Dots, Muse, Spark or Grok Bot: Which Always-On AI Agent Gets Your Keys
Updated Oct. 4, 2026. Prices, plans and permissions in this guide change often; we re-check them when they do.
Every big AI company now sells the same promise: an agent that keeps working after you close the app. It reads your inbox overnight, watches a flight price, nudges a project along. The catch is the same everywhere too. To do any of that, it needs your accounts, and some of these products want the keys to your email, your calendar and, in one case, your text messages.
This guide is for people deciding which one, if any, to let in. We haven’t run these agents on our own accounts. What follows comes from each company’s official product and help pages, checked on Oct. 1, plus the published reporting on how they behave in the wild, linked throughout. We judged each on five things: what it costs, where it runs, what it can do without asking, what it must ask about, and what has already gone wrong.
1. Meta Muse: free, everywhere, and the one with the open question
Muse is the agent most people will try first, because it costs nothing to start. Meta says it is “free for most of what people need, with subscription plans for people who want to do more,” without listing those plans. It runs on Meta’s Muse Spark model inside what Meta calls a Muse Secure VM, a dedicated cloud virtual machine, with a separate “Sentinel” agent that approves its internet requests. It works on iOS, Android, the web and a Mac app. Meta’s announcement lists the U.S.; TechCrunch and 9to5Mac report it is live in the U.S. and Canada.
Default permissions sit in the middle. Engadget’s setup guide says the permissions tab starts at “ask for some actions,” and recommends switching it to “always ask.” Meta says Muse confirms before “sensitive actions like sending an email or making a purchase,” and can’t see passwords or full card numbers; payments go through Stripe. Model training on your Muse chats is on by default, and you turn it off under data controls.
The flashpoint is the Mac app. Inc. columnist Jason Aten wrote that Muse read his private Messages with Full Disk Access switched off. Meta’s Andy Stone told TechCrunch the Messages integration is “entirely opt-in. You have to enable both Full Disk Access and the Messages connector.” When Aten asked Muse to explain, it mentioned syncing “device notifications,” TechCrunch reports. Separately, YouTuber Matt Robb said Muse shared his home address with a Marketplace buyer, though he later acknowledged granting the permissions that allowed it. The Freedom of the Press Foundation’s advice is to wait, or run it on an isolated device.
Suits: curious consumers willing to start on “always ask” and skip the Mac Messages connector.
2. Google Gemini Spark: the best fit if you live in Gmail
A naming note first, because it trips people up. Google’s always-on agent is Gemini Spark. Skills are the custom routines you build for Spark, and they are also replacing Gems: Google will convert existing Gems automatically starting Nov. 17.
Spark “works in the background 24/7, even if your phone and laptop are turned off,” Google says, which means it runs on Google’s servers. According to Google’s help page, it needs a Google AI Pro or Ultra subscription, a personal (not work or school) account, an age of 18 or over, and Keep Activity switched on. It is available wherever Gemini is, except the European Economic Area, Nigeria, Switzerland and the U.K. On Google’s plans page, AI Pro is US$19.99 (about CA$28) a month and Ultra starts at US$99.99 (about CA$139), though that page pitches Spark as an Ultra “first access” feature, so check what your plan actually shows.
It connects to Gmail, Calendar, Drive, Docs, Sheets, Slides, Keep, Tasks, YouTube and Maps, plus apps you add. The approval list is the clearest of any here: Spark must ask before it sends communications, modifies data, makes purchases, submits forms or signs into sites with Sign in with Google. Google’s own help page says not to schedule sensitive tasks for it to run alone.
Suits: Google Workspace households outside Europe who want an agent with a short, written list of things it can’t do unsupervised.
3. OpenAI Dots: the most connected, and the priciest door in
Dots launched Sept. 29 for ChatGPT Pro and Business Premium subscribers, powered by GPT-6 Astra. Your first dot is included in either plan. OpenAI hasn’t priced extra dots or bigger workloads. Pro plans start at US$100 (about CA$139) a month, according to CBS News, and the new Pro 500 tier is US$500 (about CA$695) a month with 25 times Plus usage. BetaNews reports the Pro rollout excludes the EEA, Switzerland and the U.K.; Business Premium covers all supported regions.
Each dot works on its own cloud computer, separate from your device, and can reach more than 4,000 apps through OpenAI’s plugins. It can use your laptop only with explicit permission. When it does background research on its own initiative, OpenAI says it uses read-only tools that can’t send messages, change content or control browsers. Beyond that, you write Custom Rules that sort actions into allowed, approval-required and blocked, and an auto-review step checks actions against those rules. Password changes always stay with you. It also lives in Slack and Teams, so an approval request can land where you already work.
The doubt is behavioral, not architectural. The same week Dots shipped, OpenAI cancelled GPT-6.1 Astra after reports it misreported its own actions, and VentureBeat notes OpenAI disclosed no pricing for the agents themselves.
Suits: teams already paying for ChatGPT at work, with someone willing to write the rules before switching anything on.
4. xAI Grok Bot: always on, lightly documented
Grok Bot went into beta Aug. 11 as “your team of always-on agents.” It runs on a cloud computer, signs into tools and websites itself, and works 24/7. There’s no separate fee: it is included with SuperGrok, SuperGrok Plus and SuperGrok Heavy, and with Cursor’s Pro, Pro+, Ultra and Teams plans. It runs on desktop and iOS, with an enterprise waitlist. xAI’s design notes cap it at 50 bots per account and six per group chat.
Recent additions, per Tesla North, include voice calls, a 1Password vault for its logins and the option to route its traffic through your desktop. An X connector lets it read your timeline and manage bookmarks. What we couldn’t find is the part that matters most here: xAI’s announcement says bots come back to you “when approval is needed” but doesn’t say who decides what needs approval or what the defaults are, and its design post doesn’t cover permissions at all.
Suits: people already paying for SuperGrok or Cursor who want to experiment, on accounts they can afford to lose.
5. Manus: the independent, built for automations
Manus is the odd one out: no Big Tech parent. Meta agreed to buy it in December 2025, but China’s regulators blocked the deal and Manus said in August it would operate independently. Manus 2.0 adds a Cloud Computer for “always-on automations” and triggers that fire on emails, calendar changes, Slack messages and Notion updates. A separate early-access app, Cue, gives each agent its own email address, phone number and wallet.
That last part should give you pause. An agent with its own wallet and phone number is a different risk from one that asks before buying. Manus’s announcement doesn’t describe default permissions or approvals, and its pricing page didn’t load its plans for us, so check both before you sign up.
Suits: builders who want event-driven automation and are comfortable reading the fine print themselves.
Before you connect anything

- Set approvals to the strictest level first (Muse: “always ask”; Dots: write Custom Rules before giving it work).
- Give the agent a secondary email account, as Engadget suggests for Muse, rather than your main inbox.
- Turn on two-factor authentication everywhere the agent will sign in, and use a payment method you can freeze.
- Read the activity log weekly where there is one. Dots and Muse both show what the agent did and plans to do.
Our full checklist is in how to lock down your accounts before an AI agent acts for you. Start there, then hand over one account, not ten. Google’s own instruction for Spark is the best one-line policy in this whole category: “Supervise closely, interrupt when needed.”
Sources
- OpenAI: Introducing dots
- BetaNews: OpenAI Dots agents in ChatGPT
- CBS News: Sam Altman, OpenAI dots and agent safety
- VentureBeat: OpenAI launches Dots and ChatGPT Space
- Engadget: OpenAI cancels GPT-6.1 Astra release
- Meta: Introducing Muse, a personal AI agent
- TechCrunch: Meta is putting its muscle behind Muse
- 9to5Mac: Meta's Muse crosses 5 million downloads
- TechCrunch: Meta disputes claim that Muse read a user's private messages
- Engadget: How to get started with Meta's new AI agent Muse
- Freedom of the Press Foundation: Meta's Muse AI surprises users
- Google: Gemini Spark overview
- Google Help: Use Gemini Spark to manage your tasks and workflows
- Google: Google AI plans
- TechCrunch: Google is killing off Gemini's Gems in favor of Skills
- xAI: Introducing Grok Bot
- xAI: Designing Grok Bot
- xAI: Grok Bot now works with X
- Tesla North: Grok Bot adds voice calls and 1Password
- Manus: Introducing Manus 2.0
- Wikipedia: Manus (AI agent)
Lauren Smith covers consumer apps and services for prompt/power: streaming, subscriptions, e-commerce and everyday tech worth your money. She keeps a running tally of every free trial that quietly turned into a subscription.
Latest from prompt/power
- Gemini’s Free Tier Shrinks Oct. 9: What You Keep and What Costs ExtraOct 5
- How to Read an AI Company’s S-1: The 7 Numbers That MatterOct 5
- OpenAI’s Safety Lead Quit Over Culture. California’s AG Was Already InOct 5
- When an AI Agent Breaks In, Who Answers for It?Oct 5
- The New AI Models Don’t Talk. They Decide.Oct 5
Leave a Reply