM approach seems smart. Uh, and I'm I'm not smart enough to figure out all the ways that which it can be attacked.

Like, at at some point, trust just has to be a thing,right? Um, and, uh, and I prom there's there's something interesting I found out from talking with Vincent, who is speaking next, is that you guys had to implement the same trust system that Toby, Luca had to implement, which is, uh, you build reputation over time, and things with more trust, uh, gets more privileged access,right?

And I think that that makes sense.

That's at least part of the story.

Yeah. Yeah. Yeah. Um, okay. So, uh, one of some more broader questions. What cool projects would you like to work on once you have more free time?

Vision & Skills38:33

Peter Steinberger38:34

I mean, I wanted to work on Dreaming. And now, like, my maintenance worked on Dreaming while I I'm there, like.

While you were Dreaming.

Uh, so like.

You just shifted,right?

Yes. Yes.

What what is Dreaming?

Uh, it's, like, a way to reconcile memories and, like, kind of create a little bit, like, like a Dream log. It goes through, like, your session logs. Um.

We found we found out from the Anthropic source code leak that they're also working on Dreaming,right?

Oh, yeah, yeah. I mean, there's I'm pretty sure there's, like, more companies working on that. But think a little bit, like, how do we learn as humans? You you experience a lot of things during the day, and then you sleep.

And in in sleep, your your brain does, like, a garbage collect, converts some memo some local locally stored memories into long-term storage, and, like, drops others. Uh, and that that's similar ideas that I think could also be very useful for agents.

Um, and then, like, what we shipped on Dreaming is, like, a first little step in that direction.

Yeah. And it's related to the wiki, uh, thing that Andrej has been talking about, where you sort of collect everything into a.

Wiki is is more memory, but, like, everything kind of blends a little bit together. Um, the the beauty the beauty of OpenClaw is that we can just drag stuff, you know? Like, like, everything what we worked on for the last month or so is that in the beginning, it was a big spaghetti code base mess.

And now, like, everything everything is an extension, a plugin. So you can replace memory. You can add the wiki. You can add Dreaming. You can add, I don't know, your your your whatever crazy idea you have and just make it your own.

You don't have to send everything to a pull request because we are still completely overloaded on those. You but it's it's more like Linux, where you just can install your own parts.

Yeah. Yeah. Uh, and, uh, you are building what a lot of people think, uh, is the most consequential open source since Linux, which I don't know. How do you deal with that? Uh, how do you deal with the the the the fame, "What is a day in your life?"

uh, as as the BDFL, effectively, of something like this?

What's my well, there's still a lot of coding. There's also a lot of.

By the way, in be in between sessions, he was coding back there.

Yeah. The token inside. You have to, like something has to be running.

You have to push the agents,right?

Yeah. Um,

we're shifted a little bit. Now it's a lot more a lot more talking and

steering people in theright direction, you know, like, because there's a lot of things that we already learned in OpenClaw. So, like, part of my role at OpenAI is, like, to, like, help them not make the same mistakes again.

Um, and then and then at OpenClaw is, like, try out new things that seem exciting, and some might work, and some might don't work. Enable enable companies to, like, build their own Claw without having to fork away, but, like, making everything more more customizable.

Um, yeah, and sometimes I sleep.

Sometimes you sleep. Okay. Great. Uh, I think that maybe this is the last good closing questions. Uh, what skills do you want humans and engineers in particular to focus on developing in the age of AI?

Taste was a big one, but I already mentioned that.

System design is still very important.

Yes. You we talked about this in San Francisco.

Because yeah. If you don't think about that, you will eventually slide yourself into a corner,right? Just by defining the boundaries. Like, the funniest thing is, like, everything is in the clencher, but you still need to ask theright questions.

Otherwise, that makes there's a difference of, like, good code that comes out or, like, really bad code that comes out. And that's still where, like, all the knowledge you have, like, how you build software, you can apply to steer the agent into into something that is not slop.

Yeah.

And then I think I think a skill that is becoming more and more important is saying no. And and and that's something I had to learn as well because even the wildest idea is just just a prompt away.

And usually, this one idea is never the problem, but, like, this idea and this idea and this idea and this idea, and then how all of that fits together, that's the problem.

Yes.

So, like, I think there's still bottleneck on thinking and about, like, big picture thinking.

Yeah.

Because imagine the world from your clencher. Like, you're being thrown into a code base. You might have an outdated agent set in default, but you basically don't know what the F this is. And you, like, then, like, you tell me, "Hey, add user profiles."

And you, like, somehow add user profiles and connect it to the two things you see, but you didn't see the whole system,right? And that that's where a lot of those localized solutions comes where, like, the project has, like, VARTs, and and it's our job to, like, help the agent do its best work by, like, providing them with, like, hints.

"Hey, you want to consider this? You want to look there? How would this interplay with this?" And then and then ultimately, you get, like, a much a system that actually is maintainable.

Yeah. Um, well, thank you for maintaining one of the most important software of all time, and thank you for spending time with us.

Thanks for having me.

Yeah. Hopefully, you'll stick around and answer questions. Thank you.

Allright.