On 11 August 2026, SpaceXAI launched Grok Bot in early beta. The product is a team of always-on agents that share a persistent cloud computer, sign in to websites and apps, retain working context and continue after the user closes their laptop.
That makes Grok Bot a product release rather than a new foundation-model release. The launch is important because it packages computer use, persistent sessions, memory, routines and multi-agent coordination into one consumer and team product. It also moves the main evaluation question away from chat quality: can an agent finish a real task inside the right account without exceeding its authority?
This brief was checked on 12 August 2026 against the official SpaceXAI launch note, the live Grok Bot product page, the official launch thread on X and Matt Palmer’s launch-day walkthrough. Palmer’s article is a detailed first-hand account from a Cursor team member; it is not an independent performance test.
Release record
| Field | Verified launch detail |
|---|---|
| Announcement | 11 August 2026 |
| Status | Early beta |
| Product boundary | Multiple agents sharing one persistent cloud computer per user |
| Launch surfaces | Desktop and iOS, with a macOS Apple-silicon download promoted publicly |
| Initial access | SuperGrok Heavy, Cursor Ultra and Cursor Teams Premium subscribers |
| Enterprise access | Future access through a waitlist at launch |
| Published price | Cursor Ultra at $200 per month; Cursor Premium Teams at $120 per seat per month |
Availability, plan names and prices can change. The table records the public launch state, not a permanent entitlement or procurement quote.
What changed
The official release describes bots that can work across apps, inboxes and websites, including tools without a clean API or MCP integration. A user can message a bot like a colleague, leave the task running and return when approval or judgement is needed. The product page also says bots can learn a demonstrated workflow, save it as a routine and run it again.
The more consequential feature is parallelism. Several bots can work at once, message each other and share context in a thread. The launch examples span sales research, CRM updates, invoice handling, bug reproduction and follow-up drafting. Those are vendor examples, not measured customer outcomes, but they show the intended category: an operational agent system rather than a response-only assistant.
One computer is the trust boundary
The product FAQ says every Grok Bot for a user shares one persistent cloud computer. Files, browser sessions and logins are shared across that user’s bots, while isolation is per user, not per bot. This makes hand-offs practical: one bot can leave an artefact or authenticated session for another without rebuilding the environment.
The same design concentrates risk. A login granted for one narrow job may be reachable by every bot on that computer. A malicious instruction in a webpage, email or document could be encountered by an agent that also holds access to unrelated systems. Deleting one chat should not be assumed to remove files, sessions, routines or memory from the shared machine.
Palmer’s walkthrough describes the computer as a persistent Linux virtual machine and says the desktop app can make local files available. Those implementation details come from his first-hand account rather than the shorter official release note, so teams should confirm the current architecture and data path before procurement.
Handoff, routines and memory
The launch materials describe four mechanisms that make the product feel continuous:
- Human handoff: a bot can return control when it reaches login, SSO, two-factor authentication, a CAPTCHA, payment or another judgement point.
- Routines: a user can demonstrate a workflow once, save it and run it on a schedule.
- Persistent context: bots remember conversations and working preferences across later tasks.
- Bot coordination: specialised bots can pass work and context to one another instead of routing every step through the user.
Palmer additionally describes user, agent and project memory; triggers from Slack, GitHub and schedules; secure forms for credentials; and access to Cursor plugins, connectors and skills. These are useful launch-day observations, but the public product pages do not yet provide a complete technical specification for every mechanism.
Access, pricing and published controls
The official launch note says the beta was available to SuperGrok Heavy, Cursor Ultra and Cursor Teams Premium subscribers on desktop and iOS. The product page listed Cursor Ultra at $200 a month and Cursor Premium Teams at $120 per seat a month, with Grok Bot included for existing SuperGrok Heavy subscribers. Enterprise users were directed to a future-access waitlist.
SpaceXAI says the cloud computer is encrypted in transit and at rest, offers a training opt-out and can route sensitive actions through Auto Review. It also advertises enterprise controls for data-loss prevention, certificates, proxies and network policy at boot. Those are relevant controls, but they do not establish that every consequential action is always reviewed or that every organisation’s retention, audit and residency requirements are met.
What the launch does not establish
The release materials do not publish a named underlying model checkpoint, an independent benchmark pack, a task-success distribution, an error budget or a complete approval-action taxonomy. They also do not answer every procurement question about memory retention, deletion across the persistent computer, audit-log export, incident notification, regional processing or recovery after a compromised session.
Treat claims such as “gets sharper over time” and “finishes jobs end to end” as product propositions to test, not service guarantees. A successful demo inside a prepared account does not measure variance, silent partial completion, reviewer effort or the effect of hostile content encountered during web and inbox work.
Run a bounded evaluation first
The UK NCSC’s May 2026 agentic-AI adoption guidance recommends incremental, low-risk pilots, least privilege, short-lived credentials, monitoring and incident planning. For Grok Bot, a credible 30-day gate should:
- use a dedicated test identity and synthetic or non-sensitive data;
- connect only the minimum accounts needed for one repetitive, reversible workflow;
- require approval for sending, purchasing, deleting, publishing and permission changes;
- seed emails, pages and files with indirect prompt-injection attempts;
- verify which files, sessions, memories and routines are visible to every bot;
- measure complete-task success, correction time, false completion and reviewer workload;
- exercise logout, credential revocation, memory deletion, machine reset and incident response; and
- compare the result with a simpler API workflow or ordinary automation.
The AI agent control-room guide explains how to separate proposing, approving and executing actions. The MCP permission-boundary analysis covers the connector and tool risks that remain even when the agent runs in an isolated computer.
AIEngine verdict
Grok Bot is one of the clearer attempts to turn computer-using agents into a persistent work product. Its shared machine, saved sessions, routines and bot-to-bot coordination remove setup friction that has limited earlier personal agents. That product integration is the release’s real significance; there is no launch evidence that a new model alone caused the experience.
The shared computer is also the control plane. Organisations should begin with low-risk work, narrow accounts and explicit approvals, then expand only when logs show that the system finishes accurately, contains hostile inputs and releases access cleanly. Early beta is an invitation to evaluate, not permission to give an always-on agent the same reach as an employee.
Primary sources
- SpaceXAI: Introducing Grok Bot, 11 August 2026
- SpaceXAI: Grok Bot product, access, pricing and FAQ
- Grok Bot official launch thread on X
- Matt Palmer: Intro to Grok Bot
- UK NCSC: Thinking carefully before adopting agentic AI
Image provenance
Hero image: SpaceXAI’s official Grok Bot launch artwork, downloaded from the release page and served locally as a WebP.



