NVIDIA NemoClaw: The Story of Caging a Brilliant Lobster
*English translation of a zhichai.net forum post about NVIDIA NemoClaw and the OpenShell security framework.*
Key points
- The problem: OpenClaw, a popular AI assistant framework, is powerful but overly autonomous — it can read files, send emails, and modify systems with little built-in judgment about what it should or shouldn't do.
- The announcement: On March 16, 2026, at GTC in San Jose, NVIDIA CEO Jensen Huang introduced NemoClaw, a solution built on a security layer called OpenShell.
- Core idea: Instead of restricting the agent from the inside, OpenShell builds a "cage" *around* it — safety by boundary, not by muzzle.
- Allow external network access, but require approval first
- Allow reading documents, but not modifying or deleting them
- Allow sending email, but only to internal domains
- Allow database access only 9 AM–6 PM
- Isolated execution — incidents cannot affect core systems
- Full audit logs traceable to every decision
- Controlled data flows preventing accidental leaks
- Declarative, version-controllable security policies, managed like code
Why an external cage matters
Traditional security software runs inside the same system it polices — like a referee playing on the same team. OpenShell instead uses out-of-process policy enforcement: the control layer lives outside the OpenClaw process. Even a clever agent cannot bypass restrictions it cannot reach, just as a prisoner cannot redraw the prison's blueprints.
Three guardians inside the cage
1. Sandbox
When OpenClaw runs, it sees only a limited environment: some files visible, others not; some network addresses reachable, others effectively nonexistent. Crucially, the agent doesn't know it's sandboxed — the limits come from the environment itself, like a fish unaware of the glass.
2. Policy Engine
The sandbox is the "hard" wall; the policy engine is "soft" intelligence. Rules are declared in YAML, e.g.:
Rules can be adjusted dynamically at runtime without tearing anything down.
3. Privacy Router
Every data flow passes a checkpoint. If a task involves sensitive content (say, summarizing a confidential report), the router blocks the cloud and routes it to locally deployed models such as NVIDIA Nemotron; ordinary queries can go to the cloud; data can even be split — sanitized parts sent out, sensitive parts processed locally. Security becomes a spectrum, not an all-or-nothing switch.
From personal toy to enterprise infrastructure
With these safeguards, enterprises get:
Closing thoughts
The post frames this as democratization: OpenClaw democratized AI capability, and capability must be paired with democratized responsibility. NemoClaw doesn't limit OpenClaw — it unlocks it for organizations, not just enthusiasts.
> Security should not be a shackle on innovation, but the infrastructure that supports it.
Status: NemoClaw is in Alpha; APIs may change and documentation is still being refined.
References
1. NVIDIA NemoClaw official page: https://www.nvidia.com/en-us/ai/nemoclaw/ 2. NVIDIA NemoClaw GitHub: https://github.com/NVIDIA/NemoClaw 3. NVIDIA Developer Blog – OpenShell design principles 4. SiliconANGLE – GTC 2026 launch coverage 5. TechCrunch – OpenClaw enterprise security analysis