
Security Intelligence OpenClaw and Claude Opus 4.6: Where is AI agent security headed?
Feb 11, 2026
Jeff Crume, a Distinguished Engineer focused on AI and data security; Nick Bradley, an incident response and operations expert; and Sridhar Muppidi, IBM Fellow and security CTO, debate fast AI adoption risks. They compare open-source OpenClaw to Claude Opus 4.6, warn about unvetted agents and shadow AI, dissect the Notepad++ supply chain breach, and explore ransomware commercialization and attacker scaling.
AI Snips
Chapters
Transcript
Episode notes
Agent Risk Comes From Privilege, Not License
- Open-source and proprietary agent approaches offer different tradeoffs but share the same core risk: autonomous access with minimal supervision.
- Sridhar Muppidi and Jeff Crume emphasize that agent security risks come from capabilities and privileges, not just licensing.
Enforce Least Privilege For Agents
- Do apply the principle of least privilege to any AI agent and limit access duration and scope.
- Jeff Crume warns against granting system-level privileges to opaque third-party agent code.
Offer Sanctioned Agent Alternatives
- Do provide sanctioned, approved agent options so employees avoid shadow AI.
- Nick Bradley and Sridhar Muppidi urge organizations to say how agents should be used, not just ban them.



