Grok Bot Wants Your Passwords. Grok 4.6 Might Deserve Them.
xAI shipped Grok Bot on August 11: always-on AI teammates that sign into your apps with your own credentials and work while you sleep. Grok 4.6 followed a day later and put xAI on the intelligence frontier. We read the security docs xAI's marketing skips: every Bot you create shares one computer and every login on it, and one of the subscription tiers does not appear on the seller's own pricing page.
By T.W. Ghost
In 48 hours this week, xAI shipped both halves of an argument: the worker and the engine.
On August 11, Grok Bot launched in early beta: always-on AI teammates that live on a cloud computer, sign into your apps with your own credentials, and work through multi-step jobs while you are away. On August 12, Grok 4.6 followed, the model that put xAI on the intelligence frontier for the first time. Google answered on August 13 with a repriced agent engine of its own, which we cover separately.
The Grok Bot pitch is genuinely different from every other agent product on the market, and so is its trust model. We fact-checked the launch materials against xAI's own documentation, and the gap between the marketing page and the docs is the story.
What Grok Bot Actually Is
Grok Bot, in early beta for macOS, Windows, and iOS 18+, is not a chatbot and not a workflow builder. You create named Bots, message them like colleagues, and hand them jobs. Each Bot works on a persistent cloud computer with a browser, a filesystem, and a terminal. Bots keep memory and login sessions across conversations, learn tasks from screen recordings you make (capped at ten minutes), coordinate with each other, and run multi-step jobs end to end while you are away, surfacing only when something needs your approval.
The genuinely novel part is the credential model. Competing agents like ChatGPT Agent and Claude's tooling mostly reach your apps through APIs, OAuth scopes, or MCP connectors. Grok Bots sign into your actual accounts with your own usernames and passwords, which means they can operate the long tail of software that has no API at all. That is the pitch: xAI says Bots get work "100% done" and put the results in the tools where work actually lives, not in a chat transcript. The product reportedly grew out of an internal prototype that spread across xAI for sales outbound, marketing campaigns, office operations, and bug fixes.
It is a real architectural difference, not marketing. It is also the exact reason the next section exists.
The Fine Print: One Computer, Shared by Everything
xAI's marketing page says Bots come with "their own computer." xAI's documentation says something different, and we quote it directly: "All of your Bots use the same persistent cloud computer. The computer is isolated to your account, not to an individual Bot."
Every Bot you create shares one machine, one filesystem, one browser, and every login session on it. xAI's own docs warn, twice, on two separate pages: "Do not use separate Bots as a security boundary." The deletion docs add that because Bots share a computer, files and logins may remain after a Bot is deleted.
Think about what is on that machine after a month of real use: your email, your billing portals, your GitHub, your CRM, all with live authenticated sessions, attached to an agent that reads incoming messages and acts on them autonomously. That is a structurally attractive target for prompt injection, and an expensive one if anything goes wrong, because the agent is not sandboxed away from your accounts. The agent's whole value is that it is not sandboxed away from your accounts.
To be fair about what we did not find: no published incident, and no evidence of sloppiness beyond the marketing-vs-docs gap. But there is also no published detail on credential storage or session encryption, no way to scope a Bot to a subset of credentials, and no independent security audit anyone can point to. For a beta product asking for your passwords, "trust us" is the current documentation.
Our advice, which xAI's docs technically agree with: give it a dedicated account with the minimum access the job needs, and treat every credential you hand it as shared with every Bot you will ever create.
What It Costs, and the SKU That Does Not Exist
There is no standalone Grok Bot price. It is bundled into three subscriptions:
| Plan | Price | Note |
|---|---|---|
| SuperGrok Heavy | $300/mo list | A $99/mo six-month promo has run since May, so most current subscribers pay $99 |
| Cursor Ultra | $200/mo | Confirmed on both xAI's and Cursor's pages |
| Cursor Teams Premium | $120/seat/mo | xAI's figure. This SKU does not appear in Cursor's own pricing data, which lists Teams at $40/seat |
That third row deserves a beat. xAI's launch materials price "Cursor Teams Premium" at $120 per seat per month, and no such tier exists in Cursor's published pricing, which tops out its Teams plan at $40. Either a new SKU had not propagated to Cursor's site at launch, or the tier is effectively xAI-defined. We print it as xAI's claim, not Cursor's price. Usage is described only as a "weekly allowance" with an on-demand add-on; no token or task numbers are published. Enterprise access is waitlist-only.
One more thing xAI does not tell you: which model runs your Bots. There is no model picker. Requests route through what xAI calls a managed model set with automatic failover. Which brings us to the model that shipped the next day.
Grok 4.6: The Engine Arrives a Day Later
On August 12, xAI released Grok 4.6, making good on Musk's promised "later this week" rollout. This one is not a vendor-slideware story. Artificial Analysis put it at 61 on the Intelligence Index, tied with GPT-5.6 Sol, one point behind Claude Fable 5 (62), and two behind Claude Opus 5 (63). Five points over Grok 4.5, and the first time an xAI model has sat at the frontier tie rather than a tier below.
The economics are the sharper story. AA measured Grok 4.6 completing its Briefcase agent tasks in roughly 53 turns and 0.5B input tokens on average, against 103 turns and 2.0B input tokens for Claude Opus 5 at max reasoning, working out to about $0.84 per task. That is Kimi K3 cost with slightly higher measured intelligence, at API prices unchanged from 4.5: $2/$6 per million tokens, $0.50 cached input, doubling past 200K input tokens, 500K context, with a fast variant at twice the price. It is live in the API as grok-4.6, the default in Grok Build, day-one in Cursor, and on OpenRouter, Vercel, and Cloudflare.
xAI's own launch numbers (vendor-reported, labeled as such): CursorBench v3.2 69.9%, DeepSWE v1.1 65.9%, FrontierCode 61.3%, APEX-Agents 57.5%, and a notably weak Terminal-Bench v3.0 at 26%, well behind what GPT-5.6 posts there. Secondary reporting puts it at 1.5 trillion parameters on the same V9 foundation as 4.5 with an extended SFT and RL run; xAI has never published a parameter count, so treat that as reporting, not fact.
Note the near-photo-finish in the mid-tier agentic race this week: xAI reports 65.9% on DeepSWE v1.1, Google reports 65.3% for Gemini 3.7 Flash, and GPT-5.6 Terra leads both at 69.6%. Which vendor's harness you believe is doing a lot of work in those decimals.
The Corporate Chain, Now Complete
If you noticed launch coverage crediting these releases to "SpaceXAI" and assumed a typo: it is not. SpaceX acquired xAI outright on February 2, 2026. In May, Musk said xAI would cease to exist as a separate company, and in July the rebrand to SpaceXAI, the AI division of SpaceX, became official. The x.ai domain still works and the site footer still reads "X.AI LLC," but Artificial Analysis, VentureBeat, and 9to5Mac all now write SpaceXAI. So do we, with "formerly xAI" attached until it stops being confusing.
And the last domino: in June we covered SpaceX's $60 billion all-stock agreement to buy Anysphere, the maker of Cursor, expected to close in Q3 pending regulatory approval. It closed August 14, 2026, three days after Grok Bot launched and two days after Grok 4.6. Cursor is now a wholly owned SpaceX subsidiary inside the SpaceXAI division, which is why an xAI agent product ships bundled inside Cursor subscription tiers and why Grok 4.6 was the day-one default in Cursor. The neutrality question we raised in June, whether Cursor keeps routing fairly to Claude and GPT now that a model vendor owns it, is no longer hypothetical. Watch the defaults.
Verified vs Unconfirmed: The Scorecard
We adversarially fact-checked every load-bearing claim against primary sources before printing. The ledger:
| Claim | Verdict |
|---|---|
| Grok Bot: Aug 11 early beta on macOS, Windows, iOS 18+ | Verified (xAI announcement) |
| Bundled in SuperGrok Heavy, Cursor Ultra, Cursor Teams Premium; no standalone price | Verified (xAI announcement) |
| All of a user's Bots share one cloud computer and its logins | Verified (xAI docs, quoted verbatim) |
| "$120/seat Cursor Teams Premium" exists on Cursor's own pricing page | Not found (Cursor's data lists Teams at $40/seat; $120 is xAI's figure) |
| SuperGrok Heavy $300/mo list, $99/mo six-month promo since May | Verified (multiple trackers plus promo coverage) |
| Grok 4.6: Aug 12, AA 61 tie with GPT-5.6 Sol, ~$0.84 per Briefcase task | Verified (Artificial Analysis) |
| Grok 4.6 is 1.5T parameters on the V9 foundation | Unverified (secondary reporting; xAI publishes no parameter count) |
| Which model powers Grok Bot | Undisclosed (no model picker; managed model set) |
| Linux desktop support | Contradictory (docs said unavailable while a .deb installer appeared) |
| SpaceXAI rebrand official July 2026; Cursor deal closed Aug 14, 2026 | Verified (rebrand coverage; securities filing) |
Who Should Use What
Grok Bot is for early adopters who want an always-on assistant for real app-level work and are clear-eyed about the trade: it works because it holds your logins, and every Bot you create shares all of them. Dedicated low-privilege accounts only, nothing you cannot afford to have go sideways, and treat the beta label as load-bearing. If your agent needs are code-shaped rather than inbox-shaped, Grok Build vs Claude Code is the better comparison to read.
Grok 4.6 is for cost-conscious agentic work that needs frontier-tier intelligence. The measured per-task economics are the best at its level, and at $2/$6 it undercuts everything that matches it on the index. Terminal-heavy workloads should look at that 26% Terminal-Bench v3 number first.
Everyone else: the frontier still belongs to Claude Opus 5 (63) and Claude Fable 5 (62) for the hardest reasoning and deepest coding, Gemini 3.7 Flash owns the discount agent-engine slot until its sale ends December 31, and Kimi K3 holds the open-weights flag at 60. Our model comparison has the current standings side by side.
Sources
- xAI: Introducing Grok Bot
- xAI: Grok 4.6
- xAI docs: models and pricing
- Artificial Analysis: Grok 4.6 benchmarks and analysis
- Unite.AI: xAI launches Grok Bot
- Digital Applied: Grok Bot launch and security notes
- OpenRouter: Grok 4.6
- Forbes: SpaceX buys Cursor for $60 billion
*Not sure whether an always-on agent, a frontier-tie model, or a very different lab entirely fits how you actually work? Take the free 2-minute quiz and get matched. Then read the other half of this week's agent story: Gemini 3.7 Flash.*