What is Grok Bot? The answer is in the fine print
A persistent AI coworker with its own cloud computer, your logins, and a meter nobody capped. Here's the whole picture, two days in.
I'm going to do the thing I usually do here, which is learn something in public and let you watch. I have not used Grok Bot. It came out two days ago. What I have done is read every primary source I could reach - xAI's own docs, Cursor's help center, the launch thread, the competitors' architecture pages - and I found something in there that changed my mind about the whole category, not just this product.
Let's start with the part you actually searched for.
What is Grok Bot?
Grok Bot is xAI's persistent AI agent product, launched in early beta on August 11, 2026. Each account gets an always-on cloud computer - a real machine with a browser, a filesystem, and a terminal, assigned to you and reported to run Linux - and you create named "Bots" that sign into your existing apps with your own sessions and do multi-step work inside them. It keeps running after you close your laptop. It is not sold on its own; you get it through a Cursor Ultra, Cursor Premium Teams, or SuperGrok Heavy subscription.
That's the answer. Here's the shape of it:
What it is -- Persistent AI agents with a shared cloud computer (browser + files + terminal)
Launched -- August 11, 2026, early beta
Made by -- xAI, now a SpaceX subsidiary operating as SpaceXAI
How you get it -- Cursor Ultra ($200/mo), Cursor Premium Teams ($120/seat/mo), or SuperGrok Heavy. Enterprise: contact your Cursor account team.
Sign-in -- Your Cursor account. Not an xAI account.
Where the bot runs -- Its own persistent cloud computer, assigned to your account - reported to be a Linux VM. It keeps working with the app closed.
Where you run the app -- macOS, Windows, iPhone (iOS 18+). No Linux desktop, Android or iPad client at launch.
Spend cap -- None yet, per pricing analysts who've read the docs
Audit log -- Reported as "coming"
Isolation between your bots -- None. All of your bots share one machine.
The last row is the story. I'll get there.
How is this different from just using Grok?
Regular Grok is a conversation. You ask, it answers, you close the tab, the context evaporates.
Grok Bot is a computer that keeps running after you stop talking to it. The distinction sounds like marketing until you look at what it buys you:
It works in apps that have no API. Because the bot drives a real browser with your real session, it can operate software that never shipped an integration. That's most business software. (This is the computer-use pattern I wrote about when GPT-5.5 got better at driving a desktop than I am - Grok Bot is that capability given a permanent machine and a to-do list.) xAI does say to prefer a structured connector where one exists - the docs call them connectors, the app surfaces them as "Plugins" - because clicking through a website is less reliable than calling an API. But the browser is the fallback, and the fallback is the point.
It keeps working when you're gone. One distinction worth being precise about, because coverage keeps muddling it: the app on your Mac, PC, or iPhone is just the window. The work happens on the bot's own cloud machine, and xAI's docs say it plainly - "closing the app, laptop, or iPhone does not stop a background turn or routine." (That's also why the "no Linux support" line you'll see elsewhere is misleading - there's no Linux client app, but the bot's own computer is a cloud VM, reported to run Linux.) The demos lean hard on this: the bot researches overnight, files the results in the morning.
You can teach it a routine once. Show it a workflow, it records the sequence, then replays it. This is the piece I find most credible, because it's the least magical. Recorded routines are a solved problem; putting a model in charge of adapting one is a modest ask.
Bots can hand work to each other. You can run several named specialists in one thread and have them pass tasks around. The pattern xAI shows off is a "chief of staff" bot coordinating a recruiting bot and an ops bot.
Where this pattern actually came from
If "a named agent that lives on its own machine and works while you sleep" sounds familiar, it should. Hermes and OpenClaw pioneered exactly this shape in the open-source world - free, self-hosted, model-agnostic, beloved by tinkerers who were happy to be their own security team. (I spent two months ignoring Hermes and then actually tested it; the pattern is real, and so is the babysitting.) The one published comparison that puts all three side by side lands on the honest summary: the meaningful differences today are openness, which tools each already knows how to sign into out of the box, and pricing model.
But the fight xAI actually picked is the commercial one. OpenAI shipped ChatGPT Work on July 9. Anthropic has Claude Cowork. The market has already named the category - a Reddit thread two days after launch grouped them without prompting - "Claude has Cowork. OpenAI has ChatGPT Work. XAi as Grok/Cursor Bot" - and then asked the question hanging over Google, which so far has nothing here. So the genealogy runs: the open-source agents proved people wanted this badly enough to self-host it, Cowork and ChatGPT Work productized it for professionals, and Grok Bot is xAI arriving third to the paid tier - with the free originals still sitting underneath as the way to try the pattern before anyone gets your card number.
What does Grok Bot cost?
This is where I want you to slow down, because the sticker price is the least useful number on the page.
The plans that include it:
Cursor Ultra - $200/month, individual
Cursor Premium Teams - $120/seat/month
SuperGrok Heavy - included at no extra charge. Secondary coverage reports this tier at $300/month; I could not confirm that figure on a first-party page, so treat it as unverified.
Two flags while we're here. The $120/seat team tier appears on xAI's page but I couldn't find it on Cursor's own pricing page. And xAI can't decide what it's called: the product page says "Cursor Premium Teams," the FAQ says "Cursor Teams Premium." Neither is a conspiracy - they're both beta tells - but don't budget against a per-seat price that only one of the two companies will show you, on a plan whose name they haven't settled.
Now the part that matters. xAI's own FAQ describes the billing like this: "Grok Bot subscriptions include weekly usage; eligible accounts can add on-demand usage billed from model and token cost." Read that carefully, because a lot is packed into it, and pricing analysts who've gone through the docs report there is no Grok Bot spend cap yet. Underneath it:
Your subscription includes a weekly allowance, not a monthly one, and the size of that allowance is unpublished.
Overage is billed from model and token cost. For Grok 4.6, that's reported at $2.00 per million input tokens and $6.00 per million output tokens.
There is no model picker, for members or for admins. You don't get to route the cheap work to a cheap model.
There is no dry-run mode. Testing an action performs the action. If you're rehearsing an email send, you sent an email.
The audit view showing what your bot actually did is reported as "coming."
(The billing sentence above is xAI's, verbatim. The four bullets after it come from pricing analysts who've worked through the docs and plan pages, not from a single first-party statement - so treat them as well-reported rather than official.)
Stack those and you get a genuinely new category of invoice: an always-on process, burning tokens against an uncapped meter, choosing its own model, with no per-action log to reconcile the bill against. An early user on the launch thread, jjcm, put the burn rate about as plainly as it can be put:
"I've used less tokens in the last 5 years prior to this month than I have this month."
And a commenter named rob74 asked the only question a business owner would ask:
"So using a bot is almost like having an employee... they will just invoice you for whatever they think is necessary to do the tasks you give them?"
I don't think that's unanswerable. I think it's unanswered, on day two, by design of a beta. But "we'll add spend caps later" is a different sentence from "we shipped spend caps," and you're the one holding the card on file in the meantime. I've itemized my own AI team's monthly bill before, line by line - that was the whole point of the exercise. This bill, today, can't be itemized even by the people sending it.
Who actually owns this thing?
Follow the corporate trail, because it explains the product's shape.
February 2, 2026: SpaceX acquired xAI outright. That's why the company keeps showing up in coverage as SpaceXAI - it's a SpaceX subsidiary now.
June 16, 2026: SpaceX agreed to acquire Anysphere, the company behind Cursor, in an all-stock deal reported at $60 billion. Closing was expected in Q3, subject to regulatory approval.
August 11, 2026: xAI launched Grok Bot, gated to Cursor subscription tiers, requiring a Cursor account to sign in.
Read that sequence twice. An xAI-branded product shipped on the billing rails and identity system of a company the parent, as I write this, hasn't finished buying - though reports say the close is days away, so by the time you read this the ink may be dry. And this goes well past checkout plumbing - xAI's own security documentation states that Grok Bot "uses Cursor authentication and account data settings." Your identity, your privacy controls, your data retention, and your account deletion for this product all resolve to Cursor's systems and Cursor's terms.
That's not automatically bad. Cursor's terms are ordinary developer-tool terms. But if you evaluated this product by reading xAI's privacy policy, you read the wrong document.
It also explains something in the community reaction that confused me at first. The Grok 4.6 benchmarks thread in r/singularity pulled nearly 500 upvotes, and the read running through it is some version of "For the price, Grok is very good at coding. And very fast. I think the Cursor acquisition brought them immediate returns." The enthusiasm right now is about the model landing inside a tool people already pay for. The bot is riding in on the model's coattails.
Is Grok Bot safe? Here's the line that should decide it for you
I went looking for the security model expecting boilerplate. What I found is one of the more honest paragraphs a vendor has published this year, and it's disqualifying for a lot of use cases.
All of your bots share one cloud computer. Not one per session. One per account. I'll note the record is messier than it should be - xAI's overview page says each Bot "runs on a persistent cloud VM," and one preview user on HN says his bots each got their own - but the security page is unambiguous that files, browser sessions, and command line credentials are shared across your whole Bot roster, and when the security page and the marketing page disagree, you plan around the security page.
That machine holds one browser cookie store containing every session you've ever signed into, one filesystem, and one set of terminal credentials. The docs don't bury this. They say it in the plainest language in the whole product:
"All of your Bots share one cloud computer assigned to your user account. Files, browser sessions, and command line credentials on that computer are available across your Bot roster."
And then, in case you missed it:
"Do not use separate Bots as a security boundary."
And:
"Deleting a Bot does not remove shared-computer files or browser sessions."
So the intuitive safety move - a locked-down bot for email over here, a separate bot for the CRM over there, a third one for the bank - does not do what you think it does. Any authenticated session on that machine is reachable by every bot on the account. Delete the bot and the logins stay.
There's a second line worth knowing: Grok Bot requires data storage and does not support Legacy Privacy Mode. If you were using that setting, it doesn't come with you.
xAI's recommended mitigations are to connect only the tools a job actually needs, start with read-only tasks, and take manual control of the machine yourself when a step involves entering a password, a 2FA code, or a CAPTCHA. Those are reasonable. They are also all things you have to configure. None of them are on by default.
For context on why that matters more for agents than for ordinary software: the OWASP GenAI Security Project put Agent Goal Hijack (ASI01 - the announcement calls it agent behavior hijacking) at number one on its Top 10 for Agentic Applications - above tool misuse, above privilege abuse, above everything - and in May 2026 the Five Eyes agencies published joint agentic AI security guidance saying organizations "should assume that agentic AI systems may behave unexpectedly," and to deploy incrementally, starting with clearly defined low-risk tasks. An agent's whole job is to read untrusted text - a webpage, an email, a README - and then take actions. That is the exact input path an attacker controls.
But before you decide xAI is uniquely reckless
I want to be straight with you, because I went in expecting to write "xAI shipped something careless" and the research wouldn't let me.
Claude Cowork does isolate. Anthropic's architecture doc says each session gets its own sandbox, created at start and destroyed at end, sharing no state across sessions or organizations. Better still: "Connector authorization tokens never enter the sandbox; connector calls are made on the server side." The sandbox only holds session-scoped tokens that expire in hours. Hijack that agent mid-task and there's no standing credential sitting there to steal. That's the design Grok Bot should be measured against.
And it still got broken. On July 24, 2026, the Cloud Security Alliance published research on a chain called SharedRoot: a researcher escalated to root inside Cowork's local VM and reached the entire host Mac filesystem through an over-broad mount, exposing SSH keys and cloud credentials. The entry point was ordinary - a poisoned README or webpage - though the escape itself chained through a Linux kernel bug (CVE-2026-46331). A reported 500,000 macOS users were running that mode. Anthropic classified the report as "Informative," shipped no patch for local execution, and shifted the default toward cloud execution instead. The CSA's own conclusion was that this is a recurring failure pattern across agent products, not one vendor's mistake.
ChatGPT Work, launched July 9, 2026, leaves the identity model to the customer. TechRepublic's guidance to IT teams deploying it is to inventory every connection and document whether it runs on delegated employee credentials, a shared account, or a dedicated identity - which tells you the product isn't deciding that for you.
So the honest scoreboard is: Anthropic designed the strictest boundary and still had it chained through. OpenAI made it your policy problem. xAI made it your problem and wrote it down in the manual. Only one of those three told me the boundary doesn't exist before I found out the hard way.
I'd rather have the isolation. But I'll take the honesty over a promise nobody stress-tested.
What happens when everybody has one?
The single most-shared demo from the launch thread wasn't a coding task. A user named jjcm - the same person who reported the token burn a few sections up, which is its own kind of data point - pointed a bot at sourcing and had it "reach out to ~40 fabric suppliers in vietnam, negotiate prices, lock one in, and get samples made." (Worth the footnote: jjcm later clarified the bot started with 5, tried 5 more, and he personally pushed it to contact the other 30. Even the flagship demo had a human doing the scaling.)
Impressive anyway. Then a commenter named pavel_lishin said the thing that ate the entire thread:
"Isn't this one of the problems foreseen with this? For you, it was a single prompt - for 40 companies, this probably took up some time. What happens when fifty people fire off a 15-second 'get me a shirt' prompt? When five hundred, five thousand, five million do?"
And raincole closed the loop in one sentence:
"The 40 companies will have to use AI to filter the messages too."
That is the whole second-order economy in one exchange. Your prompt costs you fifteen seconds and some tokens. It costs forty other businesses real attention, and their only defense is to buy an agent of their own to read your agent's mail. Both sides now pay a token bill for a conversation neither human is having. Another commenter, slg, summarized it better than I could:
"Everything is becoming wildly inefficient, all in the name of improved efficiency."
I don't raise this to be cute about it. I raise it because if you're a small operator, you are on the receiving end of this before you're on the sending end. Your inbox, your contact form, your job postings, your DMs. A commenter in that same thread, zeafoamrun, described the version already happening to him:
"It's crazy dude, whenever we put up a job ad it's filled with thousands of LLM generated fake candidates in a few days."
That's landing on you whether or not you ever buy a bot.
So should you use it?
Here's where I have to be honest about my own position, because it's the reason this piece exists.
My actual problem is not "I need an agent." I already run my agents like a company, not a pile of freelancers, and I've compared AI teammates head to head before. My actual problem is that I'm running Perplexity, Claude, ChatGPT, Buzz, Paperclip, Hermes, and Cursor, I like every one of them for something specific, and not one of them does the whole job. Every tool I add is another login, another bill, another place where context I already explained once has to be explained again. The thing I want doesn't exist yet: one system that can hold my whole set of workflows end to end.
Grok Bot is the first product I've seen that's shaped like that answer. Persistent, tool-agnostic, works in software that has no API, remembers between sessions. On paper it's the pitch.
Which is exactly why I'm being careful. I want it to be true, and that's the condition under which I'm most likely to talk myself into something.
So I wrote down what would actually have to happen before I move - three tests, and the reason each one is a hard gate rather than a nice-to-have. That's the rest of this piece, along with the specific configuration I'd insist on before pointing this at anything real, and the question I think is more useful than "is it good."







