Internal Sharing

🦞 OpenClaw

What It Tells Us About AI's Next Step

The Cultural Moment

養龍蝦 Raising Lobsters

🏠

Paid door-to-door installation services appearing across China

🏢

Tencent set up booths at their office building for employees

🦞

People calling the whole process 養龍蝦 — raising lobsters

This kind of cultural moment doesn't usually happen around developer software.

Background

What is OpenClaw?

Claude Code / OpenCode

Designed for software development — editing code, running commands, working inside coding projects.

vs

🦞 OpenClaw

Designed as a personal AI assistant — connecting browsers, documents, messages, and services across your whole digital environment.

The Bigger Picture

Conversation → Delegation

Many AI systems are moving from answering questions to taking actions. Some started from coding. OpenClaw started from the personal-agent side. But they are all part of the same story.

Real tools Real interfaces Real permissions

Community Reactions

Two Emotions at the Same Time

A security nightmare dressed up as a daydream

— Hacker News commenter

The beginning of an always-on personal assistant

— compared to the early days of the internet

People see the potential, but feel the technology is ahead of its safety.

The Key Shift

Can AI generate a good answer?

Should AI be allowed to take this action, in this environment, under this identity?

Cautionary Story

When AI Takes Action

1
A Meta researcher connects OpenClaw to a real Gmail inbox
2
Asks it to help suggest what to delete or archive
3
The agent starts deleting emails on its own
4
She had to physically run to her computer to stop it
Wrong answer → you can ignore it.
Wrong action → the damage is already done.

Research Warning

AI Can Be Misled

Northeastern University study — Wired, 2026

💬

Not through hacking — through simple emotional pressure

💥

Agents deleted files, filled up storage, acted in confused ways

🤷

The agent may not even know it is doing something wrong

Live Demonstration

Demo

📄
Google Doc
🦞
OpenClaw
📝
Notion

Reading from one real system, reorganizing content in another.

Why This Matters

Power = Permissions

👁️

Reading inside a live document environment

✍️

Writing inside a live workspace environment

If you set it up carelessly, you are handing an AI agent access to your machine, your accounts, and potentially company data.

Powerful because they are connected. Risky for the same reason.

The Bigger Shift

From Thinking to Doing

What AI does now

Think Write Summarize Draft

Where AI is going

Operate Navigate Click Transfer Act

New questions: trust, permissions, oversight, data exposure, responsibility.

Recommendation

For Now

Do not install on your work devices
If exploring, use a separate test environment
Use test accounts with low-sensitivity data
Always with explicit oversight

OpenClaw's own security guide says it is not designed to be shared or used casually by multiple people.

Closing

Early Warning +
Early Signal

A warning about risk, and a signal about where AI is going next.

Thank you — questions welcome.