Invest1 distinct publisher3 min readPublished
Mainland usage of OpenClaw runs at nearly twice America's, on SecurityScorecard's count. The state has tallied almost 23,000 exposed installs without publishing the base that would make that a rate.
The Investor · Invest desk

Compiled by The InvestorSomething wrong?How this is made
Three hours a day, if you take Hu Qiyun's estimate at face value and assume a 250-day working year, is 750 hours, or about ninety-four eight-hour days [14], which is a wage-sized number and the reason people queue. The catch is that one setting buys both sides of it: an agent authorised to act on your behalf with little oversight [2] is an agent holding the mailbox and, in the incidents users have recounted, the card [11]. Hu writes software for a living and still put it plainly to NBC News, saying he does not know how the thing understands his question or how it controls his computer [19].
Pricing the other side is harder, because the denominator is missing. The National Cybersecurity Alert Center's figure of nearly 23,000 exposed users [12] is a count rather than a rate, and a count rises with adoption whether or not per-machine configuration is getting better. SecurityScorecard's read that mainland usage is almost double America's [5] gives you a ratio between two countries, which puts China at roughly two-thirds of the pair's combined usage [20], and tells you nothing about installs. The 600 million generative AI users the government reported last month [6] is the wrong denominator, and it will be used as one anyway.
The counterparty puzzle is more interesting than the security one. OpenClaw is open source, written by the Austrian programmer Peter Steinberger and released in November [3], and Steinberger was hired by OpenAI last month [4], so the talent now sits inside a capitalised company while the artifact sits on machines whose owners lined up outside Tencent's Shenzhen headquarters to have engineers install it for free [8]. When it wipes a mailbox, there is no vendor of record to invoice. The standards work matters more than the frenzy around it for exactly this reason: CAICT's draft covering manageable user permissions and transparency in execution [16], and the National Vulnerability Database's advice to grant only the minimum permissions necessary [17], are attempts to make the permission model the compliance object precisely because the counterparty is not available to be one.
The counter-thesis comes in two versions worth naming. The restrictions already in place at Chinese companies, universities, state-owned enterprises and among government employees [18] could hold unsupervised agents inside households, deferring the enterprise authorisation question by a couple of years. Or the exposures are an install-week artifact, misconfiguration by non-technical users of software that can take over a whole computer and be reached remotely when safeguards are wrong [10], the kind of thing assisted installs and shipped defaults quietly clear.
My view, and it may well be wrong, is that the second version understates how much of the value is the unsupervised part: strip the authorisation back to prompt-by-prompt and the three hours go with it. The test is cheap. If the exposed-asset tally stays near 23,000 while installs keep running, that points toward hygiene rather than the structural problem I have described here.
Ranked by verification strength, evidence, and original report placement.
Hu Qiyun, 24, based in Shanghai, installed OpenClaw, which memorized his resume and scours the web each day for newly posted software engineering jobs, helps him apply, prepare for interviews and track application status; he said it saves him at least three hours each day.
While most AI systems require detailed instructions or prompts for every desired action, OpenClaw can be authorized to perform tasks on users' behalf with little oversight, including sorting and responding to emails, writing reports and making restaurant reservations.
OpenClaw is an open-source AI agent created by Austrian programmer Peter Steinberger and released in November.
OpenClaw creator Peter Steinberger was hired last month by OpenAI.
OpenClaw usage in mainland China is now almost double that in the United States, according to the American cybersecurity company SecurityScorecard.
More than 600 million people in China, over a third of the population, use generative AI, according to a Chinese government report last month on the country's internet development.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
China's accelerator swap makes Cambricon supply, not export policy, your ship-date risk1 distinct publisher
build
H200s reach China at 2.5% of the order book, and Hong Kong holds the rest2 distinct publishers
product
Baidu's AI line grew 25 percent and still lost the arithmetic1 distinct publisher
invest
Moody's puts China's 2026 AI build at $140 billion against $785 billion for six US hyperscalers1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One newsroom, named outside numbers, no method
A single NBC News report carries all of this. It does name who supplied the hard figures — SecurityScorecard for the usage gap, the National Cybersecurity Alert Center for the exposure count, CAICT and MIIT's vulnerability database for the rulemaking — but not one of those arrives with a method, a denominator or a second outlet's check. The most vivid detail, three hours saved a day, is one job seeker's own estimate. And the piece ends with a correction retracting an earlier statement that OpenAI had bought the project, which tells you how fast the facts here are moving.
Real installs, visible churn
The behaviour is hard to fake. People queued outside Tencent's Shenzhen headquarters for a free install; Tencent then put the agent inside WeChat; Alibaba, Baidu and ByteDance shipped products around it; Shenzhen started paying startups to build on it. The exposure count itself is adoption evidence — a regulator can only find 23,000 exposed users if 23,000 users exist. What keeps this short of the top of the scale is the churn in the same reporting: both named users deleted it within days, institutions are banning it, and the install sellers now sell removals.
Superlatives outrun the arithmetic
'The next ChatGPT' and 'the most successful open-sourced project in the history of humanity' are Nvidia's Jensen Huang talking, quoted here, and Chinese AI stocks moved on the sentiment. Set against that: a usage ratio from one vendor, a three-hour productivity claim from one user, and an exposure figure published without the install base that would turn it into a rate. NBC News is not credulous — the second thoughts sit right beside the frenzy, and it says plainly that both featured users quit — but the numbers doing the most rhetorical work are the ones nobody has shown their working for.
Nearly every voice has a stake
Look at who is speaking. A cybersecurity firm supplies the usage gap that makes the security story bigger. A chip executive supplies the superlatives while AI stocks rally. Tencent staffs the free install line and then wires the agent into WeChat. Shenzhen dangles up to 5 million yuan at builders. The creator has since joined OpenAI. Social-media sellers bill to install and bill again to remove. Even the warnings come from bodies — CAICT and MIIT's vulnerability database — that are drafting the very standards they would police.
Trust the direction, not the decimals
That an agent with full machine control has spread fast across China, alarmed regulators and triggered a wave of uninstalls is well established by this account, and the institutional responses are quoted rather than paraphrased. What we would not build a decision on are the two numbers readers will remember: the near-double usage ratio and the 23,000 exposed users, both single-sourced and both missing the base that gives them meaning. One newsroom, one correction already applied, no independent confirmation anywhere.