Skip to content
All articles
AI & Models9 min read

Grok Bot Is What Demand for Intelligence Looks Like

Mikey & Colin

Co-Founders

SpaceXAI put Grok Bot into beta on August 11. You give it a job, it gets a Linux machine in the cloud, and it keeps working after you close the laptop. Browser, filesystem, terminal, the usual. Two weeks later they rolled it onto SuperGrok, Cursor Pro, and Cursor Teams. They’re still calling it early beta.

A Bot is just a named agent that sticks around. You talk to it from a desktop app or an iPhone the way you’d text a coworker. It’ll use a connector if one exists, and if there isn’t one it’ll click through the website itself. The idea is that the email actually sends, the ticket actually files, and you don’t get stuck with a pretty draft in the chat window.

Roman, who works on product at SpaceXAI, said this in the launch post:

There is a huge difference between 90% done and 100% done. Most AI gets you almost there. Grok Bot can finish the swing, because the work lands where a human would put it, in the actual tool.

Roman, Product, SpaceXAI

You can run a few of them at once and throw them in a group chat. Internally they keep describing a chief of staff sitting on top of specialists, which is the version of this that sounds like an org chart. You can also walk a Bot through a workflow once, save it as a routine, and have it run later. All of a user’s Bots share one computer, including files, browser sessions, and logins. The docs say that out loud: separate Bots are not a security boundary.

The names are a mess, so once: this isn’t the Grok chatbot on X, and it isn’t Grok Build, the coding agent. The Verge put it next to ChatGPT Work, Claude Cowork, and Copilot Tasks. Cursor’s blog, now that the company’s part of SpaceX, said they’d gone “from completing the next few lines of code to building AI teammates that you can give real work to.” VentureBeat had the deal at $60 billion. Grok Bot is the first product where that sentence starts to mean something.

Rachitsky, Shumer, and the HN thread

The Verge, VentureBeat, Digital Trends, 9to5Mac, and Unite.AI all wrote it up within a day or two, mostly repeating the announcement: always-on agents, own computer, bundled into premium plans, enterprise on a waitlist. The argument showed up on Hacker News. The thread on x.ai/bot hit 351 points and a bit over 330 comments in a few hours. A second one filled up with product curiosity and Elon politics, in the usual proportions.

Half the comments are about whether a persistent VM and a messaging UI is actually how people will run agents. The other half are about not wanting Elon Musk’s company signed into their SaaS stack. Both of those are real. The comments we kept coming back to were from people who’d used it.

Lenny Rachitsky got in early and said he hadn’t been this excited about a new AI product in a while:

It’s like OpenClaw, but super easy, reliable, and less scary to use. I think this will be a huge new product line for Cursor/Grok/SpaceX.

Lenny Rachitsky, quoted in VentureBeat

Matt Shumer had been on it for a few weeks before launch. He called it “an agent for everything, not just code,” stood up a researcher, a writer, and a chief of staff, told the third to coordinate the other two, and figured it would fall over. “It worked out of the box.” What bothered him was that you don’t pick the model. The router does that on the backend, and he didn’t like the router.

We wrote about OpenClaw and Hermes earlier this summer. Those harnesses let you point the same scaffolding at Claude, GPT, Gemini, DeepSeek, or a local Llama. Grok Bot points it at SpaceXAI. That’s the deal: you get something a non-engineer can stand up in a group chat, and the memory, the logins, and the computer live on their side of the glass.

Then there’s the security stuff, which came up immediately and should have. The Verge’s version was one line: you have to be fine with letting Grok sign into your accounts. HN was less polite. Prompt injection, session hijacking, the fact that the log on the far end says it was you. One comment:

By hijacking a real person’s credentials, that person becomes the accountability sink. Very neat. Very deliberate.

Hacker News

SpaceXAI doesn’t hide the shared-computer model, and they’re unusually straight about the audit view of Bot actions still being on the way. Competitor writeups have been going after the missing dry run, the missing certifications, and the uncapped token meter. They’re selling something else. The gaps they’re pointing at are still in the official docs.

Forty suppliers in Vietnam

Publicly, the named users are SpaceXAI, a handful of well-known testers, and power users on Cursor and SuperGrok plans. Enterprise is on a waitlist. Nobody independent and of any real scale has gone on the record running production work through this. It’s eighteen days old as of this writing, and it spent the first two of those behind the most expensive seats, so that tracks.

They did publish how they use it internally, which is the closest thing we have to a customer story. Sales Bots research accounts overnight, score contacts, draft outreach in each seller’s voice, and leave a pile of emails to approve. Ops Bots seat new hires and process invoices that land in Gmail. Engineering Bots reproduce bugs in the product UI, file tickets, and hand the fix to a debugging Bot. A demo Bot checks the environment overnight and drops a checklist before morning calls. That’s junior-hire work, or a slice of an operator’s day, which is why the money conversation is about seats and meters instead of chat quotas.

The best outside example we found was a Hacker News user, jjcm, who’d been on it about a month. One Bot reached out to something like forty fabric suppliers in Vietnam, negotiated, locked a vendor, and got samples made, working with another Bot that generated a pattern file.

The replies under that comment are the part that stuck. Someone asked what happens when fifty people, then five thousand, then five million fire off a “get me a shirt” prompt. Someone else said the suppliers will have to use AI to filter the inbound. A third pointed out that job ads are already flooded with LLM-generated applicants. “Everything is becoming wildly inefficient, all in the name of improved efficiency.”

If a Bot can work WhatsApp, a CRM, and a supplier portal, starting work gets very cheap. Handling it on the other end doesn’t, at least until that side has an agent too. Then you get two meters pointed at each other, and the companies selling tokens collect on the round trip.

They’re already widening access. On August 26, SpaceXAI said Grok Bot comes with all SuperGrok plans, Cursor Pro, and all Cursor Teams plans, with its own usage so Bot work doesn’t chew through the parent subscription. Putting the agent inside plans people already pay for is a lot cheaper than trying to sell a new seat. It’ll also fill the beta with the people most likely to run up a token bill.

jjcm’s invoice

Same thread, same user:

I’ve used more tokens this month than not this month. That’s not a typo. I’ve used less tokens in the last 5 years prior to this month than I have this month. Always on perpetual agents use a LOT of tokens. IMO this is building for the future state where tokens are vastly cheaper.

jjcm, Hacker News

A chat session is a burst. You ask, you get an answer, the meter stops. An agent with a computer, a calendar, and a login is a process. It researches overnight. It pings the vendor who didn’t reply. It watches the inbox. It coordinates with three other Bots. Work that used to be gated by whether a person had the hours is now gated by tokens, and tokens are still expensive enough that another commenter called the serious users “token insensitive.”

We’ve seen a version of this already. DeepSeek, then Kimi K3, showed that a unit of model intelligence could get cheaper faster than the closed labs wanted. People didn’t use less of it. They pointed it at jobs nobody had bothered automating, mostly because the setup was a pain and there was no API.

That’s the setup cost Grok Bot is going after. You don’t need a workflow builder or an MCP server. You show it once and you message it like iMessage. Open-source harnesses already did this for people willing to run a daemon and keep memory in Markdown files. Grok Bot does it with a consumer UI, a cloud VM, and a credit card. Rachitsky reaching for OpenClaw makes sense, and the “less scary” bit is doing a lot of work. People wanted intelligence that could sit in the tools they already use, without a six-figure integration.

Monthly active users is going to be the wrong chart if this holds. What you actually want is tokens per running agent, times agents per person, times how many hours a day you’re willing to let it work. “Included” with Cursor Pro can still produce a bill that makes finance sit up. The version of Grok Bot that’s interesting is the one that never sleeps.

The model still matters. Grok 4.6 shipped into the same week, with a stated focus on long-running agents. What will decide this category, though, is identity, approvals, audit, and prompt injection. A draft that’s right 90 percent of the time is a useful intern. Sending, paying, deleting, or negotiating at that rate is a problem with a login. SpaceXAI is selling the second thing while the controls are still listed as coming, which is what “early beta” is supposed to mean, and why enterprises are on a waitlist.

The other side of the market has to catch up. If one person can spin up a Bot that emails forty suppliers, those suppliers need a way to tell a real request from a token-funded fishing expedition. If every job posting attracts a thousand generated applicants, hiring has to move off the resume. Some of that’s already happening. MCP was an attempt to give agents a real interface. Grok Bot just logging into the website is a bet that computer use can cover for the protocol layer until one exists.

What has to get cheaper

Cursor’s post about joining SpaceX is really a compute story: the largest GPU fleet, models that are cheaper to run, intelligence scaled “far beyond what exists today.” Grok Bot is the thing that makes that capacity useful. If tokens keep falling the way inference pricing has for two years, perpetual agents stop being a hobby for people on Ultra plans. If they don’t, you’re left with a very good demo and a bill that scares people off. The internal prototype that “took off across the company” only works in one of those worlds.

Hermes and OpenClaw already give a developer a local-first agent that remembers, acts on a schedule, and can swap models when prices move. Grok Bot’s pitch is that a non-engineer can stand it up in a group chat. The trade is everything living on SpaceXAI’s side, on a machine shared across every Bot you create, with no published SOC 2 of its own and an audit view that hasn’t shipped. Some companies will keep the agent in a harness they own. Others will take the teammate that texts like iMessage. It’ll look a lot like the old cloud versus on-prem split, except the payload is the company’s working memory.

It’s a beta. The named customers are mostly the company that built it. Identity, approval, and a record of what happened are still on the roadmap. The people already on it are finding out they’ll buy as much of this as the meter, and their nerve, will allow.

Mentioned in this piece

  • AI & Models8 min read

    Why AI Needs Open Models

    Open-source AI gives startups, developers and businesses an alternative to relying entirely on a small group of closed model providers. Restricting access to open models could reduce competition, increase costs and limit how companies build and deploy AI, while doing little to stop the technology from advancing elsewhere. That matters even more as the model itself becomes just one component of a larger system that increasingly determines how useful an AI product actually is.

  • The Kimi logo — a rounded black tile holding a white K with a blue dot, beside the KIMI wordmark in white.
    AI & Models4 min read

    Kimi K3

    DeepSeek showed that frontier-level intelligence could be built and served far more efficiently than the market expected. Kimi K3 takes that disruption further by combining competitive performance with open weights, giving developers and enterprises more control over how models are hosted, customized and deployed. The right response is not to restrict access, but to build stronger open alternatives and compete in a model market that is becoming cheaper, more open and far less defensible.

  • AI 2040
    AI & Models7 min read

    AI 2040

    "AI 2040: Plan A" proposes a radical blueprint to prevent a reckless global race to superintelligence through full research transparency and enforceable U.S.–China cooperation. By pausing AI capability growth at human-expert levels until 2040 using "mutually assured compute destruction," the plan ai

VE Weekly

The week in tech, AI and early-stage capital.

One send a week. Whole pieces, not a digest of links out.

One email a week. Unsubscribe in one click. Your address is never shared.