SpaceXAI's Grok Bot ran agents on one cloud machine, sharing a single credential pool. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
The Agent Stack mascot
The Agent Stack _
Daily B2B AI automation brief · Tuesday, August 18, 2026 · Issue #67

Hey there 👋

I went into SpaceXAI's Grok Bot announcement expecting a demo reel and came out stuck on one sentence in the docs. It tells you not to treat two of your bots as a security boundary, because they share the same cloud computer and the same saved passwords. That is the whole week in one line. For three days the news was about agents attacking each other and escaping their sandboxes. This week the vendors answered by shipping the machinery to run these things at work: a body, a login, an ID badge, a browser, a background check.

So the story quietly flipped. You are not picking a model anymore. You are hiring a worker and deciding how much of the building it gets keys to. Let's get into what shipped.

— Ron


The Big Thing

Grok Bot gives your agent a desk, and buries the catch in the fine print

SpaceXAI (the company formerly called xAI), working with Cursor, opened Grok Bot on August 11: persistent agents that live on a cloud computer with a full operating system, a browser, and stored credentials. They keep their login state, files, and context between tasks, so they behave less like a chat window and more like a coworker who was already logged in when you got to your desk.

The design choice worth your attention is computer use. Grok Bot drives app interfaces the way a person does, clicking and typing through the UI, so it works inside tools that never shipped an API or an MCP endpoint. It keeps running after you close your laptop, coordinates with other bots in group chats, and can learn a repeatable workflow from a single demonstration. It is out on desktop and iOS in early beta, and it is gated behind premium tiers: about $120 per seat on Cursor Teams Premium, $200 on Cursor Ultra, and $300 on SuperGrok Heavy, with an enterprise waitlist.

Here is the part I would slow down on before you provision anyone. Every bot you spin up shares one cloud computer, one set of browser sessions, and one credential pool. SpaceXAI's own documentation warns you not to treat separate bots as a security boundary. The tidy mental model of a fleet of isolated workers, each with its own access, is not what you are buying. You are buying one machine wearing several name tags. Give one bot your production admin password and you have effectively given it to all of them.

Ship it? Watch, do not deploy to prod. The persistent-coworker pattern is real, and it is the most usable version of it I have seen. But the shared-credential model runs straight into everything last week taught us about agents on shared state. Pilot it on one low-stakes workflow with throwaway logins and read-only scopes, watch the logs, and keep it away from anything you would not hand a brand-new contractor on day one.

Sources: x.ai, VentureBeat, TechTimes


Tour de Headlines

🧠 Google shipped Gemini 3.7 Flash, and started a clock on the price. Google's new workhorse model for coding and agents landed August 13 with a 1M-token context window and DeepSWE scores well above 3.6 Flash (65.3% vs 49.0%, on Google's own eval). It is live in AI Studio, Android Studio, Antigravity, the Gemini Enterprise Agent Platform, and Gemini Spark. Intro pricing is $0.75 per million input tokens and $3.75 output, roughly half the old Flash. Read the calendar, though: those rates double to $1.50 and $7.50 on January 1, 2027. Cheap now, market-rate soon. 9to5Google

📡 6sense wired live buying intent into any agent. Its new MCP Server makes account insights, predicted buying stages, qualified-account status, and keyword intent callable from Claude, ChatGPT, Writer, or Agentforce with no custom integration. Your RevOps agent stops acting on a spreadsheet you exported last Tuesday and starts reading the same signals your analysts do. It has been in open beta since July 14, with general availability slated for this month. The quoted deal-value lifts come from 6sense measuring its predictive customer base, so treat them as directional. 6sense

🪪 Gemini handed every agent an ID badge. Quieter, and the direct reply to last week's security mess: Google's Agent Identity hit general availability in late July, giving each agent a strongly attested, SPIFFE-based cryptographic identity instead of a shared service account. Each agent moves only inside the permissions granted to its own ID, and every action is logged against it. It ships alongside Agent Runtime (tasks up to seven days) and a long-term memory bank. If Grok Bot is the cautionary tale about shared credentials, this is the boring fix. Google Cloud only. Infosecurity


Sponsor

You are instrumenting the agents. Who is instrumenting the reps?

This whole issue is about giving every agent a scoped identity, a log, and a grade before you trust it. One thing on your team still runs entirely on humans with none of that scrutiny: how your reps really show up on a live call. RapportScore measures how people communicate in their own recorded conversations and coaches them on it. It scores behavior in the call, and it is honest about its edges: it does not claim to read intent or honesty, and it flags when the signal is thin instead of guessing to fill the gap. If you instrument your agents but never instrument your reps, that is the blind spot worth closing.

See your team’s score →

Tool of the Day

🪁 Cloudflare Kitesurf

The browser your agent works in, rebuilt for a reader that isn't human.

Every UI-driving agent needs a browser, and stacking Chromium in a container for each one is how your bill quietly triples. Cloudflare's Kitesurf, out August 7, is a headless browser written in Rust, compiled to WebAssembly, running inside the same V8 isolates that power Workers. It throws out the rendering layer no agent looks at: a machine-readable DOM flows in, structured data flows out, and it uses 3 to 7 times less CPU and memory than Chromium. It already passes more than 215,000 Web Platform Tests and speaks Puppeteer, Playwright, and MCP over CDP, so your existing automation mostly just points at it.

The honest tradeoff, which Cloudflare states up front: wall-clock time runs about 1.7 times slower than Chromium, because you are trading raw speed for a fraction of the footprint. For a fleet of agents doing steady, parallel web work, that math usually wins. It is free in beta through Browser Run, with an open-source release on the roadmap. Try it on one flaky Playwright job that keeps blowing your memory budget.

Read the Kitesurf writeup →


Worth a Click

  • 🌐 A cheap agentic model that isn't from the usual four. Upstage Solar Pro 4 is the only Korean model listed on Nous Research's Hermes Agent and on OpenRouter, with a 524K context window and a 42 on Artificial Analysis' Intelligence Index (above NVIDIA's Nemotron 3 Ultra and Google's 3.5 Flash-Lite). A 90% promo runs it at $0.30 in and $1.20 out through September 10. A real option for your routing table on long, document-heavy jobs.
  • 🔎 Run a background check on your agent, free. Insygna's Agent Report Card lets you connect your agent repository and get a security score across six dimensions, a findings list with version history, and a verified badge, all before you grant access to real systems. The free tier is the on-ramp to their paid platform, but the pre-deploy score costs you nothing and answers "is this thing safe to wire up?" with more than a shrug.
  • ♟️ The incumbents are shipping agents into the product you compete with. A roundup of the SaaSpocalypse response has Salesforce's Agentforce running CRM tasks in a user's place and Atlassian embedding an agent into its collaboration tools. If you sell workflow software, parity with a native agent is a losing race. Differentiate on governance, vertical depth, or a data moat instead.

Delight

The first "AI agent that runs your whole business" did not show up at a Fortune 500. It showed up at your local insurance office. SUPERAGENT 3.0 opened public self-signup on August 11 as an AI "business partner" for insurance agencies: it unifies inbound and outbound calling, campaigns, quoting capture, call intelligence, and producer training, and it provisions a phone number on the spot. Plans start around $499 a month. Read the fine print and it is very good calling-and-quoting automation with a chat onboarding flow, not the autonomous company the name promises. Still, the autonomous business is arriving one boring back office at a time, and honestly that is where it belongs.


The bottom line, for real this time: every launch this week points the same direction. Grok Bot gives the agent a machine and a login, Gemini 3.7 Flash gives it a cheaper brain, 6sense puts real data in its hands, Agent Identity stamps it with a badge and a permission scope, Kitesurf is the browser it works in, and Insygna is the pre-hire screen. The center of gravity moved off "which model" and onto "how do I onboard, credential, and supervise a non-human employee." So run the play you already know: scoped identity, least-privilege access, a probation period on a low-stakes task, and a log of everything it touched. Hire the agent like you would hire a person you cannot yet vouch for.

See you tomorrow,
— Ron

You’re receiving this because you subscribed to The Agent Stack. · Manage subscription