probearc
Tech blog · Essay · 5 October 2026

Personal AI agents in October 2026: hosting choices and what we know

OpenAI dots, Grok Bot, Meta Muse and Gemini Spark on one side, OpenClaw and Hermes on the other. What they are, how they differ, and how much is actually known.

OpenClaw and Hermes are probably familiar names by now. You may also be hearing about OpenAI's "dots" and Grok's "Bots". The field includes versions from Google, Meta, Microsoft and Anthropic too. This article covers what personal agents do, the differences between hosted and open-source options, their intended users, and how they work. It also compares what each offers. I haven't tried the hosted products. My sources are vendor documentation, project documentation and press coverage. Where the evidence is weak, I've said so. Names change quickly here. The ones used in this article are current as of 5 October 2026.

What makes an agent always-on

These products share five components. An AI model, an LLM such as GPT, Gemini or Claude, interprets your request and decides what to do next. Tools and connectors give it access to things like mail, calendars and a browser. Memory carries information across sessions. A scheduler starts work without waiting for you to ask. The agent returns its results through a channel, most often a chat window.

What separates this setup from a chatbot is the combination of a scheduler and a computer that keeps running. Work can continue after you close your laptop. You review the results later.

How you can run one

With a vendor-hosted agent, the company supplies the model and runs the system on a cloud computer it controls. These are the current options:

  • Google Gemini Spark runs on Google Cloud virtual machines. Announced at I/O on 19 May, it is available in the US through the $20 Google AI Pro plan.
  • xAI Grok Bot is sold through SuperGrok and Cursor plans. Its beta began on 11 August.
  • Meta Muse gives every user a dedicated VM. A separate agent called "Sentinel" approves actions that reach the internet. Meta announced Muse on 8 September and calls it free for most of what people need. Availability is currently limited to the US.
  • OpenAI dots requires ChatGPT Pro, starting at $100 a month. OpenAI announced it at DevDay on 29 September. Each dot gets its own cloud computer and browser.
  • Microsoft Autopilot targets companies and remains in private preview. It arrived in June under the name Scout, then took its current name on 25 September.
  • Anthropic spreads these functions across several products. Claude Cowork has scheduled tasks, teams have Claude Tag in Slack, and developers have routines in Claude Code. There is no single Anthropic product that brings them together.

For a self-hosted agent, you keep an open-source program running on your own computer or a rented server. The main choices are OpenClaw, which a foundation now runs, and Nous Research's Hermes Agent. Both use the MIT license and allow you to pick the model. Each runs a gateway process to connect with chat apps, including Telegram, WhatsApp and Slack. There is no software charge, but you cover the machine and model usage.

Both are extended through skills, which are add-ons that give the agent a new ability, such as reading a calendar or working with a particular website. OpenClaw has a public registry called ClawHub where anyone can publish skills. Hermes has a Skills Hub that installs from several sources, including GitHub repositories, Vercel's skills.sh directory and ClawHub itself. Hermes can also write its own skills. This community library is a real advantage of the self-hosted side. It is also a risk, because a skill is code and instructions written by a stranger. Security researchers reported hundreds of malicious skills on ClawHub earlier this year. Both projects now scan skills when you install them, but I found no data on how well that scanning works.

OpenClaw was the first to arrive. It went viral early this year, and the hosted agents released since then resemble it closely. In June, Microsoft described Scout as "powered by OpenClaw open-source technology". The other vendors haven't stated such a connection. For them, the comparison comes from press coverage and the timing of their releases.

Comparing hosted and self-hosted agents

Self-hosted (OpenClaw, Hermes) Vendor-hosted (dots, Spark, Muse, Grok Bot)
Control You own the machine, the schedule and the memory files The vendor owns the runtime and sets the limits
Privacy Files stay on your machine, but prompts still go to a model provider unless you run a local model Data lives in the vendor's VM under the vendor's policy
Model Any provider, or a local model The vendor's own model in most products
Extensions Community skills from public registries, which you vet yourself The connectors and plugins the vendor offers
Safety defaults Mostly opt-in, you harden it yourself Isolation and approval checks are on from the start
Convenience You install, patch and monitor it Sign in and connect your apps
Cost Free software, a small server, and per-token model spend with no ceiling A flat subscription with an allowance that is mostly unpublished

Privacy and cost are easy to misread in this comparison. I got both wrong myself.

Keeping the agent on your machine means its memory and your files stay there. It doesn't mean their contents never reach another company. The model provider still receives every prompt, email excerpt and tool result you send to its model. To avoid that, you need a local model.

Low costs also depend on the model. Self-hosting is cheap only if the model is cheap or local. OpenClaw's heartbeat wakes the agent every 30 minutes by default. Every wake-up uses tokens. Published monthly estimates run from a few dollars to several hundred. Most come from businesses selling hosting or API routing, so I wouldn't rely on any one estimate. Using a frontier model can make a self-hosted agent more expensive than a $20 hosted plan. Spending is uncapped unless you impose a limit.

The benefits of self-hosting are more specific than those broad privacy and cost claims suggest. You can read and change OpenClaw's memory because it uses plain Markdown files. Its documentation states that "there is no hidden state". Model choice and chat app choice are yours, and access doesn't depend on your country.

Hosted agents have an advantage in their default safety settings. According to OpenAI's documentation, a dot must pass an approval check before sharing information or doing anything that affects your accounts. Rules you write cannot override its built-in rules. Google says Spark requests permission before sending email or spending money. OpenClaw's README, meanwhile, says its tools execute directly on the host unless you set up sandboxing. The security findings fit that difference. A Cloud Security Alliance note lists nine OpenClaw CVEs over four days in March 2026. An April audit found 4 critical and 9 high severity issues in the default configuration of Hermes Agent.

The hosted products don't all impose the same controls. Reviewers report that a user's Grok Bots all use one cloud computer, including the same logins. Anthropic's Claude Code routines run without stopping for approval at each step. The claim that "hosted is safer" concerns architecture and defaults. I could not find measurements showing how well any of these agents withstands prompt injection.

Who these products are meant for

Vendors don't publish who actually uses their agents. Their examples give the clearest indication of whom they want to reach.

  • Meta Muse and Gemini Spark are meant for individuals using them in their personal life, not for companies. The suggested tasks include travel bookings, subscription audits, grocery lists and event lists.
  • OpenAI dots targets individuals and small teams already paying for Pro. Its documentation uses the example of keeping an offsite on track.
  • Grok Bot targets teams and knowledge workers. Sales outreach and expense management are among the eight roles that xAI documents.
  • Microsoft Autopilot and Claude Tag target organisations through Microsoft 365 and Slack.
  • Claude Code routines target developers. Suggested uses include pull-request review and nightly issue triage.
  • OpenClaw and Hermes suit people comfortable with operating and securing a server.

The documented tasks almost always finish with a list, a draft or an approval request. Each of xAI's eight roles includes an explicit stopping rule, such as "Do not change budgets or send the message".

Example 1: using the hosted Gemini Spark

A weekly list of events is one of Google's examples. This walkthrough draws on Google's documentation and TechCrunch's hands-on test of that task.

  1. After subscribing to Google AI Pro, you enable Spark in the Gemini app and select the apps it can access. Google says there is no setup because Gmail, Docs, Sheets and Calendar are already connected.
  2. You give it a plain-language request: "Every Friday at 8AM, find local events that you think I'd be interested in and add them to my rolling 'Weekend plans' Google Doc."
  3. A Google Cloud VM runs the agent every Friday. Neither your laptop nor your phone needs to be on.
  4. The agent looks through the web and relevant email. For the TechCrunch reviewer, that included local newsletters from their inbox.
  5. It puts together the list. During the test, it also wanted to put events on the calendar, but requested the reviewer's confirmation before doing so.
  6. The finished list reaches you through a message or the document.

You pay the $20 subscription. Google doesn't disclose how much of its allowance a weekly task like this consumes. The reviewer considered Spark useful but also noted mistakes: a promo code that didn't work, four items instead of the five requested, and redirect links that were broken.

Example 2: running OpenClaw yourself

A morning briefing delivered through a chat app is a common starting project in the OpenClaw community.

  1. Start with a computer that will remain on. Install OpenClaw, provide a model API key, and connect it to Telegram.
  2. Add skills that give it access to the sources you want in the briefing, such as email, a calendar and a weather service.
  3. Put periodic-check instructions in the Markdown file HEARTBEAT.md. If you want a specific delivery time, such as 7 a.m., the documentation directs you to a scheduled job. That job starts the agent and sends its output to a chat channel.
  4. The scheduler starts the agent at 7 a.m. It checks the weather, calendar and mail, then delivers a single Telegram message.
  5. There is no approval request in this flow. The pages I read did not show a built-in approval step, so you would need to add that requirement to your instructions.

Your costs are the server and the tokens consumed each time it runs. For this task, community estimates begin well under a dollar a month with a cheap model. Those figures assume very small prompts. I'd use them as a floor.

Setting up the same kind of task takes less work in Hermes Agent. Send it "Every morning at 9am, check Hacker News for AI news and send me a summary on Telegram", and it creates the scheduled job itself. Running the server and securing it are still your responsibility.

Where things fail

The failure with the most documentation involves a self-hosted agent. Summer Yue works on AI alignment at Meta. She gave OpenClaw access to her real inbox with instructions to suggest actions and wait for her approval. The large inbox led to the conversation being compacted to fit the model's context. That removed the instruction. OpenClaw proceeded to trash and archive hundreds of emails before she stopped it.

Her experience shows why the location of an approval rule matters. The "confirm first" instruction was just part of the conversation text. Hosted vendors put approval enforcement outside the model, so shortening the conversation cannot erase it.

Hosted agents run into other limits. Payments, two-factor codes and some sites that block cloud browsers can stop them. Sometimes a website prevents the agent from continuing. Sometimes the vendor has decided it should wait for you. Either way, the user encounters an interruption.

What we know about popularity

I don't have enough usage information to rank these products. I don't think anyone does yet.

Among hosted agents, only Meta Muse has public figures. TechCrunch reported estimates on 25 September: Sensor Tower put downloads at 3.4 million, Apptopia at 4.3 million and Appfigures at about 2.3 million. Those figures count downloads of a free app with heavy promotion from Meta. They don't tell us how many people actively use it. My search turned up no figures for dots, Spark, Grok Bot or the other products.

GitHub stars provide a number for the self-hosted projects. OpenClaw had about 391,000 on 5 October, while Hermes Agent had about 251,000. That tells us about attention, rather than how many people use them.

What to watch next

These are the developments and gaps I'm watching.

  • Hosted and self-hosted agents are becoming more alike. Plain sentences work as instructions in Hermes, as they do in Spark. Microsoft's first agent used OpenClaw. NVIDIA and Cisco now provide OpenClaw with sandboxing and scanning layers, adding enforcement that the core project makes optional.
  • Regional access. Consumer versions of dots, Spark and Muse remain unavailable in the EEA and the UK. None of the vendors has explained why. Spark is rolling out in India according to Google's India blog. It is the only hosted consumer agent I could confirm here.
  • Access to websites. In August, a US appeals court ruled in a dispute between Amazon and Perplexity involving a browser agent placing orders. I have only read summaries, so I won't draw conclusions about the ruling. The question of who may act for you on a website remains unsettled.
  • Shared standards. The Linux Foundation now houses the Model Context Protocol, which connects agents with tools. The major vendors are members. Payments by agents still use several competing schemes.
  • Missing evidence. I could read just one hands-on review in full from a major outlet. It was about Spark. We still have no benchmark measuring task success across days of unattended work, or measurements of prompt injection resistance.

Where I stand

Choosing between hosted and self-hosted agents mostly comes down to responsibility when something goes wrong. With hosting, the vendor places its approval system between the model and your accounts. The subscription, lock-in and interruptions are part of that arrangement. Running an agent yourself removes that approval layer and its restrictions. It also makes security your job.

The usual description of self-hosting as private and cheap needs qualification. Privacy is partial when you use a cloud model, and a frontier model makes it expensive. The more concrete benefits are memory you can read, freedom to choose any model and chat app, and access without regional restrictions.

Claude Code carried out the searches and read the pages for this research. That means the Anthropic sections rely on an Anthropic model reading Anthropic's documentation. I've tried to apply the same standard to those sections as to the others. I'd like to hear what holds up from people using these agents for real work.

First published on ringarc.ai on 5 October 2026. Comments and corrections: vikas@probearc.ai.