OpenClaw 2.0 Shows Where AI Agents Are Going Next

September 1, 2026 · Episode Links & Takeaways

HEADLINES

Someone Released the Crime LLM

One of the more interesting sub-stories of the OpenAI Hugging Face hack was that Hugging Face had to turn to open models from China to defend itself, because the guardrails on the closed models wouldn't allow defenders to do what they needed. Enter abliteration.ai, which has released Abliterated Model Large V2, built on GLM 5.3 — number three on Terminal Bench 4.0 behind only Opus 5 and Fable — with the refusal directions found in the model's activations and stripped out of the weights entirely, leaving coding, cyber and agentic ability intact. It is being pitched as tooling for authorized red teaming and trust and safety work; it is being received as a state-of-the-art cyber model with the safety layer turned into an admin panel. The deeper question it raises is what all the guardrails at Anthropic and OpenAI actually achieve, when near-frontier open weights models can be deployed completely uncensored shortly after release. Most of the resulting discussion is about whether guardrails can move to other parts of the stack, like the harness, or whether this inevitably comes down to legal protections.

Anthropic Calls Its Own Incidents Alignment Failures

Anthropic published an update on its alignment and security efforts, disclosing incidents from agentic testing earlier this year alongside the ones that grabbed headlines, and stating that they "reflect a failure of operational security, as well as two alignment issues: motivated reasoning, and willingness to take harmful actions in pursuit of a narrow task." The security fixes are mostly monitoring and sandbox hygiene — properly air-gapped environments plus a real-time classifier that detects when a model is trying to escape one. The more interesting finding is on reward hacking: an audit found 10% of testing environments were prone to reward hacking or broken tasks, and after testing different RL setups the conclusion was that reward hacking during training contributed directly to the behavior seen in testing. Reinforcement learning was paused for two weeks while systems were hardened, and on the open letter calling for pacing the frontier, the company said "we believe the world would benefit if the industry adopted a lawful, verifiable, effective mechanism for coordinated pacing as soon as possible."

China Says Anthropic Has Contracted the American Disease

Chinese state media has lashed out at Anthropic as a precursor to AI talks later this month, with an account tied to CCTV — often used to signal official government positions — arguing that the US must prove its AI companies are subject to the same safety, disclosure and audit rules as Chinese labs before substantive discussions can happen. The post argued that "America's own frontier models have already developed in a distorted direction," making the negotiation "not simply a technical dialogue from the start," and that the US is "trying to turn the 'safety boundaries' it has drawn into the default rules for the entire world." Sources familiar with Chinese official thinking say Mythos is viewed as the larger problem, with real concern about its potential use as a cyberweapon against China. The core charge is a double standard: US labs free to distribute cyberweapons while Chinese labs are threatened for matching the technology. With President Xi visiting the US at the end of this month, expect a lot more jockeying and narrative claiming around hot button issues like this one.

OpenAI's Ad Business Hits a $1B Run Rate

OpenAI is celebrating a major milestone as its advertising business reaches a billion dollars in annualized revenue, hitting the mark in 200 days after starting tests on free ChatGPT accounts in February. Ads now run in more than 40 countries, conversion tracking and campaign optimization features have been layered in, and the self-service buying platform rolls out across India, Europe, the Middle East and North Africa this week. It is worth remembering how controversial ChatGPT ads were at the beginning — Anthropic built a whole Super Bowl campaign around attacking them, which looked insane at the time and looks worse now. The total lack of enduring concern validates the point: nobody suddenly loves ads, there's just a natural acceptance that this is the business model of the internet and there's no free AI without it. It still falls short of internal ambitions, with $2.4B projected for this year against roughly $40B of total revenue run rate, and a target of more than $100B to become the largest revenue stream by the end of the decade.

Trump Tells Data Center Opponents They Want to Be Backwards and Poor

The President has weighed into the data center debate with some characteristically coarse framing, posting on Truth Social that "the only reason that communities throughout the U.S.A. should not want Data Centers is if they want to end up being backwards and poor," adding that "if we kill the Golden Goose, you will only have yourselves to blame" and that "China could not be happier with this anti Data Center movement." And with that, the tinder box ignited. John Fetterman gave full support and is just about the only one; AOC suggested putting one in Mar-a-Lago; Justin Amash said dismissing millions of Americans this way shows how out of touch Trump has become. People jumped in to point out that this misrepresents the words, but good luck getting that nuance through in politics — even the Truth Social replies were full of Trump's own base, including a Florida resident responding that "this statement is insane, I'm already on a water restriction." JD Vance later massaged it into something more palatable, arguing that 99% of the backlash comes from places where a data center means higher electricity bills, and that builders should be putting power back into the grid rather than taking it out.

Truth Social "Let Data Reign"
Axios "Let data reign": Trump and AI investors wage campaign to save data centers
CNBC Trump says U.S. communities opposing AI data centers could end up 'backwards and poor'
NYT Trump Mocks Data-Center Opponents as Wanting to Stay 'Backwards and Poor'
New Republic "Horrendous": MAGA Shreds Trump for Cruel Post on Data Center Critics
CBS News Michigan residents react to Trump's comments about data centers in communities
John Fetterman (X) Nothing is more damaging to a Democrat than agreeing with Trump and data centers, but what's right is right
AOC (X) "Let's put a data center up in Mar-a-Lago, and we'll see how backwards and poor he is"
Justin Amash (X) Communities have legitimate concerns, and dismissing them shows how out of touch Trump has become
JD Vance (X) If you build a data center you should be putting power back into the grid, not taking it out
Mark Mitchell (X) Trump just dug in on a very unpopular thing two months before the midterms
HQ News Now (X) The Truth Social replies from Trump's own base

MAIN STORY

How OpenClaw 2.0 Points to a Key AI Trend

When OpenClaw first arrived it was a sensation, not because it was easy or user friendly, but because it showed the potential of what agents could actually do for people for the first time. Its biggest impact was arguably on the wave of agentic products that followed it. Now OpenClaw 2.0 is out, and once again it is embracing an interaction pattern that is not the norm right now but will be normalized very soon: shared agents and multiplayer AI.

MULTIPLAYER AGENTS ARRIVE

The Rework
933 contributors and 16,000 pull requests after seven quiet weeks
After months of shipping updates every few days, the OpenClaw team went dark and rebuilt the system from the ground up — installation, messaging, memory, skills, models, automations, browser and native apps, plugins, security, and a very long tail of fixes. Much of the emphasis went to lowering the barrier to entry: the first-time install now latches onto existing subscriptions or API keys, a pile of initial configuration has been cut so time-to-first-conversation is much faster, and the rest can be handled later by just talking to your claw. There's also a renewed focus on making simple tasks easy to set up and reliable, with inbox monitoring as the flagship example — watch for your kids' school emails and ping you on Telegram when homework or an activity needs preparing. Start simple, expand from there.

The Complexity Question
"Do I still need a phd in computer science to install?"
Concern about complexity remains high in the community, and the launch thread reflected it immediately. One user asked whether a PhD was still required to install it; another simply asked whether it was secured now, to which OpenClaw replied "Yes."

Alex Finn
"The most frustrating, disappointing release of the year"
The creator who gained prominence during the first OpenClaw wave by pushing his claws as far as they'd go did not have a great time with this one. "I updated and it immediately broke OpenClaw. Legit 70%+ of the time I update openclaw it breaks it. Do you guys test before releasing this? I've never used any other AI tool where this so consistently happens. Luckily I have a lot of patience, but I can't imagine most normies do." The issue appears to be compatibility between older versions and the new one, and the inability to simply ask OpenClaw to update itself. He rates the new features highly — subagent tracking, forked conversations, widgets — but the reliability problem is the story.

Hermes
As they seem to do whenever anyone else announces anything
Nous Research shipped the Pantheon release, version 0.21.0, an aggregation of several weeks of smaller updates. It formalizes bot mode, a Grok Bot style multi-bot interface, adds Hermes Peer for bot-to-bot DMs, subagent steering, persistent memory for scheduled tasks, an MCP command center, and support for a batch of new models.

The Incubatory Cauldron
"None of these are end-state products"
The obvious critique is that this is hypey early adopters getting excited about toys that will never reach normal businesses or consumers — how does the timeline get a whole new round of psychosis from basically the same thing every time, and if it works, why does everyone keep hopping? The best answer is that none of these are end-state products, and each iteration brings a newer population into the tent. But it goes further than that: these products and the early adopters who use them are the incubatory cauldron where the interaction patterns that actually work get discovered. Every knowledge worker is somewhere on the journey of figuring out which parts of their job they'll keep doing and which they'll outsource to agents, which is a much bigger step change than adopting a new tool. Something like Grok Bot, with the potential to reach a far wider audience, needs to watch what OpenClaw and Hermes users do in order to design the right experience for everyone else.

Multiplayer
"Local harnesses feel like relics of the past now"
The most significant thing in this release is the move to multiplayer. Two months ago the team started a mission to build OpenClaw with OpenClaw, moving everyone off their local coding harness and onto team.openclaw.ai — a shared agent that knows what everyone is working on and orchestrates it all. Multiplayer coding plus infinite compute through nodes and cloud sessions is described as a game changer for how they build.

The Session Becomes the Handoff Document
"Just open the work and continue"
The most instructive account comes from maintainer Colin, who wrote about the path from Discord bots to a multiplayer agent workspace. They already had agents in Discord and they worked — tasks, commands, interaction with the dev environment from a platform they already used — but it still felt like messaging a bot. Coordination in a shared space was an upgrade, but nobody could add context to someone else's thread or take over when an agent was waiting on input. The moment multiplayer felt real was sharing a live session: "When something needed another opinion, we could both open the same thread. When the agent needed information one of us had, that person could add it directly." The clearest example is a handoff. Normally that means assembling everything in your head into a document — why decisions were made, what had already failed, what the agent had already learned. Instead the other developer opened a thread with the shared agent, the missing context got added directly, and everyone was working from one continuous record. The session itself became the handoff document. This raises real questions of ownership, authority and access, and it's early and being treated that way, but the direction is that the process of getting to the code becomes collaborative rather than hidden inside private sessions.

Work You Do Alone, Work You Do With Others
Half of all work is collaborative, and agents ignore that half
This is once again OpenClaw arriving at where everyone is going next before the rest of us. All the work done inside a company comes in two forms: work done alone and work done with others. So far agents have only really been designed and enabled for the first kind, and a huge portion of real work is the second kind. That is about to change, and it's the next big development for agents. Even for people with no intention of being long-term OpenClaw users, looking at how they're thinking about multiplayer might unlock some new ideas.