Hong Kong government workers warned not to install OpenClaw due to security risks
Government workers warned against installing the viral AI tool due to risks of data leaks and system intrusion.
Hong Kong authorities have issued a formal directive warning government workers against installing the AI agent OpenClaw, citing significant security vulnerabilities. The government's Digital Policy Office (DPO) confirmed to the South China Morning Post that it has reminded all bureaus and departments not to install OpenClaw or its variants on any machines connected to government internal network systems. While no specific security incidents have been reported, the DPO highlighted potential risks including unauthorized data access, data leakage, and system intrusion. The advisory reflects growing official concern over the security posture of the popular AI tool.
This move by Hong Kong follows a wave of similar restrictions imposed by mainland Chinese entities, including several brokerages, banks, and government bodies, which have begun limiting employee access to OpenClaw. In response to the mounting concerns, authorities recently released a set of six security guidelines, or 'dos and don'ts,' for organizations that choose to use the agent. These guidelines recommend users stick to the most recent official version, minimize internet connectivity or exposure, and allow the fewest permissions necessary. The Hong Kong Monetary Authority (HKMA) has aligned with this cautious stance, explicitly stating it has no plans to deploy OpenClaw on its internal IT systems, underscoring the financial sector's particular sensitivity to the tool's perceived risks.
- Hong Kong's Digital Policy Office banned OpenClaw from all government internal networks over security concerns.
- The warning cites risks of unauthorized data access, leakage, and system intrusion, though no incidents are confirmed.
- The ban follows similar restrictions by mainland Chinese banks, brokerages, and government entities.
Why It Matters
Highlights the critical security and compliance challenges enterprises face when adopting powerful, but potentially unvetted, AI agent technologies.