OpenClaw opens enterprise agent control plane as Gartner warns buyers off vendor lock-in
The OpenClaw Foundation opened its enterprise agent control plane to early users on 30 September, the same day Gartner predicted that 70 percent of enterprises will abandon vendor-built agentic AI by 2028.

OpenClaw Enterprise is an open source control plane for running persistent AI agents inside sensitive environments. It is now available for internal pilot workloads. The project announced the move in a blog post on 30 September and describes the platform as vendor neutral and free to self-host.
The timing is awkward for the vendor services industry, and useful for buyers. Hours earlier that same day, Gartner published a forecast that 70 percent of enterprises will walk away from agentic AI systems built with vendor assistance by 2028. The consultancy cited cost and the difficulty of modifying those systems without outside help. The Register reported the forecast on 30 September.
Forward-deployed engineering, and its exit problem
Gartner's target is what it calls forward-deployed engineering. Vendors embed their own engineers inside a customer to build and deploy software for that customer's specific requirements. The model can produce fast early results. It can also leave the customer holding a system it cannot maintain once the vendor's people leave, Gartner argues. The consultancy also predicted that through 2028, fewer than 20 percent of these engagements will turn recurring customer requirements into features in the vendor's core product. It warned about "FDE washing", where ordinary consulting gets sold as something more specialised.
"The best-scoped FDE engagements have clear guidelines on governance, business value delivery, IP ownership, project co-ownership, knowledge transfer, and an exit strategy from day one," said Gartner senior director analyst Mukul Saha, according to The Register.
OpenClaw Enterprise is a direct answer to the other half of the adoption problem: governance. The project says IT departments in most organisations default to banning agentic platforms outright, because a common security, safety and governance standard does not yet exist. OCE adds multi-tenancy, hard boundaries between trusted and untrusted workloads, sandboxing, LLM-based reviews and fine-grained permissions. The harness, model and sandbox are designed to be swappable.
The project started at OpenAI, was donated to the OpenClaw Foundation, and has been developed with Red Hat and NVIDIA. It is being piloted inside Red Hat and OpenAI, and the project notes that OpenAI already runs OpenClaw agents with full access to codebases and plugins. A reference architecture for the security controls is promised in the coming weeks.
Guardrails, identity and the plumbing underneath
Two other open projects landed on 30 September with the same intent. OpenAPPA, from Archestra, sits between an agent and its tools and answers one question before every action: is this data allowed to go to this destination? Its policy is declarative TOML, and the engine decides from the event log alone. The project says no scored attack succeeded against it in 1,320 evaluations, while it completed 88 to 90 percent of tasks. A separate project, UAI, proposes an open protocol for agent identity, owner binding, time- and jurisdiction-bounded authorisation and signed action attestations, with BGP-inspired federation between registries.
Elsewhere on 30 September, Tailscale explained how Meta's Muse agent joins a tailnet as its own node, with outbound-only connections and explicit confirmation on first contact with any device. Tailscale treats Muse like any other node, so existing grants and tags apply. The post is candid that prompt injection and vulnerabilities will still happen.
For buyers, the practical question is whether any of this changes the economics Gartner describes. A free, self-hosted control plane removes a licence line from the budget, not the internal engineering needed to run agents safely. Agent Skills, as DevNavigator noted on 30 September, only work when someone owns the captured knowledge and reviews it as policies change. Vercel's 25 September state of agent skills report, cited in that piece, counted more than one million listings and nearly 280 million recorded installs in seven months. The article itself flags those figures as registry activity rather than proven business value.
The counterargument comes from the vendors themselves. A blog post published on 30 September argues that selling outcomes turns technical uncertainty into financial risk, and that agent companies will need an underwriting model, quoting from a distribution of cost-to-complete before accepting work, the way Uber moved to upfront pricing. That is a harder promise to keep on a long project than on a ride.
Sources
7- 017 in 10 enterprises expected to abandon vendor-built agentic AI by 2028EN
- 02OpenClaw Enterprise - The Open Agent PlatformEN
- 03OpenAPPA: Deterministic guardrails that don't break agentsEN
- 04UAI - An open protocol for identity and accountability of AI agentsEN
- 05Your agent, your network: How Meta's Muse agent works with TailscaleEN
- 06Agent Skills: 4 Powerful Ways to Improve Enterprise AIEN
- 07Underwrite the Work - long horizon agents mean rethinking selling the outcomeEN
All figures and quotations in this text come from the sources listed below.
Content prepared by the editorial team with AI assistance.
Comments
0- No comments yet — be the first.