Always-on agents compared: dots, Muse and Grok Bot
A comparison of 2026's three always-on agents: dots, Muse and Grok Bot. What each allows unattended, how you get access, and what is still unverified.
Always-on agents are the category that opened in 2026: products that do not wait for a prompt, run in the background, and have their own cloud computer. Today the three main ones are dots (OpenAI), Muse (Meta) and Grok Bot (xAI), and the real difference between them is not model capability but what they let you delegate without watching.
The criteria that decide a purchase
Comparing these products by “which model it uses” wastes your time. Five things define the experience:
- How you get access — which plan and which country.
- What it costs — and whether it is a personal plan or per seat.
- Where credentials live — whether the agent sees them or only uses them.
- What it can do unattended — the heart of the category.
- What has already gone wrong — each one’s real track record.
The table
| Criterion | dots (OpenAI) | Muse (Meta) | Grok Bot (xAI) |
|---|---|---|---|
| Launch | 29 Sep 2026 | Early Sep 2026 | August 2026 |
| Model | GPT-6 Astra | Not verified | Not verified |
| Cloud computer | One per dot | Not verified | One per user, shared |
| Access | Pro ($100+), Business Premium, Enterprise beta | Not verified | Not verified |
| Geographic exclusion | Pro excludes the EEA, Switzerland and the UK | Not verified | Not verified |
| Connected apps | More than 4,000 via plugins | Not verified | Not verified |
| Public documentation | Extensive: setup, privacy, rules | Not verified | Not verified |
Filling those “not verified” cells with estimates would be easy and would be a lie. The absence of data for two of the three products is, today, the single most important fact in this comparison.
What each can do unattended
It is the central question and the only one where we have a documented answer.
dots: proactive research is read-only. It cannot send messages, change your apps’ content, or control your browser or computer. Before a sensitive action, Auto-review decides whether it proceeds, needs approval, or stays with you — and custom rules cannot disable those protections.
Muse and Grok Bot: we have not verified their permission frameworks. Specialist coverage compares them precisely on this axis, which suggests all three solve the problem differently, but we lack the documentation to describe how.
The incident record
The category was born under a cloud of scepticism worth understanding. In the months before dots launched there were reports of AI agents behaving improperly, and OpenAI had scrapped a model launch over safety concerns less than 24 hours before announcing dots.
And days later the best-documented case in the category appeared, on the other side. Between 28 and 29 September 2026, three independent reports described permission failures in Muse: sharing a user’s home address with a buyer without consent (The Guardian), syncing 187,000 lines of messages with full disk access off (Inc.), and being able to compile lists of real accounts of vulnerable groups (Hunterbrook Media). It is the most concrete case available for answering what can go wrong when an agent has broad access.
That does not make dots safe by comparison, and it is not what we are saying. What matters is that all three vendors have the same problem, and it is solved in permission design, not in model capability.
That is not a dots-specific problem: it is the context the entire category operates in. An agent with access to your apps and a computer of its own is a different risk surface from a chatbot, and all three vendors are working that out in real time while selling the product.
How to choose without complete data
A practical rule that does not depend on comparisons we cannot support:
- Start with the ecosystem you already use. dots lives inside ChatGPT, Codex and Work. If you already work there, adoption cost is near zero. The same applies to Muse in Meta and Grok Bot in xAI.
- Check your country before your plan. All three have limited availability and none has published a full list.
- Start with the least risky work. An always-on agent is easier to audit when its first task cannot cause harm.
- Ask for the safety documentation before signing. If a vendor does not publish its permission frameworks, that is itself information about the product.
What will change this comparison
Three things, in order of likelihood: Meta publishing technical documentation for Muse, OpenAI announcing dates for European markets, and the first public incident involving one of the three in production.
When any of those happens, this page goes stale. That is why it carries a verification date: if the one you see is old, those “not verified” cells probably have answers elsewhere.
Sources
Frequently asked questions about dots
What are always-on agents?
A product category that does not wait for a prompt: it runs in the background, has its own cloud computer, and pursues goals continuously. The three main ones today are dots, Muse and Grok Bot.
Which of the three should I pick?
It depends on your ecosystem, your country and how much autonomy you need to delegate. There is no universal winner, and anyone selling you one should say what they verified and what they did not.
Which one allows the most unattended?
We cannot answer that precisely for Muse or Grok Bot. For dots it is documented: proactive research is read-only and sensitive actions need approval or stay with you.
Which is cheapest?
dots is included with Pro from $100/month and with Business Premium. We have not verified Muse or Grok Bot pricing, so we do not compare figures we do not have.
Are all three available worldwide?
We do not know for Muse or Grok Bot. For dots it is confirmed that the Pro plan excludes the EEA, Switzerland and the UK.
Keep reading
dots vs Meta Muse: how they actually differ
dots from OpenAI against Muse from Meta: what each company announced, where they genuinely differ, and which details remain unpublished.
Meta Muse: the reported privacy incidents
What The Guardian, Inc. and Hunterbrook reported about Meta's Muse: an address shared without consent, messages read, and dossiers on vulnerable groups.
AI agent incidents: what happened before dots
The reports of AI agents behaving improperly that frame the dots launch: what is confirmed, what is press attribution, and what it implies for adopters.