In February, Meituan launched a company-wide AI pilot playfully dubbed the "shrimp farming movement," rolling out the open-source agent OpenClaw at massive scale. Employee enthusiasm ran high—but so did the costs. At peak periods, AI bills consumed over ten million yuan per day, and some agent-generated errors began to interfere with real business operations. Months later, OpenClaw founder Peter Steinberger delivered an unusually candid post-mortem at Startup School 2026, recounting the eight months that followed the project's viral breakout.
OpenClaw followed a textbook "open-source agent rollercoaster trajectory": born from personal need, iterated rapidly, yet exposed almost overnight to security vulnerabilities, configuration chaos, and cost overruns when enterprise demand came flooding in. Industry wags have joked that even China's top listed companies found themselves on the same starting line as an open-source project when it came to data security scrutiny. The remark cuts to the heart of the matter: open-source AI tools are advancing in capability far faster than enterprises can build the security and cost governance frameworks needed to contain them.

The most telling data points from the retrospective: despite external claims that 20% of OpenClaw's Skills carried malicious code, a full scan of all 67,000 Skills showed the real ratio was closer to 0.3%. Yet the project still ballooned to roughly 9,500 configuration items—so unwieldy that the founder himself gradually stopped using his own product. Security reports, media noise, and ever-expanding user demands collectively hijacked the product roadmap.
These numbers sketch the real predicament of open-source AI deployment: failing to define security boundaries early traps teams in an endless loop of hardening; unchecked configuration bloat strips products of their original simplicity and usability; and runaway bills make any aggressive pilot unsustainable. Meituan eventually identified a handful of viable use cases through its competitive horse-racing mechanism, but the price was more than four months of corrective iteration.

OpenClaw's rollercoaster offers a clear lesson for the agent industrialization effort: as agents evolve from personal toys into enterprise collaboration tools, the truly scarce resource is no longer model-calling capability—it is an observable, orchestratable, and governable runtime system. This is precisely the direction StarWar Technologies has been pursuing with its OPC Agent Collaboration Platform, enabling enterprises to manage agent permissions, costs, and operational boundaries with the same rigor they apply to traditional software.
Across the broader industry, the tug-of-war between open source and commercialization is accelerating. Open-source projects trade on community momentum and visibility to buy iteration speed, yet repeatedly absorb losses on the responsibility front of governance, security, and scaling. Commercial platforms, by contrast, bake governance in from day one—at the cost of ecosystem openness. The choice is not binary. A growing number of enterprises are adopting a hybrid model that pairs "open-source kernels with platform-level governance."
For enterprises evaluating agent deployment today, OpenClaw's eight months serve as a masterclass in risk education: define your processes, organizational readiness, and security boundaries first—then talk about scale. That is the correct way to approach AI transformation. Tooling can iterate quickly, but engineering infrastructure cannot be rushed.