One account, one computer: the gap between the marketing and the security model
Grok Bot's pitch is a roster of independent AI teammates, each spun up to handle a different job. The reality, confirmed by both xAI's own documentation and independent reporting, is that every Bot tied to a given account runs on a single shared cloud computer - one browser, one filesystem, one set of command-line credentials, available across the whole roster [1]. Official docs describe each Bot as running on 'a persistent cloud VM with a browser, filesystem, and terminal' [2], language that reads as per-Bot infrastructure but functions, in practice, as one shared machine per user.
What makes this notable is that the same concern surfaced independently across three different audiences. YouTube reviewers described it as a 'security perimeter' design - a single boundary around all of a user's Bots, meaning adding more Bots doesn't expand the attack surface the way spinning up more standalone tools would. Reddit's more security-conscious users flagged the identical point from xAI's own documentation, worrying about mixing sensitive workflows, like a finance-adjacent Bot, with a public research Bot on the same shared instance. Reviewers noted the product still lacks published reliability data and carries real exposure to prompt-injection attacks given the standing access Bots hold to real accounts [3]. When a web-docs disclosure, a technical YouTube review, and Reddit's skeptics all converge on the same structural critique from different angles, it's a stronger signal than any one source alone - the 'your own agents' framing oversells what is, underneath, shared infrastructure with a single point of failure.


