Almost every small business owner I talk to describes the same wish. They want the recurring work to just happen, without anyone having to remember to do it.
On Tuesday, xAI launched a product built for exactly that wish. Grok Bot gives you AI agents with their own cloud computer. They sign into the software you already use, work through multi-step jobs overnight, and come back to you when something needs a decision. There's no integration project and no developer involved.
Then I read the documentation. One page states that all of your bots share a single cloud computer tied to your account. Another says plainly: "Do not use separate Bots as a security boundary."
None of that makes Grok Bot a bad product. It does put a question in front of you that's easy to wave past when a tool looks this useful. What is this thing allowed to touch? This week, how to answer that before you type a password.
───
🗞️ THIS WEEK IN AI
1. xAI launched AI agents that log into your software for you
On August 11, xAI released Grok Bot in early beta. The agents get their own cloud computer, sign into tools that have no clean integration available, and run multi-step jobs on their own, returning only when something needs approval. They learn a workflow by watching you do it once.
Why this matters: The barrier to automating a task used to be technical. Now the barrier is judgment about access. Worth reading the security page before the marketing page, and I've broken down what I found below.
2. Free ChatGPT accounts now get unlimited text chats
On August 6, OpenAI made GPT-5.6 Luna the default for Free and Go users, with unlimited text conversations and a "Think" button that gives it more time on harder questions. Limits still apply to file uploads, images, and other tools.
Why this matters: A message cap in the middle of a task is a good way to lose someone before the tool ever proves itself. That barrier is gone on the free plan. If you have an employee who's been curious but not curious enough to pay, this is the week to point them at it.
3. Claude's outage record is a reminder to keep a backup plan
Anthropic had a rough first week of August, including a 7.5 hour disruption on August 5 that affected several Claude models at once. The tracking site StatusGator has logged 164 Claude disruptions since January.
Why this matters: Every one of these tools goes down, and yours will too on the morning you need it. If a task in your business now runs through one AI tool, write down the manual version of that task and where it lives. Fifteen minutes of prep beats a lost morning.
───
🛠️ THIS WEEK'S TRICK
Decide What an AI Agent Can Touch Before You Give It a Password
Every AI agent is sold on the promise that it works without supervision. Underneath that promise sits a decision you have to make yourself, which is how much of your business a piece of software that sometimes gets things wrong should be able to change on its own.
xAI's own docs put it bluntly: "An approval controls the proposed action. It does not reverse work already completed." An approval step protects you from the next thing, not the last thing. That means you do your protecting up front, when you decide what to hand over.
Step 1: List the tools and sort them into three levels
Write down every tool the agent would need to touch to do the job. Email, accounting, your CRM, scheduling, your bank, the website. Then put each one in exactly one of these:
Read only. It can look and report, never change anything.
Draft only. It can prepare the work, but a person sends, posts, or submits it.
Act. It can finish the action by itself.
Most people mentally put everything at Act, because that's where the time savings live. Start everything at Read only and promote one tool at a time, once it has earned it.
Step 2: Make it argue about what can't be undone
Paste this into ChatGPT or Claude:
I'm deciding what an AI agent should be allowed to do inside my business before I give it any access.
My business: [what you do, how many people]
Tools it would need: [e.g. Gmail, QuickBooks, my CRM, scheduling software, my bank]
Jobs I want it to handle: [describe them the way you'd explain them to a new hire]
Who does these jobs now: [me, an employee, nobody consistently]
Sort every tool into exactly one of these three levels, with one sentence on why:
1. Read only. It can look and report, never change anything.
2. Draft only. It can prepare the work, but a person sends or submits it.
3. Act. It can complete the action on its own.
Then tell me:
- Which of these actions could not be undone if the agent got it wrong, and what that would cost me
- Which single job I should start with, chosen because a mistake there would be cheap and obvious
- What I should check each week to know it's still behaving
- What would have to be true before any tool moves up a level
Assume the agent will occasionally do the wrong thing with total confidence. Don't put anything at level 3 in the first month. If I've described a job that shouldn't be automated at all, say so.
Step 3: Give it its own login, never yours
In each tool, create a separate user account for the agent with only the permissions its level requires.
Sharing your own login costs you both things you'd want in a bad week. You can't tell your activity from its activity when you go looking, and you can't cut off its access without locking yourself out at the same time.
What this works best for:
Any AI agent or automation that signs into your tools
A new virtual assistant or contractor, where the same three levels apply
Software you're about to connect to your accounting or payment systems
The moment a free trial asks you to "connect your account"
One honest limitation: this exercise tells you what the agent should be allowed to do. It can't tell you whether a specific product actually respects those limits. That part you learn by starting small and watching, which is the whole argument for beginning at Read only.
───
🔧 TOOL OF THE WEEK
Grok Bot (https://x.ai/news/introducing-grok-bot)
Grok Bot is a team of AI agents that live on a cloud computer, sign into your existing software the way a person would, and keep working while you're asleep. Because they operate the tools directly instead of through integrations, they can work inside software that never offered an automation option.
It's the most direct answer yet to "I want someone to just handle this," and that's why it's worth understanding even if you don't buy it this month.
Two things to know before you do. Every bot on your account shares one cloud computer, which means one set of logins and files that all of them can reach, and xAI says so directly. And it's early beta, which they also say directly.
Price: Bundled into three top tier plans (SuperGrok Heavy, Cursor Ultra, Cursor Teams Premium), there's no cheap way in.
Best for: Teams already paying for those plans who have a low stakes, repetitive job to hand it and the patience to supervise a beta.
Worth trying? Not yet, for most people reading this. The idea is right and the price plus the shared access model make it a bad first experiment for a small business. Watch it, and spend this month doing the Step 1 sorting exercise instead, because you'll need that answer no matter which agent you eventually use.
───
💡 PROMPT OF THE WEEK
Use this once you've decided what an assistant is allowed to do, to turn that decision into instructions it reads every time.
I'm writing standing instructions for an AI assistant that will handle [the job] for my business.
Context: [what the business does, who the customers are, what "done right" looks like]
Write a short set of operating rules it should follow every time, covering:
1. What it should always do without asking me
2. What it has to show me before anything goes out
3. What it should never do under any circumstances
4. Exactly what it should say when it's unsure, instead of guessing
Rules for your answer:
- Keep it under 200 words so I'll actually paste it in
- Write it as direct instructions to the assistant, in second person
- Build the "never" list around what would cost me a customer or money
- Point out anything I'll need to update as the business changes
Tip: show the finished rules to whoever does that job today. They'll name an exception in about ten seconds that you and the AI both missed.
───
👋 THAT'S A WRAP
Capability has stopped being the thing standing between you and an automated task. What stands there now is access, and access is something you decide rather than something you evaluate.
Pick one recurring job you'd hand over tomorrow. Sort its tools into the three levels, then go create one separate login for the agent in the tool that matters least. That's a 20 minute job, and you'll be ready when the product you want finally shows up.
Forward this to someone who's about to connect an AI tool to their email or their books. Better they read it this week than after.
See you next Friday.