Popular open source AI agent OpenClaw is expanding to the iPhone and iPad with a new native iOS app. OpenClaw for iOS can be used alongside an existing gateway as a secure node for chat, voice approvals, sharing, and device-aware automation.

The iOS app replaces iPhone and iPad workarounds that involved using Telegram or WhatsApp for on-the-go access.
OpenClaw is a self-hosted AI agent that runs on a Mac or PC. Users can connect an API key from Claude, OpenAI, Gemini, or other AI services, linking the model to content on the gateway machine. OpenClaw lets an AI model access messaging apps, files, web browsers, and more, so it can complete tasks.
To make use of the new iOS app, you'll need a gateway running on a local machine. The App Store description says the iOS app can be used in multiple ways.
- Pair with your private OpenClaw Gateway by QR code or setup code
- Chat with your assistant from iPhone
- Use realtime and background Talk mode
- Review Gateway action approvals from your iPhone
- Share text, links, and media directly from iOS into OpenClaw
- Enable device capabilities such as camera, screen, location, photos, contacts, calendar, and reminders when you choose
- Receive push wakes and node status updates for connected workflows
OpenClaw is a useful tool, but it has risks. It is susceptible to prompt injection and requires broad system permissions on gateway devices.
OpenClaw started out as Clawdbot, because the initial version created by Peter Steinberger used Claude. Anthropic complained about the name, prompting a rename.
The app can be downloaded from the App Store for free. [Direct Link]

















Top Rated Comments
I'm already exhausted from "AI".
But that doesn’t mean the technology itself is useless. The internet created enormous wealth for a handful of companies, yet it also fundamentally improved how we work, communicate, and learn. AI can be viewed the same way.
From my own experience, AI has made me a better engineer. It automates the repetitive work so I can spend more time solving the interesting problems. It’s less about replacing people and more about amplifying what they’re capable of.
Whether AI ends up concentrating power or democratizing it depends largely on whether we embrace open models and self-hosted tools. That’s one of the reasons projects like OpenClaw are exciting—they give individuals far more control than relying solely on closed, centralized AI services.
The known gateway/token issue was patched in 2026.1.29, and the later website-to-local-agent takeover chain was fixed in 2026.2.25 within about a day of disclosure. Since then, NVIDIA has put engineering time into the project, NemoClaw/OpenShell added sandboxing, filesystem and network isolation, policy approvals, and hardened deployment defaults, and ClawHub now uses VirusTotal, static analysis, NVIDIA SkillSpector, provenance checks, and Skill Cards for skill verification.
I have it controlling my HVAC and it has complete insight into my finances. I’m not worried because I don’t run it with YOLO permissions. It’s updated, isolated, least-privilege, monitored, egress-restricted, and sensitive actions require approval.
Agentic systems need guardrails. That’s not an argument against using them. It’s an argument for deploying them correctly.