Published: 15:31, August 4, 2026
‘Raising lobsters fever’ cools as security fears mount
By Chen Xiyun
Customers queue outside an artificial intelligence “6S” store in Shenzhen on March 11, 2026, as the AI hub officially launched free installations of the OpenClaw AI agent. (ROBERT HOPE-JONES / CHINA DAILY)

In a school office in Chengdu, Sichuan province, geography teacher He Haowen put an artificial intelligence agent to a live test — a head-to-head exam grading match against a human colleague, with his computer automatically processing handwritten papers and logging the scores directly onto the portal.

“It raises our happiness tremendously by taking over exhausting manual labor,” he says. “It isn’t a self-contained brain, but an agile middleman using local tools as eyes, and cloud models as brains to bridge our daily workflow.”

The shift from “talking” chatbots to “acting” software proxies sparked a viral movement across the Chinese mainland earlier this year, dubbed “raising lobsters”.

Popularized by open-source agent frameworks like Open Claw — created in late 2025 by Austrian developer Peter Steinberger and iconic for its red lobster logo — these digital assistants deploy directly onto personal devices with broad control over local computer systems. To date, primary agent repositories on GitHub have amassed over 380,000 stars.

Yet, less than a year on, the “lobster fever” is rapidly cooling down, driven by the collapse of the “almighty agent” marketing myth as solo operators face burnout, alongside urgent alerts from cybersecurity experts over local computer hijackings and severe data privacy risks stemming from the AI proxy’s privileged system access.

People have OpenClaw AI agent installed on their computers in an artificial intelligence “6S” store in Shenzhen on March 11, 2026. (ROBERT HOPE-JONES / CHINA DAILY)

Early commercial pitches celebrated agentic AI as the birth of the “one-person company,” predicting solo entrepreneurs could run full enterprises without traditional employees.

But, real-world deployments have largely disproved this premise. Chen Peilin – a former chief technology officer with mainland innovative tea drinks chain HeyTea who now runs an AI startup building management solutions on Claw architectures – had experienced the friction firsthand. When he tried to automate operations by deploying agents across sales, invoicing, research and design, he downsized 40 percent of his workforce — only to find himself overwhelmed by oversight.

“I explicitly oppose the ‘one-person company’ idea, based on my own experience,” Chen says. Managing dozens of autonomous digital agents created acute cognitive overload. “Having around five human supervisors was exhausting enough. Instead of eliminating management, agents simply shift humans into AI overseers who must handle non-stop administrative friction.”

Beyond daily operational fatigue, Li Weichen — chief scientist at cybersecurity firm KnowSec – has warned of a subtle structural trap facing solo operators. As “one-person companies” rely heavily on third-party cloud models to execute daily business logic, their unique domain know-how, workflow structures and contextual prompts are continuously absorbed by LLM (large language model) vendors,” he says.

“When solo entrepreneurs embed their deepest industry insights into agent prompts, those behavioral logs are aggregated by model providers,” Li explains. “When the next model iteration upgrades, foundation model giants can easily absorb those specialized functions, effectively closing the window for independent niche startups and accelerating market consolidation into big-tech monopolies.”

READ MORE: 'Little Lobster' enthusiasm

Global enterprise data echo this operational ceiling. A study released by McKinsey & Company in April this year showed that while nearly two-thirds of surveyed enterprises worldwide have experimented with AI agents, fewer than 10 percent have scaled them to deliver tangible value. McKinsey researchers say shaky data infrastructures remain the primary bottleneck, with 80 percent of companies citing data limitations and fragmented governance as key hurdles.

US threat-assessment firm Gartner projected in May that 40 percent of enterprise agent deployments would be decommissioned by 2027 — not from coding flaws, but because autonomous code can’t assume legal or financial liability when errors occur, forcing human supervisors to remain stuck in the loop.

Despite the disruptive commercial reality, another driver for the market cooldown is security.

“Running an agent locally is like letting an eager intern live inside your computer,” says He Jing, associate professor and technology governance expert at Beihang University. “If you don’t restrict permissions or isolate environments, you’re one malicious script away from disaster.”

Malicious skills on open-source hubs rapidly surfaced, triggering a wave of regulatory crackdowns earlier this year.

In mid-March, mainland cybersecurity agency CNCERT warned that malicious prompts could trick local agents into leaking private API keys — the digital passcodes that grant access to paid AI models and cloud services — or deleting system files. Eleven days later, CNCERT released official safe-use guidelines, explicitly advising against installing unverified agents on daily work computers and urging users to isolate autonomous software within protected containers.

Simultaneously, Hong Kong’s Privacy Commissioner for Personal Data issued compliance warnings over data leakage risks. By May, the independent body set up by the Hong Kong Special Administrative Region government had stepped up enforcement, launching targeted privacy audits across 60 prominent organizations to inspect their AI implementations.

To eliminate setup headaches and severe security threats, mainland tech giants like Tencent have launched commercial wrappers like its QClaw for general users and WorkBuddy, designated for workplace scenarios, embedding agent capabilities into everyday apps like WeChat.

Customers queue outside an artificial intelligence “6S” store in Shenzhen on March 11, 2026, as the AI hub officially launched free installations of the OpenClaw AI agent. (ROBERT HOPE-JONES / CHINA DAILY)

Ji Xinsu – a senior cloud strategy expert at Tencent Cloud and former Gartner analyst – stresses that native open-source frameworks carry steep technical hurdles, requiring specific Node.js runtimes and complex local environment configurations that exclude non-technical users.

“Our goal is hiding technical complexity entirely behind the product experience,” Ji explains. “Instead of requiring users to write code or debug local runtimes, we turn agent interaction into simply sending a message inside WeChat.”

Beyond convenience, Ji notes that commercial wrappers establish essential guardrails. WorkBuddy, for instance, introduced a background “sandbox mode” that executes autonomous workflows and pushes automated results even when a user’s local computer is powered off.

To mitigate malicious prompt injection and system hijacking, enterprise wrappers channel agents through an internal “Skill Hub” — a vetted, permission-controlled repository that blocks unauthorized third-party scripts from executing on local devices, says Ji.

“Open-source tools demand high technical literacy and leave local privileges dangerously exposed. Commercial wrappers insulate the host device, preventing agents from overconsuming computing tokens or leaking internal enterprise data,” he explains.

This photo taken on March 11, 2026 shows the screen of a mobile phone running the open-source AI agent OpenClaw at Wuxing district of Huzhou city, East China's Zhejiang province. (PHOTO / XINHUA)

Yet, cybersecurity leaders warn that safety achieved through commercial encapsulation comes with its own trade-offs.

Li points out that most of the domestic commercial agent tools remain open-source code wrapped in proprietary interfaces. By bundling their own cloud models and compute infrastructures, platform giants gradually lock users into closed corporate ecosystems, he says.

In his view, using big-tech solutions is undeniably simpler and safer than running raw open-source code. “But, the cost is ecosystem captivity. Tencent naturally wants you to use Hunyuan, ByteDance pushes Doubao, and Alibaba locks you into Qwen. The advantage is simplicity and safety, but the trade-off is getting bound to their closed ecosystems.”

ALSO READ: Beijing researchers release safety detection tool for OpenClaw

To ensure regional enterprises don’t abandon AI innovation altogether out of fear, regulators are guiding the market toward structured incubation rather than outright bans.

Hong Kong’s PCPD joined the Digital Policy Office in July this year to launch the “Safeguarding Personal Data AI Sandbox”, providing developers an isolated, compliant environment to stress-test agentic products before public launch.

“Emerging technologies naturally bring new risks, but safety issues should never serve as an excuse to block technological progress,” says Li, emphasizing a pragmatic view on the future of autonomous proxies.

“The goal isn’t rejecting innovation out of fear, but simply maintaining a clear operational baseline so that as digital proxies take over routine work, humans never surrender the steering wheel.”