The GenAI Field Guide · Trending
Persistent named agents that share one cloud computer with a browser, terminal and file system, sign in to your apps, and keep working after you close the laptop.
Grok Bot gives you a roster of named agents, each with its own role and memory, that work on a persistent cloud computer, sign in to your tools as you, and return for approval before consequential actions. Since 26 August it comes bundled with every paid Cursor plan and every SuperGrok tier, and since 28 September Team Bots let a whole team share one bot from Slack. Anyone whose staff already pay for Cursor now has an always-on agent in their organisation whether or not they planned for one, so its shared-computer security model is worth understanding now.
xAI launched Grok Bot as an early beta on 11 August 2026, describing bots as teammates that get their own computer in the cloud, sign in to the apps you use, and complete multi-step work end to end, including in tools that have no clean API or MCP server. The company now publishes as SpaceXAI: SpaceX merged with xAI earlier in 2026 and completed its purchase of Anysphere, the maker of Cursor, on 14 August, folding it into a SpaceXAI division. That ownership explains the product's shape. Grok Bot signs in with a Cursor account, its plans and billing page lives on Cursor's help site, and its security documentation says the computers run on Cursor-operated infrastructure.
Under the marketing, a bot is a long-running agent loop with a named identity, per-bot memory, saved skills and schedules, and computer-use tools on a durable virtual machine. xAI's own design write-up of 3 September frames the product around persistent agents with their own identity, memory, runtime and tools, kept on a roster you return to rather than throwaway chat sessions. You talk to bots by text or voice from desktop and mobile apps, and several bots can work in a group chat and hand tasks to one another.
Access widened fast. At launch, coverage and reviews reported it only on SuperGrok Heavy, Cursor Ultra and Cursor Teams Premium, on desktop and iOS. On 26 August SpaceXAI extended it to every SuperGrok, Cursor Pro and Cursor Teams plan, and on 28 September it opened Team Bots in public beta on Teams and Enterprise plans. Reviewers split along predictable lines: enthusiastic for non-technical users who have never had an agent that survives a closed laptop, more sceptical among engineers who can build the same thing with more control, and some who say they will not use it on grounds of trust in the company.
Every account gets one persistent cloud computer with a browser, a command line and a shared /workspace file system. The documentation is explicit that all of your bots use that same machine: browser cookies and signed-in sessions, files and command-line credentials are shared across bots, and each bot gets its own screen so several can work in parallel. Reviews describe it as a managed Linux virtual machine running the bot as a non-root user. You can watch a bot through a status indicator, a preview panel or a full-screen takeover, and you take over the screen yourself whenever a site wants a password, passkey, two-factor code, CAPTCHA or payment step, because bots hand those back rather than working around them.
A bot has no identity or credentials of its own; it acts as the signed-in member. Connector tokens stay on Cursor's backend rather than on the computer. Actions such as shell commands, plugin calls, computer use, automation writes and delegation pass through per-action approvals with allow once, always allow or deny, plus Auto Review, a separate review model that evaluates risky actions before they run. The documentation is candid that Auto Review does not review every side effect and that its prompt-injection defences, which also include marking outside content as untrusted and network policy, reduce but do not eliminate the risk. Enterprise admins can enforce Auto Review, set network allowlists, and turn on action recording and audit logs.
Learning happens through skills and routines. A skill is a saved set of instructions for a task: you can ask a bot to save a process you just did together, demonstrate a workflow for up to ten minutes, or install one from a marketplace. A routine runs a skill on a schedule or, through Cursor account integrations, on an event such as a Slack message or a GitHub notification, with up to 50 routines per bot. Memory belongs to each bot, so a sales bot and a data bot keep different context while skills are shared across your library. Team Bots extend this to a shared bot with shared plugins, credentials and skills, a Slack handle of its own, and separate private conversations and memories per user.
xAI's pages do not name the model behind Grok Bot. Secondary sources disagree: one review says it runs on the Grok 4.5 lineage, while an unofficial fan site and at least one hands-on review tie it to Grok 4.6, released alongside the Cursor deal closing. Treat the model as unconfirmed.
You need a paid Cursor plan (Pro, Pro+, Ultra or Teams) or a SuperGrok, SuperGrok Plus or SuperGrok Heavy subscription linked to a Cursor account; Cursor's plans page also lists X Premium+ through account linking, and Enterprise access goes through a Cursor account executive. Team Bots need a Teams or Enterprise plan. Legacy Privacy Mode in Cursor is not supported.