Security Intelligence

OpenClaw and Claude Opus 4.6: Where is AI agent security headed?

Feb 11, 2026
Jeff Crume, a Distinguished Engineer focused on AI and data security; Nick Bradley, an incident response and operations expert; and Sridhar Muppidi, IBM Fellow and security CTO, debate fast AI adoption risks. They compare open-source OpenClaw to Claude Opus 4.6, warn about unvetted agents and shadow AI, dissect the Notepad++ supply chain breach, and explore ransomware commercialization and attacker scaling.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Agent Risk Comes From Privilege, Not License

  • Open-source and proprietary agent approaches offer different tradeoffs but share the same core risk: autonomous access with minimal supervision.
  • Sridhar Muppidi and Jeff Crume emphasize that agent security risks come from capabilities and privileges, not just licensing.
ADVICE

Enforce Least Privilege For Agents

  • Do apply the principle of least privilege to any AI agent and limit access duration and scope.
  • Jeff Crume warns against granting system-level privileges to opaque third-party agent code.
ADVICE

Offer Sanctioned Agent Alternatives

  • Do provide sanctioned, approved agent options so employees avoid shadow AI.
  • Nick Bradley and Sridhar Muppidi urge organizations to say how agents should be used, not just ban them.
Get the Snipd Podcast app to discover more snips from this episode
Get the app