Grok Bot and the Always-On Assistant: What Changes When AI Gets a Computer
Grok Bot runs named AI agents on a persistent cloud computer that keeps working when your laptop is closed. What the persistence model, action boundary, pricing and safety controls actually look like in the first week.
On this page
- What happened
- What persistence actually changes
- The action boundary and the safety controls
- The pricing picture, with the conflicts intact
- What to do now
- FAQ
- What is Grok Bot, exactly?
- How much does Grok Bot cost?
- Is it safe to give Grok Bot my accounts?
- Does Grok Bot work while my laptop is closed?
- The bottom line
- Sources
I'll concede the strongest argument against this product first, because it's a good one. Giving an AI agent its own always-on computer, signed into your accounts, working while you sleep, is roughly the threat model security teams have spent two years warning about, packaged as a consumer feature with a waitlist. If you've read anything about memory poisoning or prompt injection, your eyebrows should already be up.
And yet. On 11 August, xAI (now operating as SpaceXAI) launched Grok Bot in early beta, and it is the clearest expression yet of where the assistant category is going: not a smarter chat window, but a persistent operating entity with a machine of its own. I've read the announcement, the docs coverage and a week of hands-on reporting. Here's what the persistence model actually is, where the action boundary sits, what it costs, and which safety controls are real versus decorative.
Key Takeaways - Grok Bot is a roster of named AI agents that share one persistent cloud computer per account: files, browser sessions, logins and memory all survive between sessions and keep running when your devices are off. - The action boundary is approvals, not APIs. Bots work through a real browser and signed-in accounts, including apps with no API or MCP server, and return for sign-off on judgement calls. - Access is bundle-gated: SuperGrok tiers and eligible Cursor plans, with standalone pricing reported around $200 per month. Third-party sources disagree on exact tiers, so treat the numbers as reported rather than audited. - The safety controls are more detailed than beta norms (per-action approvals, auto-review rules, secure handoff for credentials) but every Bot on an account shares one computer, so a second Bot is not a security boundary. - The strategic shift: the assistant stops being a session and becomes a machine. That moves the risk conversation from "what did the model say" to "what does the machine have access to," and most organisations have no policy for that yet.
What happened
On 11 August, SpaceXAI published the Grok Bot announcement, with availability on desktop and iOS. The key facts, from the announcement and the first week of coverage:
Grok Bot is a team of named agents, not a chatbot mode. You message a Bot like a colleague, hand off a task, and it works on its own cloud computer until the job is done or it needs approval. Bots can message each other, coordinate in group threads, and hand work between specialists.
Each account gets one persistent cloud computer, shared by every Bot on it. Files, browser logins, connected accounts and memory persist across sessions. Skills (saved workflows, in the SKILL.md convention) can be attached to routines that run on a schedule.
It works through real apps, including sites with no API: connectors cover Gmail, Google Calendar and Drive, OneDrive, Outlook, Teams, SharePoint and Salesforce, with MCP support for custom tools, and browser-based computer use for everything else.
Availability at launch covered SuperGrok tiers and Cursor plans, with an enterprise waitlist; coverage tracked the expansion to additional SuperGrok and Cursor tiers by 21 August. The underlying model is Grok 4.6, announced the next day with a 500,000-token context window and API pricing of $2 per million input tokens and $6 per million output, per the same reporting.
SpaceXAI says it ran the product internally first, across sales, marketing, ops and engineering, before opening the beta. The company itself is newly rebranded: this is xAI under its SpaceXAI name, with Cursor's involvement tracing to SpaceX's reported acquisition.
One honest sourcing note: plan names and prices moved during beta week, and third-party guides contradict each other (and occasionally the launch post) on which Cursor tiers qualify. I've flagged the conflicts below rather than picking a winner.
SpaceXAI launched Grok Bot in early beta on 11 August 2026: named AI agents sharing one persistent cloud computer per account, working across apps and websites with approval-based handoffs, per the announcement. Access is bundled with SuperGrok and eligible Cursor subscriptions, with expansion tracked by launch-week coverage.
What persistence actually changes
The word "persistent" is doing heavy lifting in every agent pitch this year, so it's worth being precise about what persists here. Three layers, and they compound.
First, the machine. The cloud computer keeps its filesystem, installed skills and browser sessions. A Bot you brief on Monday still has Friday's login state and the Notion plugin you connected. That's what makes "hand it off at 6pm, read the result over breakfast" an architecture rather than a marketing line, and it's the same shape as the self-hosted agent setups some teams build themselves, minus the ops burden and plus someone else's datacentre.
Second, the relationship. The Bots remember conversations, learn workflows by watching you do them once, and take corrections into saved routines. The pitch is that the asset you build by working with a Bot (its memory of how you like things done) survives model upgrades, because it lives on the machine rather than in the chat.
Third, the team. Multiple Bots run in parallel on the same computer and coordinate in shared threads, with a "chief of staff" pattern SpaceXAI describes from internal use. This is also where the honest caveat sits: per Vellum's detailed breakdown of the official docs, every Bot on an account shares that one user-scoped computer, so files, credentials and browser sessions are account-wide. A second Bot is a productivity boundary, not a security one. If your mental model was "give the sales Bot and the finance Bot separate permissions," that is not what this beta offers.
Grok Bot's persistence spans the machine (files, browser sessions, skills), the relationship (memory of preferences and corrections) and the team (parallel Bots coordinating on one account-scoped computer), per the announcement and the docs-based breakdown. Bots on one account are not isolated security boundaries.
The action boundary and the safety controls
With a chatbot, the action boundary is the send button: the worst case is bad text. With a persistent computer signed into your accounts, the worst case is a bad action, repeated, at 3am. So the controls matter more than the demo, and to its credit the security surface is more developed than beta norms, per the docs analysis:
Per-action decisions: Allow once, Deny, or Always allow, so approval scope is granular rather than all-or-nothing.
Auto Review rules in two modes: Require Approval (pause for human sign-off) and Always Allow under defined conditions.
Secure handoff for sensitive steps, where the Bot passes control back to you, which is the right pattern for passwords and two-factor codes.
Least-privilege guidance in the official docs, plus controls for when a Bot operates on your local machine rather than the cloud VM.
The gaps are equally instructive. There is no documented way to inspect, export or selectively delete what a Bot remembers, which is an odd omission for a product whose whole premise is accumulated memory. Privacy settings depend on your access route: come in via Cursor and Cursor manages your data settings, not xAI. And the always-on, schedule-driven shape means the failure mode to plan for isn't a rogue answer, it's a routine quietly doing the wrong thing every night, approved weeks ago, noticed never. Anyone who has read the recent work on multi-agent contamination will recognise why "agents writing their own persistent state" deserves logging rather than trust.
Worth saying plainly: none of this is a reason to panic, and none of it is a reason to connect your primary accounts on day one of a beta. It's a reason to treat onboarding a Bot like onboarding a contractor. Scoped accounts, approval defaults on, and a look at the audit trail before you widen access. That's agent governance as hygiene, not as fear.
Grok Bot's documented controls include per-action approvals, Auto Review rules, secure handoff for sensitive steps and least-privilege guidance, per the docs analysis. Documented gaps include memory inspection and export, and account-wide credential sharing between Bots.
The pricing picture, with the conflicts intact
What does an always-on computer cost? The honest answer is "it depends which door you came in through," and the doors kept moving during beta week. As reported across setup guides and plan trackers: SuperGrok Heavy at about $300 per month includes it; Cursor Ultra at $200 per month includes it; Cursor Teams Premium at $120 per seat per month includes it with a weekly allowance; and Vellum's breakdown reports a $200 per month standalone price after a 14-day trial. The launch post's own eligibility list is broader than several of these guides, so I'd treat every number in this paragraph as reported rather than audited, and check the live plan page before budgeting.
The structural point matters more than the figures. Bot usage is metered separately from your Grok and Cursor allowances, so delegated work doesn't eat your chat quota, which is SpaceXAI's quiet acknowledgement that always-on agents consume compute on a different curve. And there's no self-hosting: the computer is theirs. Compare the TrueForge analysis from the same month, where the whole pitch is owning the runtime. The market is currently offering both bets at once, rent the machine or own the harness, and the right answer genuinely depends on whether your constraint is ops capacity or control. It depends. Irritatingly, it always does.
What to do now
Whether or not Grok Bot is your pick, the category just became concrete. Four steps:
Today: write your organisation's answer to "can an employee put a persistent agent on a personal plan inside our tools?" Grok Bot reaches staff through consumer subscriptions, not procurement, per Beam's enterprise analysis. If the policy doesn't exist, the answer is currently yes by default.
This week: if you're on an eligible plan, run one bounded task with a dedicated, least-privilege account. Watch the approval prompts. The shape of the boundary tells you more than any review, including this one.
This month: define your action-boundary policy before your second Bot: which actions may run unattended overnight, which always require sign-off, and how you'll audit what ran while you slept.
Before any expansion: decide what may live on a machine you don't control. Files and logins on someone else's always-on computer are a data-location decision, same as any architecture call, and cheaper to make deliberately than retroactively.
FAQ
What is Grok Bot, exactly?
A roster of named AI agents from SpaceXAI (formerly xAI), launched in early beta on 11 August 2026. Each account gets one persistent cloud computer that all its Bots share: they sign into your apps, work through a real browser, remember how you like things done, and keep running when your devices are off. It is a product, not a model; the model underneath is Grok 4.6.
How much does Grok Bot cost?
Access is bundled with SuperGrok tiers (Heavy is reported at about $300 per month) and eligible Cursor plans (Ultra at $200, Teams Premium at $120 per seat), with standalone pricing reported at $200 per month after a 14-day trial. Plan details shifted during beta week and third-party sources conflict, so verify against the live plan pages before committing.
Is it safe to give Grok Bot my accounts?
The documented controls are real: per-action approvals, auto-review rules, secure handoff for credentials, least-privilege guidance. The structural cautions are also real: all Bots share one account-scoped computer with shared credentials, memory can't currently be inspected or exported, and there's no self-hosting option. Scoped, dedicated accounts with approvals on is the sensible beta posture.
Does Grok Bot work while my laptop is closed?
Yes, that's the core design. The cloud computer runs independently of your devices, and routines let saved skills fire on a schedule. It's also the feature that changes your risk model: an always-on agent acts when nobody is watching, so the approval policy you set is the whole game.
The bottom line
Grok Bot is a beta with moving prices, shared credentials and a missing memory-inspection feature, and it is also the most coherent statement yet of the assistant-as-machine category. The session is ending as the unit of AI work; the always-on computer with approvals, routines and accumulated memory is replacing it, and SpaceXAI got a credible version out the door first. The question for the next year isn't whether this shape wins (something like it will), it's whether the safety and audit tooling matures faster than the access people hand over. Watch the enterprise waitlist and the permission model. That's where the real product is being negotiated.
If you're working out how always-on agents fit your organisation, that's a conversation I have with clients regularly. Get in touch.
Sources
SpaceXAI, "Introducing Grok Bot": https://x.ai/news/introducing-grok-bot (published 2026-08-11, retrieved 2026-08-29)
Vellum, "Official Grok Bot Breakdown (2026)": https://www.vellum.ai/blog/official-grok-bot-breakdown (published 2026-08-20, retrieved 2026-08-29)
Truescho, "Grok Bot by xAI 2026: AI Teammates With Their Own Cloud Computer": https://truescho.com/en/blog/grok-bot-xai-ai-teammates-2026 (published 2026-08-15, retrieved 2026-08-29)
Skillselion, "What Is Grok Bot? Pricing and How It Works": https://skillselion.com/guides/what-is-grok-bot (published 2026-08-16, retrieved 2026-08-29)
Basenor, "Grok in August 2026: 5 Details That Actually Matter": https://www.basenor.com/blogs/news/grok-in-august-2026-5-details-that-actually-matter (published 2026-08-25, retrieved 2026-08-29)
Beam, "Grok Bot for Enterprise AI Agents: The 2026 Reality": https://beam.ai/agentic-insights/grok-bot-enterprise-ai-agents (published 2026-08-27, retrieved 2026-08-29)
Keep reading
Agent Field Notes
Get the next issue.
Agent harnesses, runtimes, security and governance, explained for the people who have to operate them.
Facing a decision like this?
We run architecture reviews, governance assessments and version-pinned framework evaluations for teams making consequential agent decisions.