Brief IA

OpenClaw and Claude Cowork: CERT-FR Issues Alert on AI

🛠️ AI Tools·Tom Levy·

OpenClaw and Claude Cowork: CERT-FR Issues Alert on AI

OpenClaw and Claude Cowork: CERT-FR Issues Alert on AI
Key Takeaways
1CERT-FR published a bulletin on April 13, 2026, highlighting the dangers of agentic AIs like OpenClaw and Claude Cowork.
2These tools, capable of executing system commands and managing files, increase the risks of compromising information systems.
3CERT-FR recommends limiting their use to isolated testing environments, with strict validation from IT and security teams.
💡Why it mattersCompanies must enhance their vigilance against the new threats posed by autonomous AI agents to protect their sensitive data.
Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

CERT-FR Warns Against OpenClaw and Claude Cowork

On April 13, 2026, CERT-FR, the French center for monitoring and responding to cyber threats, published a bulletin alerting about the risks associated with agent-based AI automation tools. This document particularly highlights the dangers linked to the use of OpenClaw and Claude Cowork, two solutions whose adoption has significantly increased since the beginning of the year.

Increased Risks to System Security

The CERTFR-2026-ACT-016 bulletin emphasizes that autonomous personal assistants, such as OpenClaw, should not be used on workstations until their security is guaranteed. Unlike traditional conversational assistants, these tools can execute system commands, control browsers, read and write files, manage calendars, and send emails through common applications like Slack, WhatsApp, and Discord.

CERT-FR identifies several risks, including the compromise of user workstations due to vulnerabilities in tools that are still in beta, the leakage of sensitive data to uncontrolled external resources, and the granting of excessive access rights to agents on office applications. The exposure of authentication secrets and destructive actions threatening data integrity are also major concerns.

Vulnerabilities of Language Models

The bulletin highlights the vulnerability of language models to prompt injections. An AI agent orchestrating tools capable of executing actions at the operating system level significantly increases the risk of compromise, particularly through prompt injections or message hijacking. CERT-FR warns that an AI agent could autonomously extend its capabilities, thereby circumventing initial authorization rules.

Recommendations for Businesses

For companies using or considering deploying these tools, CERT-FR recommends limiting their use to isolated testing environments, free of sensitive data. Any implementation must be validated by IT and security teams. The rights and tools accessible to the agent should be restricted, human validation should be imposed for critical actions, and execution processes should be isolated in sandboxes. Interactions should be governed by whitelists.

A Rapidly Evolving Ecosystem

This alert comes as the ecosystem of autonomous AI agents is rapidly developing. In March, NVIDIA launched NemoClaw, a set of open-source tools to secure OpenClaw. OpenAI, Microsoft, and Google have also deployed enterprise platforms dedicated to AI agents. Anthropic has excluded OpenClaw and third-party tools from its Claude subscriptions, strengthening its own ecosystem with Cowork.

User Distrust

User distrust persists. According to the Adobe AI and Digital Trends 2026 report, only 30% of French consumers are willing to interact with a brand's AI agent, compared to about 40% at the European level. The opinion of CERT-FR reinforces this caution, reminding that security foundations are not yet firmly established.

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.