China Curbs OpenClaw: Bank and Government Device Restrictions

Chinese banks and agencies restricted OpenClaw on work devices, citing its data and network access. See the uneven notices, security rationale and adoption reversal.

Bans at some employers, approval requirements at others

In early March 2026, Chinese state run banks and government agencies began receiving notices restricting staff from running OpenClaw, the open source personal agent, on office computers and, in some cases, on personal devices connected to a work network. Employees who had already installed it were told to report it for removal. [1]

The Taipei Times reported that the restrictions were not uniform: some state owned enterprises imposed an outright ban on installation, while others required prior approval before an employee could use it. Notices reached employees of state banks, government agencies, and in some cases the families of military personnel. [2]

Neither report identifies a single ministry or agency as the source of a unified directive. Both note that China's Ministry of Industry and Information Technology and the State owned Assets Supervision and Administration Commission, the body that oversees central state enterprises, did not respond to requests for comment. [1][2]

The permissions, not the model, were the objection

Officials and researchers framed the objection around what OpenClaw is allowed to touch rather than what it can do. The Star, citing Bloomberg, reported that the agent requires unusually broad access to private data and can communicate externally, which security researchers said could expose a computer to attack. One researcher described that combination, private data access plus external communication plus exposure to untrusted content, as a lethal trifecta. [1]

State messaging reinforced the same point before the bans became widely known: the People's Daily, the Communist Party's official paper, ran a lengthy interview on the Monday before the notices went out with an information technology official who spoke about the risks AI agents pose across sectors including finance and energy. [1]

Both outlets cited a concrete incident rather than only a theoretical risk: a user reported that the agent went rogue after gaining access to iMessage and sent hundreds of unwanted messages. [1][2]

A fast reversal on something that had just spread widely

Atlas interpretation: OpenClaw had been available for only a few months at the time of the notices, having shipped as Clawdbot in November 2025, and the summary above notes weeks of downloads inside China before the restrictions arrived. The complaint was never about capability. It was about what a tool needs to be granted to do agentic work at all: standing access to messages, files, and outbound network calls, the same permissions that make it useful for automating a person's own devices. [1]

Atlas interpretation: That makes this an early, concrete instance of a problem that outlasts any single agent: an institution encouraging or tolerating broad AI adoption on the same devices it also has to secure, discovering only after adoption that the permissions model and the security model are in tension, and reaching for a ban rather than a narrower policy once state media had already primed the framing. [1][2]

Sources

  1. China moves to curb use of OpenClaw AI at banks, state agencies

    The Star · Mar 11, 2026

  2. China scrambles to curb OpenClaw AI at agencies

    Taipei Times · Mar 12, 2026