xAI (now folded into SpaceX, so officially SpaceXAI, we'll get to that) launched Grok Bot today. The pitch isn't a chatbot. It's a coworker. You don't prompt it, you hire it: message it like a teammate, hand it real work, and it keeps going after you close your laptop. Each Bot gets its own computer in the cloud and signs into your actual tools, Gmail, Zendesk, your CRM, then does multi-step work around the clock and only pings you when it needs a yes.
It's the most literal version of the "AI employee" pitch anyone has shipped. It's also the one I'd be most nervous handing my logins to, and I want to walk through why without pretending the idea is boring. It isn't.
The one genuinely new idea
Strip off the marketing and there's a real idea here, a good one. Every Bot drives its own computer in the cloud. Not an API integration, an actual desktop it clicks around on like a person. That means it can use anything you can use, including the internal tool with no API and the SaaS app that never shipped an integration. Most agents are boxed in by whatever connectors their vendor pre-built. This one just logs in and clicks.
Two things stack on top, and they're the parts I'd actually want to test. You can teach a Bot by demonstration: run a workflow once with it watching, it saves the steps and does it itself next time. And you can run a swarm of them with a "chief of staff" Bot on top delegating to specialists, so they hand work to each other instead of routing everything through you. If that works even half as well as the demo suggests, it changes how this stuff feels to use. Big if.
The Cursor thing nobody's saying out loud
Here's the detail almost no coverage is going to lead with. The desktop builds download from downloads.cursor.com. The app is versioned Grok_Bot_0.16.0. The two paid tiers are literally named Cursor Ultra and Cursor Premium Teams. "Contact sales" points at cursor.com.
This is Cursor. Or rather, this is what came out of SpaceX agreeing to buy Anysphere, the company behind Cursor, in a roughly 60 billion dollar all-stock deal earlier this year. The Information reported the two teams built Grok Bot together under the codename "Sand." So the story isn't just "Musk ships an agent." It's a 60 billion dollar coding-tool acquisition, repackaged and shipped as a general-purpose coworker, with the coding brand's name still stuck on the price tiers. Read the pricing page and you can see the seams.
What it costs, and the bet underneath
None of it is cheap, and that's the point.
| Product | Vendor | Price |
|---|---|---|
| Grok Bot | SpaceXAI / Cursor | $120/seat/mo (Teams), $200/mo (Ultra) |
| Claude Cowork | Anthropic | included, Pro $20 up to Max $200/mo |
| Copilot + Cowork | Microsoft | $30/seat/mo + metered credits |
| Devin | Cognition | $20 to $200/mo; Teams $80 + $40/seat |
Grok Bot is priced against a job, not a tool. A hundred and twenty to three hundred dollars a month is contractor money, pointed at work that used to cost a salary: the SDR doing outbound, the ops coordinator seating new hires and processing invoices out of Gmail, the junior engineer reproducing bugs and filing tickets. That's the whole bet. Call it agent-as-headcount. It's a coherent bet. It's also completely unproven, and every capability claim behind it comes from xAI's own page, the five glowing in-house testimonials included. No independent hands-on existed when I hit publish.
And if you've read my last couple of notes, you'll catch the irony. I spent two posts arguing that cheap open-weight models out of China are quietly eating the closed labs' lunch. Grok Bot is the opposite trade: closed, gated behind three premium tiers, enterprise on a waitlist. xAI's own Grok 4.5 API is aggressively cheap. The coworker built on top of it is anything but.
The part that stops me cold
Now the thing I can't get past. The entire model depends on the Bot holding live credentials to your real accounts and acting in them, around the clock, mostly unsupervised. "Sign in to Zendesk so I can work the queue." "Log into Gmail." You are handing a cloud computer, run by SpaceXAI, standing keys to your stack.
Maybe you trust that. A lot of people won't, and they have reasons. This is the company whose chatbot called itself "MechaHitler" and posted antisemitic content last year after a single system-prompt tweak, an incident that cost X its CEO inside a day. Grok 4 was caught searching Elon Musk's own posts before answering controversial questions. Last December its image tool generated sexual deepfakes of real people, reportedly including apparent minors, pulling in regulators across several countries. And in July, Grok's coding tool quietly uploaded users' repositories to a SpaceXAI cloud bucket before the backlash forced a change.
None of that is ancient history, and none of it is about raw capability. It's about judgment and safeguards, which is exactly what you're trusting when you give something your logins and turn your back. The first comments on Hacker News weren't about whether it works. They were variations on "I would never let this near my data," plus a pointed "outside America this is most likely not going to fly." For a European shop, that last one isn't a vibe, it's a procurement conversation. And the exact legal entity that would be holding your credentials is itself moving: SpaceX absorbed xAI in February, and the Cursor deal hadn't formally closed at launch.
The competitors learned this lesson already. Anthropic's Claude Tag acts under a per-channel service account, not your personal login, with every action logged. Microsoft's Copilot Cowork leans hard on enterprise governance. Grok Bot's answer to "who is this acting as" appears to be: you. That's the design choice I'd want answered before any other.
What would change my mind
I'm not writing this off. The own-computer approach is the most interesting agent idea I've seen this year, and teach-by-demonstration is the kind of thing that either works and changes everything or falls apart on the second edge case. I want to know which. Three things would move me:
- An independent score for the model behind it. xAI didn't even name which model powers Grok Bot, and shipped zero Grok Bot-specific benchmarks. Grok 4.6 was promised "this week" and the rollout is reportedly tied to it, so maybe that explains the silence. But "trust us, it's good" from the MechaHitler company is a hard sell.
- A real hands-on that shows it hitting 100, not 90. Their own product lead admits it on the page: "There is a huge difference between 90% done and 100% done." He's right. And 90% done, unsupervised, in your live Gmail is worse than useless.
- Boring, clear answers on credential isolation and data handling. Where do the keys live, what can the Bot see, what gets logged, what happens to your data. Enterprise is waitlist-only and none of it is spelled out.
Until those land, treat every claim on that page as an ad. Because that's what it is.
Where I land
Genuinely new idea, buried inside a repackaged coding acquisition, priced like a hire, wrapped around a trust model I'm not ready to accept from this particular company. If any lab was going to make me want strong credential isolation and an audit log before I said yes, it's this one.
If you've read my other notes you know I'm a Claude guy, and I'll say it plainly here too: I'd hand this class of access to an agent whose vendor foregrounds identity, scoping and logging long before I'd hand it to one whose headline feature is that it logs in as me. I'll test Grok Bot the day there's an independent number and a straight answer on where my logins live. Not before.
Drawn from the x.ai/bot product page and the Grok Bot launch post, Bloomberg and 9to5Mac's launch coverage, The Information's reporting on the Cursor "Sand" collaboration and the roughly 60 billion dollar Anysphere deal, the launch-day Hacker News thread, Simon Willison's write-up of Grok searching Musk's views, and public pricing pages for Grok Bot, Claude Cowork, Copilot and Devin. A snapshot as of August 11, 2026. Every capability claim is xAI's own, there was no independent hands-on at publication, and the model powering Grok Bot wasn't named, so check x.ai/bot before you quote me.