Anthropic temporarily banned OpenClaw’s creator from accessing Claude this week. Details are fuzzy, because platform enforcement stories always are when the platform controls the narrative. Something about terms of service, usage patterns. Or both. And the ban got lifted after some back-and-forth. But for a stretch of time, the developer behind one of the most popular open-source AI agent tools on GitHub could not access the model his tool was built around.

I keep seeing people frame this as drama. “Anthropic overreacted.” Or “the guy was clearly abusing the API.” Pick a side, argue about it on X, forget about it by Friday. But whether the ban was justified is actually the least interesting question.

What the ban exposed

OpenClaw has 100K+ GitHub stars. Thousands of people use it daily for task automation, scheduling, communications. And it routes primarily through Claude’s API — not exclusively, but enough that losing Claude access does not just degrade the experience. It guts the core product.

So when Anthropic flagged the creator’s account, the blast radius extended well past one developer’s login credentials. Every user whose workflow depended on OpenClaw running on Claude was one trust-and-safety ticket away from a dead tool. And none of them had done anything wrong. They did not violate any terms or trip any automated system. They just built daily habits around an agent that had a single point of failure, and that failure point activated with zero warning and zero mechanism for the downstream users to prevent it or even see it coming. A single support ticket can cascade into thousands of broken workflows, and nobody downstream gets a warning or a vote.

This is a different category of risk from the Anthropic-Pentagon situation I wrote about in March. That dispute was geopolitical and dramatic, the kind of thing that generates App Store surges and cable news segments. ToS enforcement actions are none of those things. They happen quietly, without press releases, without anyone outside the affected user base even noticing until somebody posts about it on Hacker News two days later. And they are far more common.

Wrong question

“Did Anthropic have the right to ban him?” Sure, probably. That is not the point.

Leased, not owned

Every LLM provider reserves the right to terminate your access for almost any reason, and the terms are written to maximize the platform’s flexibility, not yours. You agree by clicking a button you did not read. And the provider gets to decide later whether your usage pattern qualifies as acceptable, whether your application fits the “permitted use” definition that their legal team rewrote last quarter, whether your agent’s behavior crosses some line that did not exist when you started building on their API eighteen months ago. This is fine for weekend projects. But it becomes a structural risk when your entire product’s capability routes through a single endpoint controlled by a company whose enforcement decisions you cannot predict, cannot appeal quickly, and cannot survive without.

Nobody at OpenClaw chose to accept this risk explicitly. They just started building. And the dependency calcified over time, the way dependencies always do.

BYOK agents don’t have this problem

A browser agent with multi-model support does not have a single point of failure. If one provider bans your key, suspends your account, or changes their terms in ways you cannot live with, you swap to another model and keep working. Your workflows stay intact. Your users notice nothing. Because the agent is the product, and the LLM underneath is plumbing you can reroute.

Dassi supports Claude, GPT, Gemini, DeepSeek, and others, and you can use your existing ChatGPT subscription directly without needing an API key. So if Anthropic’s trust-and-safety team flags your account on a Friday afternoon, you change one dropdown on Saturday morning. Your browser agent keeps working because it was never dependent on one model in the first place.

The part everyone misses

OpenClaw users did not lose access because they got banned. They lost access because their tool’s developer got banned. And that is a layer of indirection most people never think about until it bites them. You trusted a tool. The tool trusted a provider. And the provider made an enforcement decision that cascaded down the chain to you, sitting at your desk, trying to get crap done on a Wednesday afternoon.

Building on a single provider’s API means trusting a chain of relationships you cannot see or influence. And that chain, as OpenClaw’s users briefly discovered this week, is more fragile than anybody’s landing page will ever admit.

OpenClaw’s creator got his access back. Next time, somebody won’t.