HomeVideos

State of the Claw — Peter Steinberger

Now Playing

State of the Claw — Peter Steinberger

Transcript

1089 segments

0:00

Our

0:07

[music]

0:15

next presenter is the creator of Open

0:18

Claw, the world's fastest growing

0:20

open-source AI. He recently joined

0:23

OpenAI to work on bringing agents to

0:26

everyone. Please join me in welcoming to

0:28

the stage Peter Steinberger.

0:52

Good morning everyone.

0:55

>> [applause]

0:57

>> So, Swiss asked me to do a state of the

1:00

claw. Who here is running open claw?

1:03

Give me some hands.

1:05

Ah, it's like 30 40%. Very good. Um,

1:10

yeah,

1:12

it's been quite a few months. Um, the

1:16

project is now five months old.

1:19

I think it's fair to say by now that we

1:21

are the fastest growing project in

1:24

GitHub's history. Um, if you've seen the

1:26

the graph, usually it's some some

1:29

projects look like a hockey stick, but

1:31

ours was just like a straight line and a

1:33

friend called it stripper pole gross

1:37

and that comes with its own challenges.

1:39

So, we have I think now we are the the

1:43

largest number on GitHub stars. There's

1:45

a few that are bigger but they're

1:47

basically educational target. No other

1:49

software project is that big. It's

1:51

around 30,000 commits. It we're closing

1:55

in 2,000 contributors

1:58

soon to be 30,000 PRs. Um,

2:03

see, and we're not slowing down. So, you

2:06

see that it's a ramp, but you know, it's

2:09

we only have April 9. So, um,

2:15

velocity keeps keeps being good.

2:20

And at the same time,

2:23

it hasn't been easy. You know, I I had

2:26

two roads when I when I decided what I

2:28

want to do and I I did the whole company

2:31

thing. I was like, I don't want to do

2:32

this again. And then I joined OpenI, but

2:35

then we also created the Open Cloud

2:36

Foundation. And now I kind of have two

2:38

jobs.

2:39

And running the foundation is like a

2:42

running a company on hard mode because

2:44

you have like all the all the things

2:46

that you need to take care of but also

2:48

you have a lot of volunteers that you

2:49

can't really direct.

2:52

So

2:54

one of my goals has been working on the

2:56

on the bus factor like who does comets.

2:59

Um and you see that it's slowly

3:02

improving.

3:04

Vincent's actually talking after me but

3:07

we're still not we're still not there.

3:10

Um, in the last months I I talked to a

3:13

lot of companies.

3:16

So we now have people from Nvidia on

3:19

board. We have someone from Microsoft on

3:21

board to like help with MS Teams with

3:23

like a Windows app. Uh, we have someone

3:25

from Red Hat who's really helping us um

3:28

with security and dockerization. We work

3:31

with a lot of Chinese companies. We have

3:33

people from from Tencent and Biteance.

3:35

um they're actually much larger users

3:38

than any other continent

3:42

and yeah people from pretty much around

3:44

the world but like the main thing I I

3:47

want to like talk a little bit about is

3:48

about open claw is so insecure you know

3:51

you've you've seen the

3:54

you've seen the memes like open claw

3:56

invites the bad guys

3:59

and you probably also seen

4:04

companies like Nvidia

4:05

doing Nemo claw and like everyone has

4:09

little lobsters.

4:13

So

4:15

you also notice that like in the last

4:17

two three months there's been a lot of

4:19

releases where things broke.

4:21

I've basically been been dodoed by

4:24

security advisories. So that's what I

4:28

did um and what I focused on. So far we

4:31

got 1,142

4:34

advisories. That's around 16.6 a day. 99

4:39

are critical. Um we published around 469

4:43

and we closed 60% of them. So these

4:47

numbers sound like absolutely

4:48

terrifying.

4:51

If you compare it for example to like

4:52

other large projects like the Linux

4:55

kernel gets like eight or nine a day. we

4:58

get like twice as much and curl so far

5:00

has 600 reports we have like twice as

5:02

much as curl.

5:07

So every time I I get a

5:10

security incident, the rule is the

5:14

higher the higher they screaming how

5:16

critical they are, the more likely it's

5:18

slop. Like we we I mean you've probably

5:22

also seen the news like we we we are

5:24

very fast moving into a world where

5:29

we have to change how we build software

5:31

because all these AI tools are getting

5:33

so good at identifying

5:37

even the most weird multi-chained

5:40

exploits and like we're gonna going to

5:42

break all the software that exists. I

5:44

give you an example like

5:46

uh Nvidia they

5:49

they launched Neimoclaw and Neimoclaw is

5:52

a a plug-in and a security layer for

5:54

open claw. You can put it in a sandbox.

5:57

I the keynote was on Monday. They

5:59

invited me on Sunday to like work with

6:01

them. I hooked it up to Codex security.

6:04

It found like five different ways how to

6:06

break out of the of their secure sandbox

6:08

within half an hour.

6:11

That's because like if you use that

6:12

product, you get access to the unnerved

6:15

model that is quite a bit smarter in

6:18

terms of cyber than what the public has

6:21

access. Exactly. Because it's dangerous.

6:27

But yeah um

6:30

also this whole industry those people

6:33

for them it's like credits right the

6:35

more the more issues they find the more

6:37

they seen so like openclaw was like the

6:40

insecure product that everybody tried to

6:42

break so literally like hundreds of

6:43

people firing up their clankers trying

6:46

to break open claw

6:49

um

6:54

the typical attack surface is like

6:57

remote code execution,

7:00

bypass approval, code injection, pass

7:03

traversal. Uh again sounds all very

7:07

dangerous

7:09

and I give you I give you one one

7:11

concrete example. Um

7:14

Gshjp.

7:16

This is about a this is a CVSS of 10. So

7:20

it's like the scariest thing that you

7:22

can possibly do.

7:25

It is an issue where if you

7:30

uh sync for example the iPhone app that

7:33

we haven't even shipped yet but is in

7:34

progress and you give it only read

7:37

permission then you could like break the

7:40

system to also get write permission.

7:43

So this this one was so critical that

7:46

the I know this one's actually different

7:48

one

7:50

in all in all practical ways

7:54

it is not even an incident because the

7:56

the the typical use cases you install it

7:59

on your machine

8:01

either in a cloud or if you have to on a

8:04

Mac mini I stopped fighting this I'm

8:06

just letting people have fun now

8:10

but in 99% 99% cases you'll either have

8:15

access to your gateway or you have not

8:17

access to the gateway. In in in my

8:19

defense, this was my mistake that I

8:21

tried to create a a more permissive

8:23

model. For example, if you have devices

8:26

that would target speech and then would

8:29

only like read certain things. So

8:31

there's like some use case where you

8:32

could like have a a reduced permission

8:34

system would make sense.

8:36

Um but nobody's even using that. But

8:39

this doesn't matter because the rules of

8:42

the of those how you create the CVSS

8:44

numbers don't contribute to that at all.

8:47

And I try to play by the rules. So it is

8:49

a 10 out of 10. And the world is going

8:52

crazy over incidents that in all

8:54

practical ways will not affect people.

8:58

There's some other stuff that does

8:59

affect people. Uh we have nation states

9:03

trying to like hack people. There was

9:05

like ghost claw which is like from

9:07

likely from North Korea which is

9:10

basically

9:11

confusing people with a different NBN

9:13

package and if you if you go to a wrong

9:15

website and you try to download it you

9:17

get like a a root kit. Um that's outside

9:20

of our control. This happens for other

9:22

people as well. Um,

9:25

also there's the Axios thing which funny

9:28

enough we are not using Axios

9:31

but we are using MS teams or Slack as a

9:36

dependency and they're using XIS and

9:38

they didn't pin us and of course uh

9:41

because that's how supply chain attacks

9:43

work we were also affected.

9:48

Yeah. How do you survive 1,142? I'm sure

9:51

it's 1,150.

9:53

Uh for a while I I I tried to handle a

9:57

loop by myself and which is absolutely

9:59

impossible.

10:01

So So the fastest way to get help was

10:04

like getting getting help from companies

10:08

um and Nvidia has been really amazing to

10:10

like give us some people that basically

10:14

work full-time going through the slop

10:16

and hardening the code base.

10:22

Oh, there's also one that is

10:28

okay.

10:30

That um

10:33

this is one of the anglers. The other

10:35

angle is like there's a lot of companies

10:37

that do fearongering and it's not just

10:40

companies, it's also universities. I

10:43

don't know if you've seen it. There was

10:44

like this um

10:47

paper who made the rounds agents of

10:48

chaos and they say oh it's it's about

10:52

agents in general but then there's four

10:54

pages that explain the open claw

10:56

architecture in utmost detail

10:59

but you know which page they didn't even

11:00

mention

11:02

a security page where we explain how you

11:04

should install it because then it

11:06

wouldn't be fun then it wouldn't be it

11:08

would be hard to make a good story. So

11:11

what they instead did is they ignored

11:15

all of the recommendations we do on

11:17

security. Recommendation is it's your

11:19

personal agent. Don't put it in a group

11:22

chat. If you put it in a group chat,

11:24

turn on sandboxing because if anyone can

11:27

talk to your agent, they can excfiltrate

11:29

anything that the agent can do, right?

11:32

So if it's a team agent, it should only

11:34

know what the team can know and not any

11:36

secret data. And you probably want to

11:37

like have it restricted. If it's your

11:39

personal agent, you should be the only

11:41

one being able to talk to you. But if

11:43

you don't play by these rules, you can

11:45

get some really fun interactions like,

11:47

"Hey, I can talk to your agent and it

11:49

can break your system." And then because

11:51

I I was I was grilling them a little bit

11:53

because I had some questions how to do

11:55

things. They told me, "Oh yeah, no, we

11:56

run it in pseudo mode because we wanted

11:58

the agent to be like maximum powerful."

12:01

So they actually fought the setup. It's

12:04

actually not easy to run it in pudo

12:05

mode. You have to change code. um

12:09

but they didn't mention it in the report

12:11

because again that wouldn't give them

12:13

cloud.

12:18

So yeah um my current frustration is

12:21

like there's like a whole industry that

12:24

try to put the project in negative

12:26

light. It's a nightmare.

12:28

It's insecure by default. It's

12:30

unacceptable.

12:31

Um

12:33

and meanwhile a lot of people love it

12:36

and people who actually

12:38

read the security docs understand it can

12:40

use it just fine. One example that I

12:42

found particularly great is u we had one

12:46

remote one rce that panicked Belgium.

12:50

So the Belgium cyber security did a

12:53

release uh about a remote execution

12:56

environment

12:59

and the whole bug was

13:03

a feature where a malicious website

13:06

could create a link

13:11

that would

13:13

trigger the gateway and then forward

13:15

your gateway token. Now if you use the

13:18

setup that is the default and that is

13:21

recommended the gateway token is local

13:24

only or if you have to it's in your

13:26

private network no external website can

13:29

actually access it. If you

13:33

actively fight the setup and for example

13:35

use cloud code to set it up without

13:37

reading, you might be able to get this

13:39

setup working.

13:41

But again,

13:43

that's not anything what's said on the

13:45

website.

13:49

So to be very honest, yes, there's

13:52

absolutely

13:54

uh risk. the the the big risk is the the

14:01

basically the legal trifecta. You know,

14:03

any any agentic system that has access

14:07

to your data,

14:10

has access to untrusted content and the

14:13

ability to communicate is something

14:16

that's potentially at risk. That's not

14:19

anything special to OpenClaw. It's like

14:21

any any agent any power agent system has

14:24

a problem. The more the more powerful

14:28

you make it, the more it can do for you,

14:31

but the more you also have to understand

14:33

what it does. So this is like the the

14:35

main issue

14:40

>> but people not talk about this. Yeah.

14:42

And then also

14:44

um

14:47

some part about maintaining.

14:50

So

14:53

the problem is like if you get all those

14:54

security advisories,

14:57

you know that most of them are created

14:59

with agents, but you still have to use

15:02

your brain to actually read it because

15:04

we're not at the point where you can

15:06

fully trust or I'm not at the point

15:07

where I I can just fully trust that the

15:10

agent will figure it out. So it is a

15:12

huge burden on on time and you never

15:14

know. I mean sometimes you can you can

15:16

often guess you know anytime the reput

15:19

is too nice or like someone apologizes

15:22

that's very likely AI because usually

15:24

people in security don't apologize. Um

15:29

but it is a huge problem and it's

15:30

something that I see more and more open

15:32

source projects complaining about or

15:34

like breaking. Um,

15:37

some are very public about it like

15:38

ffmpeg.

15:41

Usually you get the report. It's very

15:44

rare that you actually get a report and

15:45

a fix. If you get a report and a fix,

15:48

it's usually a very bad fix. If you rush

15:52

it, as I sometimes did in the beginning

15:53

because I was overload, you will very

15:56

certainly break your product.

16:04

[clears throat] Yeah. So this is

16:05

something that's just very difficult to

16:07

pull up only with volunteers. So we so

16:12

what are we working on?

16:14

Number one is

16:17

I

16:19

people say like open AI bought open claw

16:22

that's not the truth. they might bought

16:24

my soul.md

16:25

um but they very much understand that in

16:28

order for what the world needs is like

16:32

more people that play with AI to like

16:35

understand what AI can do to both

16:37

understand the risk and also the

16:38

possibilities they understand that if

16:41

you or like someone who never played

16:44

with never used AI suddenly is at home

16:47

and uses openclaw they'll come to work

16:50

and they will ask why don't we have AI

16:51

at work so they very much understand

16:53

that like supporting this project is

16:55

very useful and in order for that

16:57

project to be successful cannot be under

16:59

one company. Therefore, I'm kind of

17:01

building Switzerland with the open glove

17:03

foundation and I have Dave was helping

17:05

me with it. Um, it's almost done. The

17:08

last thing that's keeping us going is

17:10

like the American bank system which is a

17:13

little bit slow and very confused when

17:15

you're not American.

17:16

Um, it's inspired by what Ghosti did.

17:20

And this will actually then help us to

17:22

hire full-time people to both keep up

17:26

the pace, improve the quality, and free

17:29

up some of my time that I can work on on

17:31

cool stuff again.

17:37

And that's my little update on State of

17:40

the Claw. I'll be around later for like

17:42

a Q&A. Thank you for listening.

17:45

[applause]

17:46

Okay,

17:48

great. Thank you for the whoop. Love the

17:50

whoop. Um, so excellent. Okay, you've

17:53

chosen the claw uh track to get started

17:57

on for our our breakouts and uh uh it's

18:00

going to be great. I think it's going to

18:01

be it's going to be a good session. Um

18:03

we are going to be hearing about a bunch

18:05

of different things uh related to uh

18:08

openclaw and just personal AI assistance

18:10

in general. There's some open claw

18:12

contributors, openclaw maintainers, uh

18:15

um uh open claw competitors, uh and open

18:18

claw creators, uh going to be here on

18:21

the stage. Um we're actually going to uh

18:23

be taking this through until the lunch

18:25

break. Um oh, there we go. We can see up

18:27

there. So, it's about an hour and a half

18:29

of uh of sessions, slightly shorter

18:32

sessions than uh than earlier, I think.

18:34

Um but we're going to be starting with

18:35

uh an AMA. came in. You saw Peter

18:37

earlier on, but you're going to get a

18:38

chance to ask questions and there's

18:40

going to be a bit of a conversation uh

18:42

with Peter and Swix. So, I think to get

18:44

us started, I will simply invite Swix up

18:47

who will kick things off. So, uh please

18:50

welcome him to the stage. Swix, come on

18:52

up. Swix.

18:54

[applause]

18:57

>> All right.

18:57

>> Actually, you can just go together.

18:59

>> You can come out together. There's no

19:01

secret. Peter, welcome. Everybody there

19:03

is

19:04

>> [applause]

19:07

>> Okay, so the deal for this is meant to

19:09

be an AMA. Uh the the main idea is that

19:12

I've run six of these AI engineers and

19:15

whenever we have some big maintainer,

19:17

big VIP, we only give them a talk, but

19:20

actually you guys have questions that

19:21

you want to ask. Uh so uh we wanted to

19:24

sort of create that opportunity. So you

19:25

can you can submit there. I'm going to

19:26

moderate uh and and all that. Uh the

19:29

spicy one I'm just going to start off

19:31

with. Pete just quote uh quote tweeted

19:33

uh me and saying send all your questions

19:36

about closed claw right uh [laughter]

19:40

I think uh people have a lot of

19:42

questions about um the future of

19:44

openclaw at openai uh and uh I wanted to

19:48

give you the space what what is the what

19:49

are people saying about closed claw and

19:50

then what is your response

19:53

>> I didn't even think about it was like it

19:56

came up when when I decided to go to to

19:59

openi And

20:02

I think I think people have a point that

20:06

open air wasn't always

20:08

amazing with open source. And I I think

20:11

a lot changed like Codex is open source

20:13

now. They released Symfony which is a

20:15

really cool orchestration layer. So like

20:16

like they're really leaning in and

20:18

understanding open source now. They

20:20

understand that open cloud needs to stay

20:23

open work with any model be it be it one

20:27

of the the big companies or being a

20:30

local model um everybody in the industry

20:34

wins if more people spend time with AI

20:38

you know if if I if I think AI is

20:41

something scary and then suddenly I I I

20:43

play with open claw and suddenly it's

20:45

like fun and weird and then I come to

20:47

work and there's no like I don't have AI

20:50

tools at work. I'm going to get to my

20:51

boss and say why the f do we not have AI

20:53

at work and and then like those

20:56

companies would probably not run open

20:59

claw but we want something that's like

21:00

hosted and managed and and then somebody

21:04

can can make a sale. So they they're

21:06

like very much on board. They provide me

21:08

with resources. Um, actually it's me

21:11

like I could get a lot more people from

21:12

OpenAI to help with the project, but

21:15

that would just make a picture that they

21:18

could have taken over the project and I

21:20

don't want that. So I I I brought in

21:22

people from Nvidia, we have someone from

21:24

Microsoft, from Telegram, someone from

21:27

Salesforce of all the companies. So So

21:29

shout out actually there's cool people

21:31

at Slack. So we have someone that

21:33

maintains the Slack plugin. Now I

21:36

brought Tensent on board, Bite Dance. We

21:39

talked to Alibaba, Miniax, Kimi, like

21:41

all the all the model providers. They're

21:43

like very much on board. Um, Nvidia has

21:46

been immensely helpful. They

21:50

I think I one of the coolest companies

21:51

in terms of here's some engineers who

21:53

actually like just hire agency and just

21:55

do things.

21:56

>> Yeah. Uh and now that I have all the

21:58

other companies, I'm also bringing a few

21:59

people in from OpenAI to to help

22:01

maintain the project because it's I mean

22:04

software is just like changing that the

22:06

the pace at which this project operates

22:09

is is insane. You kind of like you need

22:12

an army. Um and I'm working on that.

22:16

>> You have an army. Uh and but but you

22:18

know even the contributor chart that you

22:20

showed uh shows that it's hard to get

22:22

quality contributors to stick around.

22:24

people keep hiring your maintainers and

22:25

then you have to find new ones.

22:27

[laughter]

22:28

Um so there's a lot of questions about

22:29

local models and open models. Uh you

22:31

know like not every part of the stack is

22:34

open. There's many models where you

22:36

don't have access to the models and and

22:38

you know there's sort of weird

22:40

restrictions. Um how important is open

22:42

and local models to the future openclaw?

22:46

I mean part of part of what what

22:49

motivated me to build open claw is you

22:51

see all these large companies and then

22:53

they have connectors to my Gmail and

22:56

then my my email is hosted somewhere

22:58

then this company has full access to my

23:00

email and then I can get a little bit

23:02

down there like it's much more exciting

23:04

to me if I have all my data actually

23:07

under my control and I and like a little

23:09

bit of it goes up there if I need the

23:11

top tier token.

23:13

>> Yeah. and like a second kind of

23:15

hierarchy of uh fallback models.

23:17

>> Yeah, you want to I mean I'm I'm

23:18

European at heart. You want to own your

23:19

data, you know. So so so and nobody

23:22

built it. So for me that was very

23:24

attractive and also the the fact that

23:28

you know if if you're a startup you want

23:30

to connect to Gmail, it takes like half

23:32

a year and it's like a very very

23:34

difficult process. But if I'm a consumer

23:37

my clanker can click on any website and

23:39

it happily clicks on I'm not a bot. If

23:42

you have to give me the data somehow, if

23:44

you can if you give me the data, my my

23:47

agent is able to get the data. So you

23:49

can work around a lot of those those

23:51

silos those big companies are building

23:53

and ultimately you can do much cooler

23:55

automation use cases that large

23:57

companies can never do.

23:58

>> So it's it's like

24:00

it's a little bit the the hacker way.

24:03

>> Yeah. And um any indications from the

24:07

open team on GBTOSS? Is that continu

24:10

continuing to be a stream of work that

24:13

uh will be aligned with open claw or or

24:16

is that like separate?

24:18

>> I'm not I'm not in a position to give

24:20

yeah

24:20

>> give you insights on that just that

24:24

um part of what opencloud triggered is

24:27

that like more people in the company are

24:29

getting excited about open source. Um,

24:33

and I I love that that OpenAI is moving

24:35

more into the open direction. Again, if

24:38

you compare it to some other top tier

24:40

labs that start with an A, uh, that very

24:43

much will sue you if you if you leak any

24:46

of their source um, or block you if you

24:50

are too successful. I I I think Open is

24:53

on a good direction.

24:54

>> Yeah. Okay. I want to highlight this

24:57

question. Um, people love hearing about

24:59

your coding workflow. I think right by

25:02

now your idea of um uh the prompt

25:05

request rather than the pull request is

25:07

is very well socialized and also you've

25:10

been shocking people with just how

25:11

you're spending tokens at OpenAI.

25:13

[laughter]

25:14

Uh so basically uh the people want to

25:18

know how you ship and what do you do

25:20

about agent waiting times like why is

25:22

you know you're spinning out so many

25:23

agents. I

25:24

>> I know like I I never imagined that this

25:26

one picture of me would blow up so much.

25:29

>> Yeah. actually

25:30

>> uh give give some numbers just just to

25:32

align people. I I think and there's

25:34

times where I was running almost 10

25:36

sessions at the same time especially

25:39

when I used codeex with 50 51 it was

25:43

quite slow I think now I have to say we

25:47

it's still weird we made improvements

25:51

they both make it faster and then

25:52

there's also fast mode so by now my

25:54

typical workflow is

25:56

maybe half of that maybe five six

25:58

windows instead of double just because

26:00

each loop is faster and like the

26:04

area of work I sync in workers is pretty

26:06

much the same. So I I don't have to use

26:09

split screen so much anymore and I think

26:11

we're going to move into a future where

26:15

um

26:16

token will be will be faster

26:17

[clears throat] and faster. So at some

26:20

point like this is not natural that you

26:22

work on on six things at the same time.

26:24

Um

26:26

but it's basically a workaround until

26:30

until faster. Yeah. Uh, one of my, uh,

26:35

interesting things of putting you next

26:37

to Ryan was to see how the two of you

26:40

kind of approach uh, token maxing.

26:42

Basically, I'm curious what you think

26:44

about the the complete dark factory

26:45

approach, right? That uh, you don't even

26:48

review code that goes in.

26:53

I think that's more and more doable.

26:57

But also, you know, when I when I

27:00

dark factory in a way also means I come

27:03

up with everything I want to build in

27:04

the beginning and I just don't think you

27:07

can build good software in that way.

27:09

Like

27:11

the way to the mountain is usually never

27:13

a straight line. It is it is it is very

27:16

curved. Sometimes you go a little bit

27:18

off track and then you you see something

27:19

new that inspires you. You find like

27:21

shortcuts. Um

27:24

once you're at the top you you you can

27:25

find the optimal path but you never walk

27:27

like this. So at the same time you will

27:30

the first idea that you have about your

27:32

project is very unlikely going to be the

27:34

final project. But if I if I suddenly

27:37

use the waterfall model again that will

27:39

be the final project. For me that

27:41

doesn't work for me. Like I I build

27:44

steps I play with it. I see how it

27:45

feels. I get new ideas, my prompts

27:48

change. So to me, it's a very iterative

27:51

approach. So I don't see how you could

27:53

fully automate that. You can definitely

27:55

build pipelines for certain things.

27:57

>> Yeah.

27:58

>> But even even for PRs, you don't just

28:00

want to build a pipeline that just

28:01

merges PRs because a lot of them just

28:03

don't make sense, you know, like people

28:05

people will pull your product into all

28:07

kind of directions. But if you automate

28:11

that, the AI will very unlikely know

28:14

what's the right direction. You can

28:15

guide it. I have like a vision document

28:17

that I tried some of that but

28:21

the bottleneck is still sinking and like

28:25

having taste. [laughter]

28:27

Yeah, taste is very important. Uh how do

28:29

you define taste? This is something that

28:31

in my conversations with people everyone

28:33

understands taste is the moat but nobody

28:35

agrees on what taste good taste is. So

28:38

I'm just curious to hear yours. I think

28:40

in this day and age is like

28:43

the very low level of taste if if it

28:45

doesn't stink like AI and you know

28:47

exactly what I mean you know if if

28:49

something is just so writing style

28:51

personality

28:52

>> also also also UI by now you've seen so

28:55

many so much aentic built UI that you

28:58

immediately know if it's AI

29:00

>> yeah if it has the the color border on

29:02

the left right

29:03

>> yeah I mean for a while it was like the

29:05

purple gradient but much more so I I

29:07

feel It's it's like a feeling the same

29:12

as you can identify AI written slop

29:16

right away.

29:16

>> Yeah.

29:17

>> Um that's why I say it's a smell. Like

29:20

even if you can pinpoint this, you will

29:22

know. So So that's probably the lowest

29:25

the lowest characterization of taste.

29:27

And and then going higher up because now

29:30

so much of software is is automatable.

29:33

There's actually much more time you can

29:34

spend on like the little details. I

29:36

don't know, you know, like like just

29:39

when you when you when you when you run

29:40

open claw, you get like a little message

29:43

uh that sometimes roasts people.

29:46

Those are like the delightful details I

29:48

think that

29:49

>> you'll just not get if you prompt in a

29:51

high level.

29:52

>> Yeah. One one of my favorite tastes of

29:54

yours is how you you uh really put a lot

29:56

of work into your soul soulm and you uh

29:59

you know open source your approach and I

30:02

don't think people worked on enough soul

30:04

until until you came along. So I think

30:06

that's really interesting. Uh my I I I

30:08

have a podcast I haven't done yet. I

30:10

haven't released yet with uh Mikuel

30:12

Parakin, who was the CTO of Shopify now,

30:14

but he was the uh guy leading Bing where

30:17

Sydney was uh the original sort of

30:20

unaligned chatbot [laughter] that

30:22

emerged. Uh but I think people really

30:24

have fun when when your soul your

30:26

chatbot has personality. Your clanker uh

30:29

you know has different obsessions.

30:31

>> Well, it wasn't because it the world

30:33

changed, right? We had we had chat GBD

30:38

in 2023 and 4 and it was basically

30:43

us having AI without understanding what

30:45

AI can do. So we rebuilt a Google so you

30:48

have like a search field and like you

30:50

get a response and you you don't expect

30:52

Google to have a personality.

30:54

>> Yeah. But now that we moved more towards

30:57

agents, like if if I I didn't think

30:59

about in the beginning WhatsApp relay

31:01

and I just hooked it up to cloud code.

31:05

Um and then I when I was on WhatsApp, I

31:08

noticed that it doesn't feel quite

31:09

right. Like even even though like cloud

31:12

code already has some personality, it

31:14

didn't really fit how people would write

31:16

to you on WhatsApp. So that that's how

31:18

my whole iteration started was like uh

31:20

this again it's about taste, right? It

31:23

doesn't feel quite right. It's like too

31:24

wordy. It uses too many dots. It it it

31:27

my friends text different. And then

31:29

that's how I started working. They say,

31:30

"No, this isn't like try to write more

31:33

like a human." [laughter]

31:36

>> Uh yeah, I I actually run a writing

31:38

>> like a lobster.

31:39

>> Uh like a lobster. Yes. Um

31:43

uh you know the one of my favorite

31:44

quotes of yours is uh madness with a

31:46

touch of sci science fiction. Yeah.

31:49

Right. Like that this is how you run

31:51

>> um uh AI projects. And I think

31:54

>> not all the art projects, but

31:55

specifically

31:57

something like OpenClaw would have never

32:00

been able, it would not have come out of

32:02

an American company just because it

32:04

would have been killed in legal long

32:07

before it would have been released

32:08

because it just has some problems that

32:11

we haven't really solved as an industry

32:12

yet.

32:13

>> Yeah.

32:13

>> But now we have some mitigations and

32:15

it's getting better. The models are

32:16

getting a lot better. But I don't see

32:21

how any of the big labs could have

32:23

released that. You know, it would be too

32:24

much push back. Oh, and like not enough

32:28

market proof that this is what people

32:30

want.

32:30

>> Yeah.

32:30

>> So like it had to be done by someone

32:35

>> like

32:36

>> outside. Yeah. That that that

32:38

>> sitting

32:38

>> like literally like when I when I built

32:40

it in the very beginning, I was like,

32:41

"Oh, what's the worst that can happen?"

32:43

like it could exfiltrate my token,

32:47

my emails. Yeah, nothing is nothing

32:50

nothing's in there that would like

32:51

completely kill me. You could like

32:53

upload some of my pictures. I was like,

32:55

yeah, I guess the worst are already

32:56

online if you use Grinder. Um,

32:59

[laughter]

33:00

so it was like it was like,

33:02

okay, I can live with that risk. It will

33:04

be uncomfortable, but it's like it's

33:06

manageable.

33:07

>> Yeah.

33:07

>> Uh, if your company is a different it

33:10

requires a little different approach.

33:12

>> Yeah. By the way, uh his Instagram

33:14

account, good follow under

33:16

underfollowed.

33:17

[laughter]

33:18

It's also it's also has some good stuff.

33:20

Um okay. Uh you were talking about

33:22

WhatsApp, talking about Telegram. A lot

33:24

of these text apps. Um uh text apps are

33:27

good. People are also looking for like

33:28

the next form factor. People want like

33:30

the maybe the the glasses, the earbuds.

33:33

What What is your sort of wish list in

33:36

terms of having agents in your life?

33:42

I started on that actually already, but

33:44

then I was just getting bogged down by

33:48

all the people using it and just like

33:52

the daily grind.

33:55

But if you're at home, I want to be in

33:58

any room and you know at Star Trek when

34:01

you can when you say computer

34:05

I I I want to like talk to my agent

34:07

wherever I am and it should just be able

34:09

to like respond to me. It should know

34:11

where I am. I have like little iPads in

34:14

every room and and my agent can use the

34:16

canvas feature and project stuff on

34:18

those iPads. So like if I ask a question

34:21

that that is like easier to be to be

34:23

answered by also showing me something

34:25

like it could use like the nearest

34:26

display because it's aware of where I

34:28

am. So the phone is just a very

34:32

convenient input point but I kind of

34:34

want to like talk to it from anywhere.

34:36

Yeah.

34:36

>> Like yeah if I'm around and I have

34:37

glasses I should just like be able to

34:39

like listen in and like project

34:40

something on me.

34:42

>> Um

34:43

>> but just ubicular follow you

34:45

>> I think yeah once we have

34:47

>> really smart home. Yeah,

34:49

>> like agents on your phone, but really

34:51

you want ubiquitous agents and then you

34:53

want maybe you will have your your your

34:57

uppercase open claw your private agent

35:01

at work. You might have your I don't

35:03

know lowerase openi claw

35:07

and then

35:11

that claw should be able to like talk to

35:13

your personal claw uh in a way that both

35:18

your company and you are comfortable

35:19

with. So that's kind of like the future

35:20

where we need to work out.

35:22

>> Yeah. Uh one of uh I just

35:24

[clears throat] did a podcast with Maran

35:25

Dre who's a huge fan uh and and also uh

35:28

have conversations with Andre Karpathy.

35:30

Both of these guys are running OpenCloud

35:32

to run their house. And I think OpenClaw

35:33

for homes is like a kind of underrated,

35:36

but like people are really discovering

35:37

it. And my funniest sort of irony is

35:40

that is it's only possible because the

35:42

internet of means that most smart

35:45

devices are terrible in security, which

35:46

means Open Core can run them.

35:49

>> Oh, it's going to be able to work so

35:50

much better in in a few months when the

35:52

models are getting really bad.

35:54

[laughter]

35:55

>> Yeah, they're very good. Um, okay. One

35:58

security question. uh about prompt

36:00

injection. How do you want to solve

36:03

prompt injection or what what uh ways in

36:06

which uh have you been thinking about

36:09

the prompt injection problem?

36:12

Probably not enough yet. On the other

36:14

hand, like the the the front end models

36:17

are really quite good at detecting all

36:20

the

36:22

all the cases where like just stuff

36:25

randomly comes in from a website or an

36:27

email is usually not a problem anymore.

36:29

You mark as untrusted content, very hard

36:32

to excfiltrate you from that. If if I

36:36

have unlimited access to your claw and

36:39

can bombard it with stuff, then there's

36:42

still a chance.

36:43

>> Then then there's still a chance. But

36:44

like for one of things,

36:46

>> it's no longer the biggest problem. If

36:48

you use that's also why why you know

36:50

that this is probably the angle where

36:51

like some people say, "Oh, Peter doesn't

36:53

like local models." But then I see like

36:55

people running like a 20 uh billion

36:58

parameter model that just does whatever

37:01

you tell it and and it's not trained to

37:03

have any defenses at all. That's still

37:06

problematic. If you run that and then

37:08

you use a web browser or email um would

37:12

worry me. That's why that's why OpenClow

37:15

warns you if you use a small model. And

37:17

I know people spin the whole thing like

37:18

we hate model. I I love I love I love

37:21

that it we support everything, but like

37:23

you have to

37:26

steer

37:28

the regular user a little bit into a

37:30

direction to make it harder for them to

37:32

shoot themselves in the foot.

37:34

>> Um

37:36

yeah, there there is some ideas for

37:38

problem injection. It's

37:40

[snorts]

37:42

>> just a little bit away. I haven't

37:44

announced that.

37:45

>> I think Simon Willis has been working a

37:46

lot on on this. is I mean he coined the

37:48

term prompt injection and the sort of

37:50

dual LLM approach seems smart uh and I'm

37:54

I'm not smart enough to figure out all

37:56

the ways that which it can be attacked

37:58

like at at some point trust just has to

38:00

be a thing right um and uh and I pro

38:04

something interesting I found out from

38:05

talking with Vincent who's speaking next

38:07

is that you guys had to implement the

38:08

same trust system that Toby Luca had to

38:10

implement which is uh you build

38:13

reputation over time and things with

38:15

more trust uh gets more privileged

38:18

access, right? And I think that that

38:20

makes sense.

38:23

>> That's part of the story.

38:24

>> Yeah. Yeah. Yeah. Um okay, so uh some

38:28

more broader questions. What cool

38:30

projects would you like to work on once

38:31

you have more free time?

38:33

>> I mean, I wanted to work on dreaming and

38:35

know like my maintenance worked on

38:36

dreaming while I I'm there like

38:38

>> while you were dreaming.

38:39

>> Uh so shift it, right?

38:41

>> Yes. What what is dreaming? Uh it's like

38:44

a way to reconcile memories and like

38:46

kind of create a little bit like like a

38:48

dream log go through like your session

38:50

logs. Um

38:53

>> we we found out from the enthropic

38:55

source code leak that they also working

38:57

on dreaming, right?

38:58

>> Oh yeah. Yeah. I mean there's

39:00

I'm pretty sure there's like more

39:02

companies working on that. But think a

39:04

little bit like how do we learn as

39:05

humans? You you experience a lot of

39:07

things during the day and then you sleep

39:10

and and in sleep your your brain does

39:12

like a garbage collect

39:14

converts some me some

39:17

local locally stored memories into

39:19

long-term storage and like drops others

39:22

and that that's similar ideas that I

39:24

think could also be very useful for

39:26

agents. Um and then like what we shipped

39:29

on dreaming is like the first little

39:30

step in that direction.

39:31

>> Yeah. It's related to the wiki uh thing

39:34

that Andre has been talking about where

39:37

you sort of collect everything into a

39:38

>> wiki is is more memory but like

39:40

everything kind of blends a little bit

39:41

together. Um that the beauty the beauty

39:44

of open claw is that we can just try

39:46

stuff you know like like everything what

39:49

we worked on for the last months or so

39:51

is that

39:53

in the beginning it was a big spaghetti

39:55

codebased mess and now like everything

39:57

everything is an extension a plug-in. So

39:59

you can replace memory, you can add the

40:01

wicki, you can add dreaming, you can add

40:05

I don't know your your your whatever

40:08

crazy idea you have and just make it

40:09

your own. You don't have to send

40:11

everything to a pull request because

40:13

we're still completely overloaded on

40:14

those. But it's it's more like Linux

40:17

where you just can install your own

40:19

parts.

40:20

>> Yeah. Yeah. And uh you are building what

40:24

a lot of people think uh is the most

40:27

consequential open source since Linux

40:29

which I don't know how do you deal with

40:30

that? How do you deal with the the the

40:32

fame what is a day in your life uh as as

40:36

the BDFL effectively of something like

40:39

this?

40:40

>> What's my Well, there's still a lot of

40:42

coding. There's also a lot of

40:44

>> by the way in in between sessions he was

40:46

coding [laughter]

40:48

back there.

40:49

>> Yeah. They get tokenized. You have to

40:50

like something has to be right.

40:51

>> You have to push the agents, right?

40:53

>> Yeah. Um

40:56

where it shifted a little bit now it's a

40:58

lot more a lot more talking and

41:02

steering people in the right direction

41:04

like because there's a lot of things

41:06

that we already learned at Open Claw. So

41:08

like part of my role at OpenI is like to

41:10

like help them not make the same

41:12

mistakes again. Um

41:15

and then and then open claw is like try

41:17

out new things that seem exciting and

41:19

some might work and some might not work.

41:21

Enable enable companies to like build

41:25

their own claw without having to fork

41:26

away but like making everything more

41:28

more customizable. Um yeah and sometimes

41:31

I sleep sometimes you sleep. Okay great.

41:34

Uh I think that maybe this is the last

41:36

good closing questions. Uh, what skills

41:38

do you want humans and engineers in

41:40

particular to focus on developing in the

41:42

age of AI?

41:48

>> Taste was a big one, but I already

41:49

mentioned that

41:53

system design is still very important.

41:56

>> Yes, you we talked about this in San

41:58

Francisco. Yeah,

42:00

>> if you don't think about that, you will

42:02

eventually swipe yourself into a corner,

42:05

right? Just by defining the boundaries

42:09

like the funny thing is like everything

42:11

is in the clanker but you still need to

42:13

ask the right questions otherwise

42:16

that makes the difference of like good

42:18

code that comes out or like really bad

42:20

code that comes out and that's still

42:21

where like all the knowledge you have

42:23

like how you build software you can

42:25

apply to steer the agent into into

42:28

something that is not slop.

42:31

>> Yeah. And then I think I think a skill

42:32

that is becoming more and more important

42:35

is saying no.

42:38

And and and that's something I had to

42:40

learn as well because

42:42

even the wildest idea is just just a

42:45

prompt away.

42:47

And usually this one idea is never the

42:49

problem but like this idea and this idea

42:52

and this idea and this idea and then how

42:54

all of that fits together that's the

42:56

problem.

42:57

>> Yes. So like

42:59

I think we're still bottlenecked on

43:01

syncing and about like big picture

43:03

syncing because imagine the world from

43:06

your clanker like you're being thrown

43:08

into a code base. You might have an

43:11

outdated agent.md file, but you

43:13

basically don't know what DF this is and

43:15

you like then like you tell me, hey, add

43:18

user profiles and you like somehow add

43:21

user profiles and connect it to the two

43:23

things you see, but you didn't see the

43:25

whole system, right? And then that's

43:26

where a lot of those localized solutions

43:28

comes where like your project has like

43:30

vS and and it's our job to like help the

43:34

agent do its best work by like providing

43:35

them with like hints. Hey, you want to

43:37

consider this? You want to look there?

43:39

How would this interplay with this? And

43:41

then and then ultimately you get like a

43:42

much a system that actually is

43:45

maintainable.

43:46

>> Yeah. Um well, thank you for maintaining

43:49

one of the most important software of

43:50

all time and thank you for spending time

43:52

with us.

43:52

>> Thanks for having me. [applause]

43:54

>> Hopefully you stick around and answer

43:55

questions. Thank you.

43:56

>> All right.

44:01

[music]

44:06

[music]

Interactive Summary

Peter Steinberger, creator of OpenClaw, the fastest growing open-source AI project now supported by OpenAI, discusses its rapid growth, technical challenges, and future vision. He addresses the widespread perception of OpenClaw being insecure, explaining that many critical advisories are often low-risk in practical use, or stem from users ignoring security recommendations. He highlights the burden of dealing with AI-generated security reports and the need for human discretion. Steinberger emphasizes OpenAI's support for OpenClaw's open-source nature to foster broader AI adoption, and the formation of the OpenClaw Foundation to hire full-time staff and ensure project quality. He also shares his iterative coding workflow, the importance of 'taste' and system design in the AI age, and his vision for ubiquitous, customizable agents capable of 'dreaming' and operating with user data control.

Suggested questions

6 ready-made prompts