GTC 2026 NemoClaw and OpenClaw: NVIDIA's agentic OS pitch explained
Watch the original video · 139 min
This segment runs from 1:46:32 to 1:56:37 of the GTC 2026 keynote. Jensen Huang argues that OpenClaw, a third-party open-source agent framework, is the “operating system” of agentic computing, then introduces NVIDIA’s NemoClaw stack and OpenShell runtime as the enterprise security layer for it. Watch it if you run IT or platform teams, build on agent frameworks, or are trying to judge how NVIDIA plans to earn money from agents beyond selling GPUs.
Key takeaways
- OpenClaw is not NVIDIA’s; NemoClaw is. Peter Steinberger created OpenClaw. NVIDIA built NemoClaw, which installs Nemotron models and the OpenShell runtime on top of OpenClaw in one command (1:55:15).
- The pitch is “agent as operating system”. Jensen lists resources, tools, file access, scheduling, sub-agents and multimodal I/O, then says that is the same list you would use to describe an OS (1:51:32).
- Every CEO is told to have an “OpenClaw strategy”. He compares it to Linux, HTML and Kubernetes strategies in earlier eras (1:52:24).
- SaaS becomes “agents as a service”. Jensen predicts every software-as-a-service company turns into an agent-as-a-service company (1:53:51).
- The security gap is the product opening. Agents that read sensitive data, run code and talk to the outside world need policy engines, network guardrails and privacy routing, which is what OpenShell supplies (1:54:42).
Chapter notes
1:46:32 – 1:50:10 Who built OpenClaw and why it spread
Jensen opens by pointing out Peter Steinberger in the audience and crediting him as OpenClaw’s creator. He then claims OpenClaw became the most popular open-source project in history within weeks, outpacing what Linux built over 30 years. NVIDIA’s own press release uses softer wording, calling it the fastest-growing open-source project in history. The stage claim about overtaking Linux was not stated in the official release, so treat it as Jensen’s framing rather than a measured statistic.
A short demo shows one console command pulling down OpenClaw and spinning up an agent. Jensen follows with community anecdotes: Andrej Karpathy’s “autoresearch” project that runs experiments overnight, and a user whose father automated a home brewery and its ordering site. These stories are not technical evidence. Their job is to establish that agents have already escaped the lab, so the enterprise conversation that follows feels urgent rather than speculative.
1:50:10 – 1:52:51 OpenClaw as the operating system for agents
This is the conceptual core. Jensen walks through what an agent framework does: manage resources, call tools, read and write files, connect to large language models, schedule jobs, decompose a task into steps, spawn sub-agents, and talk through text, voice or messaging. His conclusion is that this checklist matches the definition of an operating system. The press release states the line more crisply: “OpenClaw is the operating system for personal AI.”
The analogy matters for how NVIDIA positions itself. If agent frameworks are the new OS layer, then NVIDIA does not need to own that layer. It needs to be the default hardware, model and security vendor underneath it, the same way it never owned Windows or Linux but sold the silicon both ran on. The comparison to Linux, HTML and Kubernetes (1:52:24) reinforces that: each was an open standard that forced every company to form a strategy around it.
1:52:51 – 1:54:42 From tools for humans to agents for rent
Jensen sketches enterprise IT “before OpenClaw”: data centers hold files and structured records, software vendors sell tools, and systems integrators teach people to use those tools. He stresses that governance, security, privacy and compliance remain valuable in that stack.
The disruptive claim lands at 1:54:05: every SaaS company becomes an “agent as a service” company. In plain terms, vendors would stop selling seats for humans to click through and start renting specialized agents that do the work. Whether that shift happens on Jensen’s timeline is uncertain, but the direction is consistent with how many SaaS firms already market AI add-ons. For NVIDIA the implication is direct: agents consume far more tokens than humans clicking buttons, and tokens are produced by GPUs.
1:54:42 – 1:56:37 The security problem, NemoClaw and OpenShell
Jensen names the obvious objection himself. An agent inside a corporate network can access sensitive information, execute code and communicate externally. Put those three together and an agent could, in principle, pull employee, supply-chain or financial data and send it outside the company.
NVIDIA’s answer, built with Steinberger, is NemoClaw: an enterprise reference stack for OpenClaw built on the NVIDIA Agent Toolkit. Its key piece is OpenShell, a runtime that gives each agent an isolated sandbox and enforces three kinds of control. Policy engines decide what an agent may do, and Jensen says existing SaaS vendors’ policy engines can be plugged in. Network guardrails limit what the agent can reach. A privacy router decides when a request can leave the machine for a cloud frontier model and when it must stay on a local open model such as Nemotron.

The slide shows the business logic more clearly than the speech. Nearly every box around the agent maps to an existing NVIDIA library: data processing (cuDF, cuVS), virtual GPUs, models and serving (Nemotron, NeMo, Dynamo, NIM), the AI-Q research blueprint, and cuOpt for optimization. NemoClaw is therefore less a new product than a distribution channel that bundles NVIDIA’s software catalog into the agent runtime companies are already installing.
Jensen briefly revisits the theme at 2:03:43, predicting that engineers will get annual token budgets on top of salary. He said he could imagine adding tokens worth about half an engineer’s salary; this was not in any official release. That passage is covered on the Nemotron coalition page.
What changed since GTC 2025
At GTC 2025 (March 18, 2025), NVIDIA’s agent story was model-and-blueprint centric. It launched the Llama Nemotron reasoning models in Nano, Super and Ultra sizes and the AI-Q Blueprint, which connects enterprise knowledge to agents through NeMo Retriever and the open-source Agent Intelligence toolkit. Partners named included Microsoft, SAP, ServiceNow, Accenture and Deloitte. The framing was that NVIDIA supplies models and recipes and enterprises build their own agent platform.
GTC 2026 flips the emphasis. Instead of asking enterprises to assemble agents from NVIDIA parts, NVIDIA endorses a third-party framework that already has momentum and positions itself as the security and model layer under it. Three things are new this year:
- A named runtime. OpenShell did not exist at GTC 2025. The 2025 agent releases did not include a sandbox that wraps the whole agent; content guardrails lived in the separate NeMo Guardrails library.
- Local-first deployment. The 2025 releases centered on NIM microservices in the data center. The 2026 release explicitly lists GeForce RTX PCs, RTX PRO workstations, DGX Station and DGX Spark as always-on agent hosts.
- The model line moved on. Llama Nemotron gave way to Nemotron 3, which Jensen says runs inside OpenClaw; see the Nemotron page.
What carried over: AI-Q and NIM appear on the NemoClaw slide, so the 2025 building blocks were absorbed rather than replaced.
Skip list
- 1:47:44 – 1:49:10: the install demo video. It shows a terminal and a chat window but no architecture detail.
- 1:49:38 – 1:50:10: the brewery and “lobster lager” anecdote. Entertaining, no product information.
Glossary
- OpenClaw — An open-source agent platform created by Peter Steinberger that lets an LLM-driven agent use tools, files, schedules and sub-agents. Not an NVIDIA product.
- Claw — NVIDIA’s shorthand for a self-evolving, always-on autonomous agent built on OpenClaw.
- NemoClaw — NVIDIA’s stack for OpenClaw that installs Nemotron models and the OpenShell runtime in one command, using the NVIDIA Agent Toolkit.
- OpenShell — NVIDIA’s agent runtime that provides an isolated sandbox with policy-based security, network guardrails and privacy controls.
- Privacy router — The OpenShell component that decides whether a request stays on a local model or may go to a cloud frontier model.
- Agent as a service — Jensen’s term for SaaS vendors renting task-specific agents instead of selling software seats to humans.
For the hardware and economics that make always-on agents affordable, see token economics and the inference inflection and the full keynote notes.
FAQ
Is OpenClaw an NVIDIA product?
No. OpenClaw is an independent open-source agent platform created by Peter Steinberger. NVIDIA's contribution is NemoClaw, a stack that installs on top of OpenClaw, plus the OpenShell runtime that NemoClaw sets up.
What does NemoClaw actually add to OpenClaw?
According to NVIDIA's March 16, 2026 release, NemoClaw installs Nemotron models and the OpenShell runtime in one command. OpenShell provides an isolated sandbox with policy-based security, network guardrails and a privacy router that decides when an agent may call cloud models.
Where in the GTC 2026 keynote is the OpenClaw segment?
It runs from about 1:46:32 to 1:56:37 in the official recording. Jensen returns to the theme briefly around 2:02:40 when he talks about every company needing an OpenClaw strategy and token budgets for engineers.
Can NemoClaw run without the cloud?
Yes. NVIDIA says it can use open models such as Nemotron running locally on RTX PCs, RTX PRO workstations, DGX Station or DGX Spark, and only route to cloud frontier models through the privacy router when policy allows.