Currently submitted to: JMIR AI
Date Submitted: Jul 31, 2026
Open Peer Review Period: Aug 10, 2026 - Oct 5, 2026
(currently open for review)
Warning: This is an author submission that is not peer-reviewed or edited. Preprints - unless they show as "accepted" - should not be relied on to guide clinical practice or health-related behavior and should not be reported in news media as established information.
OpenClaw and the Automation of Medical Artificial Intelligence: Autonomy, Security, and Regulation
ABSTRACT
OpenClaw is an open-source autonomous artificial intelligence (AI) agent framework that has been rapidly adopted since its initial release in November 2025. Originally developed by Peter Steinberger under the name Clawdbot and subsequently renamed OpenClaw in January 2026, the platform surpassed 250,000 GitHub stars by March 2026, and a medical skills ecosystem of more than 800 community-curated tools has grown around it, spanning clinical documentation, bioinformatics, imaging, and drug discovery. In this Viewpoint we argue that the properties driving that adoption are the wrong optimization targets for clinical medicine. We term this the autonomy paradox: initiative, persistence, and autonomous action are valuable in productivity settings, whereas clinical systems are built around constraint, verification, and escalation. Three lines of evidence support this. First, a coordinated supply-chain campaign placed more than 1,200 malicious skills on the official ClawHub marketplace, and the ClawJacked vulnerability (CVE-2026-32025) allowed any website to take full control of a locally running agent without user interaction. Second, adversarial testing has reported average defense rates as low as 17% against sandbox-escape attacks. Third, an open-source project with no corporate entity cannot execute Business Associate Agreements under the Health Insurance Portability and Accountability Act, and the European Union AI Act classifies medical AI as high-risk, imposing conformity-assessment obligations that community-governed software is poorly positioned to meet. We conclude that near-term use should be confined to research and administrative contexts, and we set out the properties an agent framework would need before it could be considered for patient-facing deployment: causal grounding, deterministic or tightly constrained execution, action governance, audit by design, and human supervision.
Citation
Request queued. Please wait while the file is being generated. It may take some time.
Copyright
© The authors. All rights reserved. This is a privileged document currently under peer-review/community review (or an accepted/rejected manuscript). Authors have provided JMIR Publications with an exclusive license to publish this preprint on it's website for review and ahead-of-print citation purposes only. While the final peer-reviewed paper may be licensed under a cc-by license on publication, at this stage authors and publisher expressively prohibit redistribution of this draft paper other than for review purposes.