
Grok Bot is xAI's agent product: persistent teammates that each get their own cloud computer and work inside your apps, even when your laptop is closed. This week's upgrades center on "bring any model, one subscription" routing, a Primary Bot that delegates to specialist bots, and approval drafts that let you edit or kill a message before it sends. The catch is that the agent is logged in as you, so start with approvals on and narrow permissions.
What changed this week
Grok Bot launched in beta on August 11, 2026, according to xAI's launch post. It is included with SuperGrok ($30 a month and up), Cursor Pro ($20 and up) and Cursor Teams ($40 to $120 per seat), on desktop and iOS as of the publishing of this post. xAI doesn't charge for Grok Bot separately; you get it through those plans.
Four tracked creators covered the latest wave: Riley Brown, Alex Finn, Nate Herk and Pat Simmons, with roughly 257K views between them. The shift they describe is from chatbot to execution engine. Instead of answering a question, the bot runs multi-step work across your apps on its own cloud machine.
Model routing: the headline feature
On X, @Layton_Gott put the pitch this way: "Grok Bot isn't even really Grok Bot anymore lol. because if Claude, Midjourney, Suno, or anyone else is better for the job... Grok Bot will just use them."
Per the creators' videos, the Primary Bot reads each prompt and sends it to a fitting model. Hard reasoning goes to Claude Opus 5.5, images to Midjourney, audio to Suno, and quick text to a lighter Grok model. Some creators also say it factors in current API costs in real time. That detail is unverified, and none of the routing has been confirmed in an xAI announcement, so treat it as reported behavior.
The practical lesson is to split big multi-step skills into small ones. Routing happens per prompt, so a research step can run on a cheap model while only the reasoning step needs a frontier one.
Inline drafts: the approval gate
Before the bot sends an email or Slack message, it can show a mini-app card in the chat: a small Gmail or Slack window where you edit the wording or discard the draft. The reporting we reviewed says this brake applies to final actions. Reading data and intermediate steps reportedly ask for no confirmation, which matters for the next section.
The catches
Your bot is logged in as you. Pasquale Pillitteri notes the agent is already signed into your inbox, CRM and billing. Hidden instructions in a web page, ticket or PDF could try to trigger actions. A May 2026 Giskard write-up on a separate Grok and Bankr trading setup, where a morse-code message led to a $150K crypto transfer (about 80% was returned), is the same failure class: excessive agency plus prompt injection. It was not Grok Bot itself.
Personal bots share one cloud computer. Per the creators, different bot names are not different security boundaries. A file you leave for the marketing bot can be read by the finance bot. Treat it like a shared office desk.
Bot email addresses. Creators say a bot can claim its own address through a plugin like Agent Mail or a feature that is rolling out, then sign up for tools and newsletters. We could not confirm this in primary documentation, so verify it on your account before building a workflow on it.
Route traffic through your computer. A setting sends the bot's web traffic through your own IP address so retail sites are less likely to block it as a cloud bot. It works, but it also ties the bot's behavior to your home or office network.
Unpublished weekly limits. Proactive features run against usage limits from a separate weekly allowance, not published. A long project can hit a wall mid-run. Call Missed also flags that long multi-step runs and large prompts can raise token spend.
Two prompts to start with
Morning: "What approvals do you need from me right now?" The Primary Bot scans connected apps and surfaces pending drafts.
Night: "What can you work on for the next 8 hours that pushes us closer to our goals?" This puts the cloud computer to work while you sleep.
A safe setup for a one-person business
Give each bot a dedicated service account, not your main login.
Grant narrow write permissions and add more only when a bot earns it.
Require approval for anything outbound or irreversible.
Keep audit logs and review them weekly.
Treat every page, ticket and PDF the bot reads as potentially hostile.
FAQ
What is Grok Bot?
Grok Bot is xAI's agent product. Each bot is a persistent teammate with its own cloud computer that works inside your apps. It is separate from the @grok chatbot on X.
Can Grok Bot use Claude and Midjourney?
Creators covering this week's upgrades say the Primary Bot routes tasks to models such as Claude Opus 5.5 and Midjourney. xAI has not confirmed this in an official announcement that we found.
Is Grok Bot safe to connect to my business email?
Only with guardrails. The bot acts with your access, and reading steps may not ask for confirmation. Use a dedicated account, narrow permissions, approvals on outbound actions and audit logs.
What does Grok Bot cost?
Grok Bot has no standalone price. It's included with SuperGrok ($30 a month, up to Heavy at $300), Cursor Pro ($20, up to Ultra at $200), and Cursor Teams ($40 Standard or $120 Premium per seat per month) as of the publishing of this post. It has its own weekly usage allowance, separate from your plan's usage, and xAI hasn't published its size.
Watch the episode:
Want more breakdowns like this? Get the free playbooks at joebuildsai.com.
