Three companies now sell the same idea: an agent with its own computer that keeps working after you close the tab. OpenAI launched Dots at DevDay on September 29, 2026. SpaceXAI shipped Grok Bot on August 11. Meta launched Muse on September 8-9. This post compares OpenAI Dots vs Grok Bot vs Meta Muse on the things that decide a purchase: plan gating, price, where credentials live, what each agent may do unattended, and what has already gone wrong.
We are using only what explainx.ai has already verified in the linked deep dives, plus each company's own launch language. Where a number is not published (extra Dots pricing, country lists), we say so instead of guessing.
TL;DR: OpenAI Dots vs Grok Bot vs Meta Muse
| Question | OpenAI Dots | SpaceXAI Grok Bot | Meta Muse |
|---|---|---|---|
| Launched | Sept 29, 2026 (DevDay) | Aug 11, 2026 (early beta) | Sept 8-9, 2026 |
| Model | GPT-6 Astra | Grok 4.6 era models | Muse Spark 1.3 |
| Who can use it | ChatGPT Pro and Business Premium in eligible markets; Enterprise/Edu/Healthcare via admin beta | SuperGrok Plus/Heavy, Cursor Pro+/Ultra/Teams, plus a limited free trial | US only at launch; iOS, Android, web, WhatsApp |
| Price | First dot included; extra dots unpriced | Bundled; reported ~$120 to $300 per month tiers | Free to 100M tokens/week; $20 and $100 plans |
| Where it runs | Own cloud computer and browser; optional laptop access | A Linux VM per member, shared by all your bots | Per-user Secure VM |
| Credentials | Saved for supported sites, hidden from the model | Bots sign in as you | Real secrets stay outside the agent; surrogate tokens |
| Unattended writes | Proactive research is read-only | Persistent bots act on connected tools | Human approval for checkout and data leaving the VM |
| Connectors | 4,000+ plugins | Tools you log into, Google Workspace, Amazon, DoorDash | Curated connectors, Instagram DMs, Plaid, Stripe Link |
| Public incidents | None yet (one day old) | Credential-scope criticism, shared-VM caveat | Marketplace address share, Mac zero-day, human concierge test |
What is each agent, in one paragraph?
Dots are OpenAI's always-on agents. Each dot gets its own cloud computer and browser, connects to 4,000+ apps, and can be inspected at any time. You talk to it in ChatGPT on desktop, web, and mobile, plus Slack and Teams, with texting promised. Read the full Dots breakdown for the permission language.
Grok Bot is SpaceXAI's pitch of "AI teammates that do real work for you. They sign in to your tools, use them just like you do, and come back with finished work." It grew out of the Cursor relationship covered in the SpaceX-Cursor close post, and it now has a marketplace with dozens of public bots.
Muse is Meta's consumer play. Mark Zuckerberg called it "the personal agent that understands your goals and works 24/7 to get things done for you." It hit #1 on the US App Store about a week after launch.
Who can actually use them, and what do they cost?
Access is the first filter, and it is where these products differ most.
| Plan situation | Best fit |
|---|---|
| You want to try an agent for free today | Muse (US only) or the Grok Bot limited free trial |
| You already pay for ChatGPT Pro or Business Premium | Dots, first dot included |
| You already pay for Cursor or SuperGrok | Grok Bot |
| You are outside the US | Check Dots' "eligible markets"; Muse is US-only at launch |
| You run an enterprise | Dots (admin beta) or Grok Bot (admin-panel activation live since Sept 3) |
Dots. OpenAI's rollout copy says the first dot is included at no extra cost, with an allowance for deeper work and extended limits in the first month. Later, more dots or more speed and monthly work. There is no public rate card for a fleet.
Grok Bot. Access widened from the original gated tiers to SuperGrok Plus, Cursor Pro+, and Cursor Teams, with a limited free trial for everyone else. Reported price points run from roughly $120 per seat per month on Cursor Premium Teams up to $300 per month on SuperGrok Heavy. SpaceXAI has not published standalone Grok Bot pricing, so treat those figures as bundle costs.
Muse. The most transparent pricing of the three: free up to 100M tokens per week, with $20 and $100 monthly plans. If you want to feel what an always-on agent does before spending anything, this is the cheapest experiment, provided you are in the US.
For a broader cost lens on the models behind these products, see the GPT-6.1 Sol pricing breakdown and our Grok 4.6 launch coverage.
Where do your credentials live?
This is the question that separates the three, and it matters more than any benchmark.
Dots save passwords for supported sites without exposing those secrets to the model. Password changes always stay with the user. The cloud computer is isolated unless you choose to connect your own laptop, which is a separate trust decision.
Muse goes furthest on architecture. Real OAuth tokens live in a per-user credential store outside the agent's sandbox. A separate process called Sentinel inserts the real credential at the network boundary, so a prompt-injected agent tries to leak a secret it never held. Meta pays up to $130,000 for a working prompt-injection exploit. The caveat from our deep dive: today, Meta itself can see Secure VM data, and a Confidential VM is promised later in 2026.
Grok Bot takes the plainest approach: the bot signs in as you. SpaceXAI's own documentation says all of a member's bots share one Linux VM, its logins, and its files, and warns "do not use separate Bots as a security boundary." That is honest, but it means a mistake in one bot's scope is a mistake in all of them.
If you have read our MCP security guide, the ranking follows the usual rule: the less an agent can directly hold, the smaller the blast radius when something is injected.
What can each agent do while you are away?
| Behavior | Dots | Grok Bot | Muse |
|---|---|---|---|
| Background research | Yes, read-only | Yes | Yes |
| Send messages unattended | Not in proactive research; acting work needs rules and review | Yes, through connected tools | Gated per connector by Sentinel (allow, deny, ask) |
| Purchases | Behind rules and review | Voice ordering via Amazon and DoorDash reported | Human approval on every checkout; single-use virtual cards for new merchants |
| Multiple workers | Future: more dots | Multiple bots, each callable by others | One agent |
Dots draws the sharpest line: proactive research cannot send messages, change app content, or control the browser or computer. Anything that acts sits behind Custom Rules, auto-review, and Activity View. That is the easiest consent sentence to explain to a security team.
Grok Bot is the most autonomous in practice. The engineering-org essay describes five specialized bots coordinating 200+ Cursor cloud agents, and the voice ordering update added errands to office work.
Muse sits in between, with kernel-enforced approvals on network egress rather than a research-only mode.
Here is the Grok Bot early-beta thread that started the "teammate" framing:
What has already gone wrong?
Track record is the part of this comparison you cannot get from a launch post.
Muse has the longest public record because it launched earliest among the consumer agents. Highlights:
- Meta's Muse shared a YouTuber's pickup address with a Marketplace buyer after he chose Allow Always, and told him only after the buyer left.
- Meta tested a human concierge on some Muse phone calls, rolled it back, and hot-fixed a Muse for Mac zero-day.
- Amazon blocked Muse from shopping on Amazon.com, citing undisclosed store access, no self-identification, and apparent credential capture.
- Our synthesized verdict, Is Meta's Muse safe?, flags the Instagram DMs plus Plaid combination as the highest-stakes grant.
Grok Bot has had scope and reliability criticism rather than a single headline incident. It is still labelled early beta, early users reported missed items on cleanup tasks, and a bulk email purge is the kind of action our real-world use cases post says to review before approving.
Dots has no incident record, and that is a statement about age, not quality. The launch demos did not all land on stage, but the product shipped. Wait for your tenant, run a read-only task, and inspect Activity View before you extend trust.
The pattern across all three: the failures are not model failures. They are consent failures, where an agent used a permission the user granted broadly and forgot about.
Which one should you pick?
Use this decision list rather than a leaderboard:
- You want a free, low-stakes trial in the US: start with Muse, and do not connect banking or DMs on day one.
- You live in ChatGPT and Slack already: Dots, because the first dot is included and background research is read-only.
- You build software and pay for Cursor: Grok Bot, especially if you want several coordinated bots. Keep them on revocable accounts.
- You need to pass a security review: Dots' rules (read-only research, hidden passwords) or Muse's Sentinel design are the easiest to defend. Grok Bot's shared-VM caveat needs an explicit exception.
- You want to avoid lock-in: treat the agent as a replaceable worker. Keep instructions in portable files like agent skills so you can move between them.
If your real need is unattended coding rather than a personal assistant, none of these replaces Codex persistent mode or a proper loop-engineering setup.
Questions people are asking
Is Dots just Muse or Grok Bot from OpenAI?
The shape is the same: persistent identity, a computer, connectors. The differences are in the rules. Dots publishes a read-only background mode and a hidden-password vault; Grok Bot publishes a shared-VM warning; Muse publishes a broker architecture and a bug bounty. Those are three different consent sentences. See the OpenAI leak fact-check for how the product got its name.
Did OpenAI ship the rumored Aeon?
The Aeon codename surfaced in pre-launch reporting and Codex code strings. OpenAI announced Dots, not Aeon, at DevDay. Treat Aeon as a leaked internal name.
Does chatting with the agent count against my plan?
For Dots, conversation with your dot does not count toward ChatGPT usage limits, but Codex and ChatGPT Work tasks it starts do. Grok Bot users reported hitting usage limits on day one of the wider rollout. Muse meters by tokens per week.
Can I run all three?
Yes. Give each one a different, revocable set of accounts, and never attach the same primary inbox, bank link, and password manager to more than one.
Here is the Dots demo moment people clipped from DevDay:
Honest limitations of this comparison
- Dots is one day old. No independent testing, no incident history, no country list, and no extra-dot prices.
- Grok Bot price figures are reported tiers, not a published standalone rate.
- Muse is US-only, and its App Store rank and ratings are self-reported.
- Architecture claims are vendor claims. Sentinel, the Dots password vault, and Grok Bot's VM model have not had a public independent audit that we can cite.
- This market moves weekly. Plans, limits, and incidents will change before this post does.
What to do this week
- Pick one agent that fits a plan you already pay for. Do not buy a new subscription just to compare.
- Give it a research-only goal first, and open the activity or trajectory view.
- Connect one low-stakes account. Skip banking, DMs, and your primary email.
- Write rules the way you write a CLAUDE.md: what it may read, what it must ask, what it must never send.
- Revisit in a week and only then widen scope.
Follow @explainx_ai for updates as the admin docs and incident reports fill in.
Related reading
- OpenAI Dots: always-on GPT-6 Astra agents
- OpenAI DevDay 2026 full recap
- Grok Bot early beta: agents that log into your tools
- Grok Bot real-world use cases
- Grok Bot Marketplace
- Meta Muse launch and Sentinel architecture
- Is Meta's Muse safe? The honest answer
- MCP security guide 2026
Official: Introducing Dots · Muse
Plans, prices, and incident details are accurate as of September 30, 2026. Extra-dot prices, Dots country eligibility, and standalone Grok Bot pricing were not published at the time of writing.
