Welcome to the week the agent economy grew up in public. Managed hosting for OpenClaw and Hermes went generally available, NVIDIA shipped a security stack for running agents, a hot new tool got caught with its admin dashboard wide open, and a federal judge told the Pentagon its blacklisting of Anthropic was unlawful. Four ecosystem stories and one courtroom shocker, with a clear message: the demo era is over, and the hardening has begun.

Cloudways Makes OpenClaw and Hermes a One-Click Managed Service
DigitalOcean’s Cloudways subsidiary has taken the wraps off Managed AI Agents, its first product line built specifically for deploying open-source agents, with OpenClaw and Hermes as the launch platforms. You can now spin up an agent the same way you spin up a web app: no VPS rental, no gateway configuration, no port forwarding, no midnight security patches, and you get the same billing, support, and dashboard you already use for hosting. That is the moment running your own agent stopped being a hobbyist flex and became a checkbox on a hosting order form. Why it matters: the plumbing is becoming a commodity, and the hosting giants are racing to own it before the next wave of agent users shows up.
NVIDIA Ships NemoClaw So Agents Don’t Run Rampant on Your Infrastructure
NVIDIA released NemoClaw, an open blueprint for running OpenClaw, Hermes, and LangChain Deep Agents more securely, and it is a serious answer to the question every IT department is asking: how do you let an autonomous agent touch company systems without it torching the place? It wraps OpenShell runtime policy controls around the agent, sandboxes shell and tool execution, routes inference through managed Nemotron models, and adds NeMo tooling for specialization, so an enterprise can define exactly what an agent may touch and what it may never do. Capability was never the bottleneck for enterprise agents; trust was. Why it matters: hardware vendors just started building the guardrails in, which is the strongest signal yet that security, not intelligence, is the real enterprise battleground.

DeepSeek Harness Launched 15 Days Ago and Its Dashboard Has No Login
DeepSeek Harness shipped on August 13, and researchers have already documented a no-login dashboard vulnerability that is unauthenticated and remote-code-execution capable, which is a polite way of saying the admin panel is open to anyone who can reach it. We took the whole thing apart last Saturday: how the flaw works, why unauthenticated dashboards become RCE so reliably, and what to check on your own setup, whether you run Harness or anything with a similar admin surface. Why it matters: when fast-moving open-source projects ship control planes without authentication, every early adopter becomes a beta tester for someone else’s security posture, so patch and audit before you brag.
Hermes Ships ‘claw migrate’ and the Agent Switching Wars Officially Begin
Nous Research’s Hermes now includes hermes claw migrate, which imports an existing OpenClaw (or legacy Clawdbot/Moldbot) setup in one command, with sensible handling of conflicting skills via skip, overwrite, or rename modes, and secrets redacted from every plan and report. OpenClaw’s own documentation now covers migrating in the other direction, with previews and verified backups, so the bridge runs both ways. We updated our Hermes vs. OpenClaw comparison with a full migrating section, because this changes the calculus for everyone sitting on a half-configured agent. Why it matters: when switching agents is a single command instead of a weekend migration, nobody is locked in, and both projects have to compete on merit rather than momentum. See our updated comparison here.

A Federal Judge Rules the Pentagon’s Blacklisting of Anthropic Was Unlawful
The week’s biggest story wasn’t a model launch: a US judge ruled that the Pentagon’s blacklisting of Anthropic was unlawful and blocked it, and the decision dominated Hacker News with two front-page threads and more than 500 combined points. Courts are increasingly being asked to referee how the government treats AI companies, and this ruling went squarely against the administration, with Reuters and the New York Times both covering the fallout. Why it matters: it is the first major legal check on the government’s AI policy, and it puts agencies on notice that blacklisting an AI company still has to survive judicial review, which is exactly the accountability this industry needs.
What This Means for You
If you run any agent, this week’s lesson is unglamorous: treat your dashboards like doors. If it has no lock, the internet will walk through it, so check authentication on every control plane you run, rotate keys, and re-read your agent’s permissions with the paranoia of someone who just read about a no-login admin panel. Second, the hosting market just got real: Cloudways’ GA means you can outsource the entire plumbing, but managed hosting is a trade, not a gift, and you are trusting a vendor with your agent’s keys, so read the terms before you migrate. Third, switching agents is now frictionless, and that is a gift: try the other project for a weekend, because the cost is a command, not a data migration. And if you publish anything on the web, remember agents are your readers now: the free AI Crawl Checker at marcusli.com tells you whether ChatGPT, Claude, and Perplexity can actually cite your site, and generates a starter robots.txt so you decide who reads what. Being invisible to AI answers is a choice, but it should be yours.
Last week we took DeepSeek Harness’s no-login dashboard apart, walked through why unauthenticated dashboards become RCE, and built a checklist for checking your own setup.
Look back at this week in five years and you will see the moment agents stopped being a demo. Managed hosting, hardware security stacks, one-command migration, and a court telling the Pentagon to follow due process: these are the boring, essential parts of a real industry, and boring is exactly what the agent economy needed. The next phase won’t be decided by whoever ships the flashiest model; it will be decided by who can run agents safely, cheaply, and within the law.

