12-year-olds in therapy - the silent rise in youth porn addiction

Avoid using OpenClaw in mission-critical settings, giving unrestricted access: IMDA

Sign up now: Get ST's newsletters delivered to your inbox

The logo of OpenClaw, an open-source AI assistant, is seen on the software's website in this illustration picture taken March 12, 2026. REUTERS/Florence Lo/Illustration

OpenClaw implementations in core production and financial systems should be reviewed, said the Infocomm Media Development Authority.

PHOTO: REUTERS

Google Preferred Source badge

SINGAPORE – Users of OpenClaw have been advised against giving the artificial intelligence tool unrestricted access to files and applications, or running it on personal devices that contain sensitive data.

OpenClaw implementations in core production and financial systems, among other mission-critical environments, should also be reviewed, said the Infocomm Media Development Authority (IMDA) in its first warning to organisations in Singapore.

This is to prevent the agent from running amok, shutting down transactions or leaking sensitive data.

IMDA’s advisory, released on May 14, comes amid restrictions or bans by some governments and corporations around the world.

Created and released in November 2025 by Austrian developer Peter Steinberger, OpenClaw is a popular personal assistant as it allows users to connect AI models – such as OpenAI’s ChatGPT, Google’s Gemini and Anthropic’s Claude – to instant messaging and e-mail systems to execute multi-step workflows automatically.

“It can automate everyday tasks – such as compiling research from multiple websites, drafting reports or e-mails, and coordinating schedules,” said IMDA in its advisory. When applied to workflows, it can also respond to customer queries, pull data to generate business reports and assist developers in debugging code.

“Nevertheless, deploying OpenClaw safely requires careful set-up, particularly given the limited built-in security controls. Users should understand the risks involved and be prepared to implement appropriate guard rails themselves.”

Top stories

Explore top stories from all sections in one place

When the tool was launched, it came with key security concerns such as a lack of extensive testing, access control and authentication gaps, and the risk of exposing sensitive data, said IMDA.

As at April, around a quarter of more than 400 vulnerabilities and exposures related to OpenClaw reported on intelligence platform OpenCVE were found to be high on the severity scale, which could lead to major damage such as data theft, said IMDA.

By default, OpenClaw is able to access files anywhere on one’s computer as it inherits the privileges of the user account that installs it – giving it access to any file the user has permission to access.

For instance, when OpenClaw is connected to communication channel Slack, it may accept instructions from any participant in the channel without added authentication. This increases the risks of unintended or harmful actions. So, users should restrict who can post in the Slack channel, or introduce approval workflows that require explicit human approval, said IMDA.

Users also run the risk of exposing their sensitive data to external AI model providers, as OpenClaw typically relies on AI models such as Claude to reason and plan actions.

“As part of this process, users’ messages to OpenClaw, as well as files or e-mails that OpenClaw has access to, may be transmitted to these models as context,” said IMDA.

And while skills downloaded from online marketplaces are a key driver of OpenClaw’s capabilities, they may not have gone through rigorous testing and may contain malicious instructions. “Many skills on public marketplaces like ClawHub are currently flagged as malicious,” said IMDA.

The authority cited reports of the malware Atomic macOS Stealer – designed to steal sensitive data from Apple users – being distributed under the guise of OpenClaw skills such as YouTube video downloaders, cryptocurrency wallet trackers and Google Workspace tools.

To circumvent this, users should default to using trusted skills only – where its source code is publicly inspectable and maintained by a known publisher, said IMDA.

“Skills that lack transparent source code, verifiable provenance, recent maintenance activity, or that request permissions beyond their stated purpose should be treated as higher risk and avoided.”

OpenClaw requires autonomy and broad access to data to be helpful, but this comes with higher risks of unpredictable actions and data leakage, said IMDA.

It added: “Accepting the risks associated with granting OpenClaw broader capabilities should be an intentional decision, and not the result of default configurations that were overlooked.”

To minimise such risks, IMDA outlined several recommendations. These include advice against creating a single “all-powerful” OpenClaw agent with unrestricted access, and against installing OpenClaw on primary work or personal devices that contain sensitive data.

Instead, users are urged to use multiple agents with narrow and clearly defined roles, such as separate agents for calendar scheduling and coding projects.

Human approval should also be implemented through system-level controls as a guard rail where possible, said IMDA, adding that this is especially crucial for high-stakes and irreversible actions.

Technical controls, such as creating a unique identity and account for the agent, are also encouraged to avoid letting agents reuse personal credentials. All actions taken by the agent should be traceable and logged to a persistent directory.

Said IMDA: “Managed identity for agents should be recognised as a foundational control layer, particularly as agents increasingly act as proxies for human users across systems.”

The warnings and recommendations in the advisory are based on the authority’s Model AI Governance Framework for Agentic AI, released in January, and the technical experiences of the Government Technology Agency of Singapore, Cyber Security Agency of Singapore, Grab, Microsoft and Tencent.

In Singapore, more than 20 community-led OpenClaw events have been held that have drawn a variety of workers, including developers and entrepreneurs, keen to learn from real-use cases for the tool.

In March, China banned state-run enterprises and government agencies from running OpenClaw on office computers, out of security concerns. The same fears have also reportedly driven tech companies such as Meta to ban employees from running OpenClaw on their work laptops.

“OpenClaw highlights how rapidly autonomous AI tools are advancing – they offer significant benefits, but also pose real risks if used carelessly,” said IMDA, adding that the aim is not to avoid such tools but to use them with clear limits, accountability and safeguards.

“As the technology continues to evolve, this case study offers a starting point rather than a complete solution. Ongoing vigilance and stronger safeguards will be essential, especially for enterprises with higher security needs.”

Read the full story and more

Want more exclusives, sharp insights into what’s happening at home and abroad? Subscribe now.

ST One Digital Plan
ST One Digital Plan
Monthly Recurring
$9.90/month
No lock-in contract
No lock-in contract

    Enjoy these subscriber benefits

  • Access all subscriber-only content on ST app and straitstimes.com
  • Easy access any time via ST app on one mobile device.
  • E-paper with 2-week archive so you won’t miss out on content that matters to you
See more on
Recommended buys
All products have been vetted by the SPH Media shopping team. We may earn an affiliate commission if you buy through our links.

In Your Opinion Podcast

12-year-olds in therapy - the silent rise in youth porn addiction

Sign up now: Get ST's newsletters delivered to your inbox

Banning explicit websites might seem like an effective solution, but consider whether our conservative culture and deep-rooted stigma around sex are actually driving a silent porn addiction crisis among youths.

Banning explicit websites might seem like an effective solution, but consider whether our conservative culture and deep-rooted stigma around sex are actually driving a silent porn addiction crisis among youths.

ST GRAPHIC: LIEW JING FEI

Google Preferred Source badge

Synopsis: On Wednesdays, The Straits Times takes a hard look at Singapore’s social issues of the day with guests.

Asia holds the highest rate of problematic pornography use in the world at nearly one in five people, according to a study which researchers term ‘Asian Paradox’. While casual viewing can be healthy for adults in some instances, this taboo weaponises the dopamine hit for tech-savvy youths.

In this episode, assistant podcast editor Lynda Hong sits down with Dr Peter Chew, Associate Professor of Psychology at James Cook University Singapore, to unpack this silent epidemic.
They explore the neuroscience behind the digital dopamine trap, why a teenager’s developing brain is vulnerable, and why symbolic website bans are failing.
 
Dr Chew also dismantles common misconceptions, explaining the crucial difference between clinical addiction and religious guilt; how sex education should change; and why abstinence-only programmers cause higher unwanted pregnancies. 

Highlights (click/tap above):

Last four privately-owned HDB wet markets to be refreshed after leases expire by end-2027

Sign up now: Get ST's newsletters delivered to your inbox

ST20260510_202691000236/Jasel Poh/ kgmarket10 

Photo of the wet market at Woodlands North Plaza on May 10, 2026.

Can also be used for stories on: Groceries/Grocery, Inflation, Prices, Market, Budget, Economy, Cost of Living.

The markets, which have their leases expiring end-2027, are located in Fajar Shopping Centre, Yew Tee Square, Bukit Batok West Shopping Centre and Woodlands North Plaza.

ST PHOTO: JASEL POH

Ng Keng Gene and Justine Ong

Google Preferred Source badge

SINGAPORE – Residents in four neighbourhoods can look forward to renovated wet markets in the coming years, with ownership of the markets returning to the Housing Board after 30 years in private hands.

The markets, which have leases expiring in end-2027 at the latest, are located in Fajar Shopping Centre, Yew Tee Square, Bukit Batok West Shopping Centre and Woodlands North Plaza, said Senior Minister of State for National Development Sun Xueling in a Facebook post on May 9.

Citing two other wet markets in Keat Hong and Serangoon which were taken back by the HDB and renovated after the end of their leases, Ms Sun said that residents living near the four wet markets can “look forward to a similarly better shopping experience close to home”.