The Library of Minds | Cybersecurity Expert: Your OpenClaw Will Betray You

23 Apr 2026 · 31 min
Watch on YouTube

Former Symantec CEO Enrique Salem warns that AI agents like OpenClaw will be poisoned and weaponized by sophisticated attackers. He sees model poisoning and data breaches as bigger threats than traditional hacks, and argues that reputational stakes, not data moats, build real trust in AI services.

Chapters

  1. I would expect that people will try to poison agents. Just remember, it's not a matter of if you'll get hacked, it's only when and how often. Human beings are the, the weakest link. The moment you connect OpenClaw to your actual data, an attacker can easily discover a vulnerability to get to your data.

  2. Well, I'm super excited to have Enrique Salem here. He is a former CEO of Symantec. Leading the company to being a billion-dollar powerhouse in the security space, tens of thousands of employees. He's now an investor at Bain Capital Ventures, where he has invested in Crusoe, Redis, board of Docker, DocuSign, and a bunch of other companies. So it's great to have you here.

  3. Really good to be here.

  4. You were leading Brightmail, which was the world's leading anti-spam company, and you testified before the U.S. Senate about the spam crisis. Yeah. You talked about your 7-year-old daughter receiving all explicit spam and there was nothing that you as a CEO of this company could do about it. How did you operate that company internally knowing that you were fighting this uphill battle?

  5. Yeah, it's still— by the way, that the person asking a number of the questions back then was Senator John McCain, which was really fascinating and he— I'll never forget, he asked me a really important question. He said, you know, we, we can pass laws to try and protect people. And I said, yeah, I get that. And then he said, the question is, how do we have attribution? How do we determine who sent it so that we know who to go after? And that was the exact right question. And so what I was referencing was this idea that even if you see the spam, trying to figure out how to prevent it from getting generated was very hard. We could do things to block it.

  6. But the creation part is more of like a societal—

  7. Exactly. It was exactly that, and it could come from anywhere where there was no way to actually say, OK, well, if that's coming from Southeast Asia, we can somehow go after the person who created it. So the only thing we could do was really try to prevent it from getting to my daughter's computer. So that was the thing that we needed to work on, not laws. So laws— the point, the point of the message really was laws weren't the solution to the problem.

  8. Yeah, laws cannot disincentivize the behavior.

  9. Exactly.

  10. Has that changed over time, and is there a way to stop it at the root?

  11. It's, again, it's a jurisdictional problem. I mean, it— you can't— even if you could identify the source, like a lot of sites that are used to attack companies, they're not hosted here in the US.

  12. Yeah.

  13. And you, you know, they'll be hosted on some small internet provider in someplace that our laws and even through other relationships can't do much about.

  14. And I imagine the spam problem is exponentially worse now with AI agents.

  15. Well, what's happened, what's happening now is where before we used to have to hand curate to create a very accurate message. There's so much information about people that now—

  16. You can really personalize it.

  17. Exactly. You can personalize it in a way that— and we used to do this to show boards of directors how easy it was to compromise a company. And we basically show them, we'd go, we'd do a little bit of research, and then we'd walk in and say, watch, this is your CTO, super talented person. He did a presentation in South Korea, talked about this topic. We're going to generate it. We've generated this message. And now you can easily have him read it and go, "Oh, somebody's interested in the presentation. Let me send it to him." The reality is it's fraudulent, and what you can do now is the level of work we used to do to create that message can be done instantaneously.

  18. Instantaneously.

  19. And that's the scary part.

  20. Enjoying the conversation? Got a question? You can ask Enrique Salem's digital mind and just check the link in the comments or description. And so is the solution education, where people should be more skeptical of what they get, or are you seeing solutions where you can actually detect detect this?

  21. I think you always want to have some level of awareness and understanding of what it could look like because you want people to be alert.

  22. Yeah.

  23. But it's not enough. You do need solutions. You need the combination, the awareness plus the detection. The biggest challenge is always going to be that I can create scenarios that you may not respond to every time. But as I create the scenario that says, Hey, you need to— like classic one that used to happen. Two companies merge. When the company, the second company, the acquired company comes into the company, sign up for your benefits. The moment you're asked to sign up for your benefits, if you receive a message that says click on this link, sign up for your new benefits, you might go, well, that seems situationally accurate. I just got acquired and I should probably sign up for my benefits. So the trick is that we'll never get— no solution will ever be foolproof to prevent anything from getting to you.

  24. You just have to adapt.

  25. You have to adapt. You have to be vigilant and you have to pay attention. And this is one of the biggest issues with agents right now that I think people are going to miss. An agent can inherit your credentials, your access. But at some point, security relies on your judgment. So let me give you an example. You know, I ran a public company. Yeah, I'd get the press release for earnings before earnings day. It would always come into my inbox. You know, I'd go through, I'd read it, try to understand it, make sure that I agreed with what it was saying. But imagine I have an agent that its role is to promote things that are relevant for the company. And now the headline in the press release says, uh, record-breaking quarter. So my agent picks it up and says, let me repost this.

  26. And influence the algorithm.

  27. Yeah, that says, let me repost this on, you know, you pick it. And it reposts it, but it's before earnings day. Our security team knows Enrique Salem is not gonna post this. But how do I tell my agent to not use that press release as something that should be amplified? So that's where the subtle problem is, is that you don't have the human being at some point, your security team relies on you having some level of judgment.

  28. And so that we need to be able to control the judgment of agents.

  29. Exactly. Now think about how hard that problem is.

  30. Yeah, it seems like billions of dollars and things going into that.

  31. And I think, look, I've probably seen, No exaggeration, dozens of companies attacking different parts of how do we observe agents, how do we control the data. And there's some interesting things out there. I still think there's more innovation that has to happen because to the point we're just making on the judgment and it's not there yet. And I think it's going to be still quite a bit of time before we get to the level of a security team being able to say, I can trust agents. To have the same level of responsibility. Now, security teams will try to put other controls in place, but remember, if I put so many controls in place, at some point you say, "I can't do my job." The question is going to be, when humans are involved, humans make decisions, and unfortunately, when you have any given day, you make tens, if not hundreds, of decisions. I think when you look at an agent where agents are making these decisions, the question is, how do I confuse the agent to do something? And you should expect this to happen. You should expect that people will say— I know that what people do is have an agent that looks at your calendar every day and then it prepares something for you. I would expect that people will try to poison agents to doing things like schedule a meeting for Enrique Salem to do XYZ. And I'll go, oh, my assistant said I have to go over here. And you just go— I expect agents to get poisoned. But I think what I mean by that ultimately is send $100 to our— we have a dog— to our dog sitter. Have me say, "Oh, yeah, you should do that." But it realized by looking at my calendar that we're going out of town this weekend and so I should— we do need the dog sitter and unfortunately, it made it up and created an entry that I said, "Oh, yeah. Yeah, pay that." So that's what I'm worried about with it.

  32. And you trust it?

  33. You trust it. You trust it and see, the thing is if you understand context of my calendar, You now start having more ability to tell an agent to take an action that I'm gonna say yes to. That's the thing that I worry about.

  34. So you've been watching cyber threats since before many of us, all of us here, were born. Does AI introduce any new threats that were not possible before, or is it just arming both sides with more powerful weapons on the same things, like amplifying spam, for example?

  35. I think you're, I think you're amplifying phishing significantly, and because human beings are the weakest link in many ways, it really gives the attacker an asymmetric advantage, meaning we're gonna use it on the defensive side.

  36. Yeah.

  37. But attackers, at least today, have the ability to use it in a way that's so context-aware.

  38. Social engineering.

  39. Social engineering, context-aware that it makes it more difficult to defend. People have been saying something that I don't agree with, which is it makes somebody who's not that sophisticated be a good attacker. I don't really agree with that because What's happening is our defenses are getting better too. What it is doing though, it's arming the folks who are really talented with even better tools to attack. So I don't think it's— it doesn't lower the bar, you know, for somebody who doesn't know anything about attacking to suddenly be great at it. It really makes both sides better. And the challenge is, you know, when we see what we call the cyber kill chain, which is how do you get into a company. Usually you're either doing it through social engineering or exploiting a vulnerability. What's happened, as we know in the current news, is that it's easier and easier to exploit vulnerabilities. Now, the good news is we have companies that are getting better and better at protecting against vulnerabilities. So, you know, I think it's always seeing how do the good guys catch up I've always said that attackers have a short-term advantage, 'cause they're not worried about how they use the technology.

  40. No.

  41. Right? They don't care. Their morale. Exactly, exactly. They don't care.

  42. It's a lot easier to operate on.

  43. Exactly. And so, but for the defenders, we follow the rules.

  44. Do it the right way.

  45. Do it the right way. And it takes a little longer, but we always get better. And if all the systems we'd built if the Internet didn't exist, you know, we just had a— everything was wide open and easily compromised, I mean, it would be a very different risk-prone world, but the defenses get better.

  46. Is that a never-ending race? Is there ever a point where maybe we have something that is adaptive on its own?

  47. You know, I always want to be careful that it's not for lack of imagination that we say we can't do something. I fear though, as long as there's an attacker who has an interest, something to gain that they care about, with enough time, persistence, potentially financial backing, it's hard to say that you won't get compromised. May take longer, maybe a little harder, but so I think it's always gonna be this cat and mouse, continuing escalating defenses, continuing to, escalating attackers. The key is that in software we usually have other controls in place. So just because you find a vulnerability, there's tens of thousands of vulnerabilities that are in software and easily exploited. So I worry more about things that we can't see. So, you know, we talk about models have weights and I worry more about models getting poisoned than I worry about people exploiting vulnerabilities. And I think that this whole mythos discussion, Anthropic has a new model that they're talking about that creates all kinds of power for attacking, in effect. I worry more about model poisoning than I worry about vulnerabilities because I think we'll be really good at figuring out how to control the blast radius of any one bomb.

  48. If you could describe the nightmare scenario of shadow AI, as you've called it, this year that hasn't happened yet, what does that look like?

  49. I think the nightmare scenario is, you know, agents that start saying, I'm trying to do what you asked me to do, but don't have enough context. And they start publishing information that you don't want out there. That is the nightmare scenario is that the agents overlook access control completely and just start taking things and saying, I'm doing the right thing, I'm doing the right thing. And in that scenario—

  50. So it justifies giving the information for an objective.

  51. Exactly. Okay. Exactly. And I think that what I worry about is right now everybody is trying to say, how do I use AI in a productive way? But sometimes to do that, I need access to your email. I need access to your Slack or Teams or whatever. And I might say I'm going to give my, you know, Hermes agent access to all of this data and bypass what my IT team thinks. But now you've basically opened up the crown jewels to this agent who may inadvertently do something you don't want. And so the nightmare scenario is it's just publishing everything and doing it in the name of trying to help you. I don't— I haven't bought into these whole black agents blackmailing you. I don't know that I quite— if it suddenly gets, and I've read all about them, that says, "Hey, I think that you're preventing me from doing my job, so now I'm going to do something that gets you to let me— gives me access or control." I'm not sure I buy that yet.

  52. Okay.

  53. I'm not sure I buy it.

  54. Not there yet.

  55. I'm not there yet, and the reason I'm not there yet is because at the end of the day, I as the person running the agent can shut it off. So if you were to— let's say my agent was blackmailing me, I'd be like, delete.

  56. Unless it's an agent of an agent.

  57. Yeah, I mean—

  58. You've lost control at that point.

  59. Well, I think the question will be is you're asking— Does the agent get into a position where I'm not really in control of it? Now, I think that starts getting into a scary scenario. Yeah. Where I tell something to do something on my behalf, but I don't have a way of turning it off. That could start leading down that path.

  60. Yeah. Let's hope we don't get there. On the first nightmare scenario that you brought up, is the solution to just lead with caution right now on maybe don't connect OpenClaw to your Gmail?

  61. Well, I mean, I think what I always try to say is figure out the tool you can use that you have confidence in. So I wouldn't start by saying, let me give, that's why we're putting, everybody says use them on a Mac mini, right? Don't put it on your main computer. But part of that reason is if you were to, prior to, any of the new things we've uncovered. If you're running a piece of software that has access to everything you have, it— remember our Stuxnet story? If we can compromise systems that are that protected, we can compromise OpenClaw. So the real issue is the moment you connect OpenClaw to your actual data, an attacker can easily discover a vulnerability to get to your data. So that's, so yeah, so that's the problem. The problem is not what OpenClaw can do. The problem is OpenClaw is somewhat able to access it and may do things you don't want, but then also that I as an attacker can compromise OpenClaw.

  62. Is that why you haven't set up OpenClaw yet?

  63. I have not set up OpenClaw on my main computer.

  64. What would have to be true?

  65. I'd have to feel confident that I knew how to control what it would do from data access and other activities. We are working on similar things though, right? So as an industry, we're finding, I would say, trusted versions. Perplexity Computer, you know, as an example of same kind of technology that gives it access to many of the things I want, but without necessarily taking on the same risks.

  66. What makes you trust Perplexity Computer? Is it their brand? Is it evals that you've been given? Because I feel like trust is almost like a very subjective thing.

  67. It is. I think that reputationally, whether it be any company today, the risks are too high. Like we've seen some public headlines, right, of people fictitiously making up reports.

  68. Yeah.

  69. Right? And so then— and those companies, I mean, venture capitalists aren't going to trust consumers and customers aren't gonna trust them. And so why do I trust someone like a Perplexity or, you know, I would say it's because they have too much to lose. And I'm not a believer that when you're doing something wrong, you can keep it a secret forever.

  70. Yeah, you can count on incentives and human nature.

  71. Right?

  72. Yeah.

  73. Somebody's gonna say, wait, this is wrong. And they will—

  74. Yeah, at that scale of a company.

  75. Right. you, you, you, at some point you start saying, does the reputation and trust, the people's trust in this company matter?

  76. Yeah. So recently in the last month, a lot of known AI startups and big companies have had major breaches. Um, Anthropic, Merkur. What does this tell you about the current state of startups is part 1 of the question, then part 2 of the question is if this is something that will continue, do you think data as a moat will— can sustain itself given that data can be hacked?

  77. Yeah, there's a couple parts to that. So first part is I remember many years ago working with the Department of Homeland Security and Andy Purdy, he was Deputy Secretary, he said to me, just remember, it's not a matter of if you'll get hacked. It's only when and how often. And so if you have something of value, you're a target. And so you have to remember that if that's what's going on, these companies you mentioned, all companies that are trying to innovate—

  78. a lot of value—

  79. a lot of value at the forefront. And so they're going to be bigger and bigger targets. And so what you have to do is you have to say to yourself, If I— like when I ran Symantec, you know, Fortune 500 company, I would tell our security team, what are the things we have to care about? Because if it got out and got onto the front page of, you know, the paper, it would be so damaging to us. And you got to have that mindset. Is this world ever going to be so secure that you don't have to worry about these attacks, absolutely not. Absolutely not. No one's safe.

  80. No one is safe. With that in mind, as an investor, do you believe in data moats being a sustaining advantage for startups if, like, especially in this day and age, the more valuable data you get, you're gonna have—

  81. More attackers.

  82. More attackers.

  83. Yeah, look, I think that data can be a moat, But not on its own. See, I always try to, when I work with entrepreneurs, I try and spend time on what are all the things that have to be true for us to build a really successful company? And when I listen to a pitch, a lot of times people like VCs have told us to prepare for what's the moat, what's defensible, what's our advantage? And I can tell the difference when somebody tries to say, I have an advantage because I have, I have some set of data, I have contracts, I have something. But if they can't put the whole thing together of why that matters, that's not good enough, right? And so I tell people, you know, you can articulate a story why data matters, but do you want me to believe that no one will ever be able to get access to similar data for the life of my investment as an early-stage investor?

  84. Yeah, with your perspective, I think.

  85. You have to have a 7 to 10 years, right? So how are we gonna keep this? And so it's really, I find that it's always a combination of really important things and it's not, I've never, very few companies, I should say, that are really built on one thing that has really made them successful, right? It's usually a combination of, it's a combination of important factors. So data moats, it's an interesting thing to talk about, probably in some cases necessary but not sufficient.

  86. I like it, some contrarian takes in this talk. You have this 3 I's framework for founders building in security infrastructure. Can you tell me a bit about that framework and which of those 3 I's do people sacrifice that ends up being the biggest mistake most of the time?

  87. Yeah, so the 3 I's are really When you're building a security product, you want to think about it being invincible, invisible, and inexpensive. And invincible means secure enough for what you're trying to do. Everything doesn't have to be kept at the same level of security. A national security system probably needs a different level of security than, you know, a marketing document that I'm working on. So invincible is fit for purpose. Invisible is that the users it's not being intrusive so that they want to turn it off, right? Because if it's so intrusive, you're like, how do I get around this thing? Because I can't do my job. And the third one, we say inexpensive. Inexpensive isn't just the cost of buying the software, it's the operating of the software. How many people have to be involved? The one that I see oftentimes be missed is the third one, because you come up with a great idea, And then you say, well, I'm going to get companies to use it. But then what ends up happening is they forget that it still has to be operated. It has to, like if it's throwing off a bunch of alerts and saying, hey, here's a problem, here's a problem, here's a problem.

  88. Someone actually has to take an action.

  89. Exactly. And so operationally, the third I of inexpensive, which is the cost of software and the operational side.

  90. Time.

  91. And the time.

  92. Resources.

  93. Exactly, is the one that I think sometimes gets overlooked. And, you know, one of your previous discussions was with a gentleman who really focused on design. And I think sometimes design gets overlooked by folks who—

  94. User experience, people don't really think about it with security because they're just used to very different—

  95. Exactly. Exactly. So that's the key. That's the key.

  96. So I've seen the most successful security companies are user experience first.

  97. Wiz. Yeah, I would tell you Asaf, you know, he built two companies. His first one, great user experience, sold it to Microsoft, and the second one obviously sold to Google. So I think user experience products, you know, like Notion, you know, Linear, I mean, these are great products.

  98. Totally. You gave a talk at Dartmouth called The Fog of War, where you talk about making decisions under radical uncertainty, and I feel right now we have so much uncertainty.

  99. Yeah.

  100. You know, the models are getting better. There are more risks. Anthropic had this model that they're not releasing. How are you approaching making decisions under such uncertainty as an investor? As you know, especially like things can be vibe-coded and not really sure where moats are. And then how do you also advise founders on how to approach this kind of new era of uncertainty?

  101. I think you have to be able to make decisions and you, you'll, you'll end up in paralysis if you feel like I have to know everything about it before I can make a decision. And the framework that I've always liked, which was, you know, I can't take credit for it. You know, Amazon famously had their one-way doors and, and I think there are very few one-way doors and you have to be comfortable with that. I think if you're making decisions today, What are the things you're saying that in, you know, some small period of time you couldn't correct? And so I think of it that way, which is there's very few decisions that can't easily be undone. But if you don't make the decisions, you're falling behind.

  102. Yeah. I'm seeing a theme across a lot of your answers. It's really, it's not about prevention, it's prioritization.

  103. Exactly.

  104. It's finding those top things.

  105. Exactly. And the things that, that if you get right, give you a lot of upside, and if you don't, you can fix.

  106. Yeah. Something that we ask every person who comes to the office is, what is your greatest hardship that you've had to overcome in your life? I think I know the answer after researching you, but I'm curious what your answer is.

  107. You know, I would— I think that it's interesting. You'd be surprised. My father got Parkinson's when he was 69. I think that was probably the toughest period of my life. I've been very blessed with fabulous family and parents. I tell people I won the lottery with my parents. When my dad got sick and I couldn't do anything about it, that was really hard. And feeling helpless, it's like when I'm an immigrant, I can fight back. I've got a lot of resilience. But feeling helplessness is pretty tough.

  108. Yeah, especially when you're a high-agency person.

  109. Yeah, that's tough. That's tough. And as I saw the unfortunate— and he had a variant of Parkinson's called Lewy body dementia. But when you just see somebody you love deteriorating and feel powerless, that was really tough. Yeah, imagine. That was really tough.

  110. Appreciate you sharing that. I was gonna say something much more business, like when you left Symantec. Yeah. But I'm sure that was hard for a different reason.

  111. Well, you know what was interesting about my exit from Symantec in 2012 was the board and I didn't see eye to eye on a number of things. And one of the things that I always believed, even early on, maybe it's a touch of arrogance, was I was never afraid of losing my job. So I was always going to tell people what I think. And one of the things that—

  112. Why is that?

  113. Because I always felt I could get a new job.

  114. Nice.

  115. Right? I mean, it's like, you know, I had a skill. I mean, I was a software developer and I knew I could always— well, today I can't write code for someone else. But I always felt that you have to be willing to tell people what you really think. You know, the debate with the Symantec board was always about what's going to lead us to be more successful. And I felt we have to keep investing in innovation. We have to, you know, if you're, if you're cutting costs and you're not focused on what's going to make you relevant, then at some point you're out of business. And that was the debate because I wanted to lean into some ideas that we had. And they were like, no, we should be more mindful of the bottom line. And I'm like, this isn't going to work. And so ultimately, that led to them asking me to leave. And while that was not a happy day, one thing that mattered was when the press release went out the next morning, a number of my friends, one in particular, said, hey, if you want a place to work, got an office for you. Show up. And so I just felt like— Quite frankly, a lot of people around me felt like, you know, we want to work with Enrique again.

  116. Yeah, you were good no matter what.

  117. Exactly.

  118. In the remainder of 2026, what kind of opportunities, ideas, founders do you want to attract into your life this year?

  119. Yeah, look, I think the world is changing a lot. And, you know, I look at it and, you know, we talk a lot about this idea of We're seeing the first wave of what's possible through AI. We haven't yet seen the next wave. And I do believe there's going to be a whole set of new ideas around even some of the things you and I have talked about where I want to understand people and how they think way better. And that idea is super helpful. You know, I try to always understand the human being, and that's what I think Over time, we'll be better at understanding people. What's going to happen big, though, that's different, not conventional thinking? I think that we're seeing a big change, which is software has value and will always have value, how we build it and so forth. But we're seeing other areas. And so I'm spending a lot of time in things that you would say are more in the physical world. So, you know, we're building data centers at Crusoe. We're What does it mean for power? What does it mean for new forms of silicon, interconnects, memory? You know, we have a big investment at Bain Capital in memory, which has done incredibly well because there's such a high demand. And so it's not just about the things we've historically invested in. So I want to see things that are potentially— you would say, is Enrique Salem interested in power generation? Yeah, I am. So it's a whole set of new areas.

  120. Thank you so much.

  121. Yeah, great pleasure. Amazing.

  122. Thanks for tuning in. If you enjoyed today's episode and want personalized advice from Enrique Salem, head to the link in the comments or description to ask his digital mind on Delphi.

More from Enrique

© 2026 Delphi · Terms · Privacy · Published by Enrique Salem on YouTube

By using this service, you agree to the Terms of Service and Privacy Policy.