Home / Insights / OpenAI Dots vs Grok Bot, Hermes and OpenClaw in Europe
Comparison

OpenAI Dots vs Grok Bot, Hermes and OpenClaw in Europe

Summarize with AI Prompt copied. Paste it into the chat

OpenAI Dots are always-on personal AI agents, launched on 29 September 2026. Each dot has its own cloud computer and browser, runs on GPT-6 Astra, connects to more than 4,000 apps and keeps working while you are in a meeting or asleep. In the Netherlands and Belgium you cannot get one on a personal Pro plan. You can get one through ChatGPT Business Premium, and through Enterprise once an admin switches the beta on. So in Europe the personal agent arrives as a workplace decision, and it lands on the desk of IT.

This is written for the IT manager, CIO or security officer at an organisation of 250 to 5,000 people who will be asked about Dots this month, probably by someone who saw the demo. The launch coverage compared features. This piece puts Dots next to Grok Bot, Hermes Agent, OpenClaw, Microsoft Scout, Claude Cowork, Gemini Spark and Meta Muse on the five questions your change process and your auditor will ask, and says plainly where the public documentation stops.

What are OpenAI Dots, in plain terms?

A dot is a named agent inside ChatGPT that holds ongoing responsibility instead of answering one prompt. According to OpenAI's announcement and Engadget's report, it works like this:

  • It has its own machine. Every dot runs on a cloud computer with its own browser. You can open that computer at any time to see what it is doing. Access to your own laptop is optional and starts switched off.
  • It reaches you where you already work. You message it in ChatGPT, Slack or Microsoft Teams, and it messages you back with progress, questions and approval requests.
  • It works when you have not asked. OpenAI calls this proactive research. In that mode the dot uses your connected apps through read-only tools, so it cannot send messages or change content.
  • It follows rules you set. For each kind of action you choose one of four behaviours: act without asking, act only if you asked for it in the prompt, ask first, or hand the step to you. Some actions, such as changing a password, always stay with the user.
  • It is one dot per person for now. Teams of dots, and specialist dots with their own identity inside a company, are announced but not generally available. Specialist dots start as pilots run together with OpenAI's engineers.

The examples OpenAI gives are ordinary office work: finding work that was never invoiced and preparing the invoice, rerunning an analysis when new lab data arrives, turning customer feedback into small tested fixes. That ordinariness is the point. This is not a research toy. It is aimed at the to-do list of a knowledge worker.

Which always-on agents can you use in Europe?

For Dots the help centre is specific. Pro users get dots everywhere except the European Economic Area, Switzerland and the United Kingdom. Business Premium users get them in every region where ChatGPT is supported. Enterprise, Edu and Healthcare workspaces get a beta that stays off until an admin enables it. Texting with a dot is limited to Pro users in the United States. OpenAI gives no reason for the European exception.

Comparison: OpenAI Dots, Grok Bot, Claude Cowork, Gemini Spark, Meta Muse, Microsoft Scout, Hermes Agent and OpenClaw by hosting, availability in the EEA and identity

Dots is not alone in this. The pattern across the whole category is the real news for a European reader:

  • Meta Muse, launched on 8 September 2026 for consumer errands, is available in the United States only, according to eesel's overview and Trending Topics.
  • Gemini Spark is offered wherever Gemini works except the EEA, Switzerland, the United Kingdom and Nigeria, and only on a personal Google account. Work and school accounts are excluded, says Google's help page.
  • Grok Bot, launched by xAI on 11 August 2026, names no regional limits in its launch material. It is not sold on its own: it comes bundled with SuperGrok Heavy and two Cursor plans, as Unite.AI reported.
  • Claude Cowork runs tasks in Anthropic's cloud, including scheduled ones, on Pro, Max, Team and Enterprise plans. Its help page lists no regional restrictions.
  • Microsoft Scout, announced on 2 June 2026, is in private preview through Microsoft's Frontier programme.
  • OpenClaw and Hermes Agent are open source. You download them and run them yourself, so no vendor decides where you may use them.

Put together: the consumer door to always-on agents is mostly closed in Europe, and the two doors that are open are the business plan and open source. Both lead into your organisation. One comes in through a licence somebody can order, the other through a download on a developer's laptop. Neither waits for a policy.

Dots vs Grok Bot, Hermes and OpenClaw: who is who?

These products look alike in a demo. They differ on the one point that matters for operations, which is who runs the machine the agent lives on.

  • Vendor cloud, personal agent: Dots, Grok Bot, Muse, Spark and Cowork. The vendor hosts the agent's computer. You get speed and no infrastructure to set up. You depend on the vendor's controls and the vendor's logging.
  • Your tenant, governed agent: Microsoft Scout. Microsoft says each agent gets its own Entra identity and works inside Purview's data protection policies, including sensitivity labels. One detail stands out: Microsoft states that Scout is built on OpenClaw's open source technology. The engine is the same. The layer of identity and policy around it is what Microsoft adds.
  • Your own server, your own responsibility: Hermes Agent and OpenClaw. Hermes Agent comes from Nous Research, is MIT licensed and is self-hosted only, with container isolation and approval for dangerous commands as standard, according to innFactory's comparison. OpenClaw began as a personal project by Peter Steinberger and moved to a foundation in February 2026. It connects to more than fifteen messaging channels. With both you choose the model, and you are the one who patches.

Grok Bot deserves one specific note. The marketing says every Bot has its own computer. The documentation, as Digital Applied's analysis reads it, says all Bots on one account share the same persistent cloud computer, and xAI itself warns against treating separate Bots as a security boundary. If your developers have Cursor Ultra, Grok Bot may already be inside the building.

Whose name is on the action?

This is the question the launch coverage skipped, and it is the first one an auditor asks. OpenAI describes a personal dot as an extension of you. It works through the apps you connected. It can use your email account, and at launch it cannot have an address of its own. So when a dot sends a message or changes a record, your systems log the employee, not the agent.

That breaks two things quietly. Segregation of duties assumes that the person who prepares a payment and the person who approves it are different people. If an employee's dot prepares the payment and that same employee clicks approve on the request from their own dot, the four-eyes principle is formally met and practically empty. And joiner, mover and leaver processes assume that revoking an account ends the access. An agent with saved sessions and a memory of its own is a second thing to revoke.

Microsoft Scout and OpenAI's specialist dots take the other route: the agent gets its own identity, so its actions can be attributed to the agent. That is the model your identity team will want. Today it exists in preview and in pilots, not as something you can order for 400 people. There is no finished standard underneath it either, which we covered in AI agent identity: four drafts, zero standards.

What can it do without asking?

Every product in this comparison has an approval step, and every vendor is candid that it is not a guarantee.

  • Dots checks actions that touch your accounts or share information against your instructions, your Custom Rules and OpenAI's own safety requirements. OpenAI adds that a dot can make mistakes, also when it is following your rules.
Pull quote from Crux Digits: An agent that acts under your name leaves your name in the audit log.
  • Grok Bot asks per action, with allow once, deny or always allow. For passwords, two-factor codes and payment confirmations it hands control to the user. xAI writes that its automatic review should complement least privilege, not replace it.
  • Claude Cowork has three modes: ask for every action, act with automatic safety checks, or skip the prompts entirely. On Team and Enterprise plans an admin can set the approval requirements.
  • Hermes Agent and OpenClaw do what you configure. There is no vendor default to fall back on.

Two things are worth knowing here. First, on a personal agent the rules are written by the user, in the user's own words. A rule typed by a busy account manager is not a control your organisation designed. Ask each vendor which rules an admin can enforce for everyone, and ask for the answer in writing.

Second, the day before Dots launched, OpenAI held back a newer model, GPT-6.1 Astra. Its head of safety systems said the model did not meet the bar on staying within scope and authorisation, and on how it reports back what it did, Al Jazeera reported. Dots run on GPT-6 Astra, the earlier model, which we compared in GPT-6 Astra vs Claude Fable 5.1. The lesson is not alarm. It is that the vendor itself treats staying inside what was authorised as the hard part. Your approval design should do the same. We described one way to phase that in AI agent autonomy: treat it like a new hire.

What does it remember, and what happens when you switch it off?

The help centre contains the two statements that matter most to a privacy officer, and almost nobody repeated them.

A dot reviews the information in connected apps on its own initiative and forms memories from it, even when nobody asked a question about it. And disconnecting an app does not delete what the dot already took from it. To delete that, you delete the dot, which also removes its conversations, memories and scheduled tasks.

For a European organisation that raises practical questions:

  • Purpose. A mailbox connected for one task is read for the dot's general usefulness. Your FG or DPO will want that described in the DPIA before the first mailbox is connected.
  • Erasure and retention. If a customer asks for deletion, their data may also sit in the memory of several employees' dots. The help centre describes no way to delete a single item, only a reset.
  • Offboarding. When someone leaves, the dot's memory of their clients and colleagues stays where it is. Decide who resets it and when.
  • Training. OpenAI states that content from Business, Enterprise and Edu workspaces is not used to improve its models by default. For Grok Bot, storage in the cloud is mandatory and training and retention follow the terms of the Cursor account, according to the same Digital Applied analysis.
  • Staff. An agent that reads team channels processes data about employees. In the Netherlands that can bring the works council's right of consent under article 27 of the WOR into play, the same mechanism we described for shadow AI detection. Belgian works councils have their own rights to information and consultation. Ask before the pilot, not after.

What did the Dutch regulator already say?

On 12 February 2026 the Autoriteit Persoonsgegevens published a warning about OpenClaw and similar experimental agents. The AP reports that roughly one in five plugins appears to contain malware, that the platform is vulnerable to instructions hidden in websites, emails and chat messages, and that critical vulnerabilities let attackers take over systems remotely. Its advice is direct: do not use these agents on systems that hold privacy-sensitive or confidential data, such as financial administration, employee data or identity documents.

Two points in that warning reach well beyond OpenClaw. The organisation stays responsible under the GDPR, whatever the software is called. And the AP asked for clarification at European level that autonomous agents fall under the AI Act. In Belgium the law firm Sirius Legal noted that the Belgian authority had not publicly repeated the warning, and gave the same checklist anyway: isolation, least privilege, logging that lets you reconstruct actions, and a documented risk analysis.

Hosted products like Dots are not what the AP warned about. They are not experimental, and OpenAI describes safeguards against malicious instructions plus monitoring that can pause a dot. The class of risk is the same, though. An agent that reads your inbox reads whatever an outsider puts in it. And 4,000 connectable apps is a supply chain, with the gaps we described in what the marketplace safety scan misses.

On the AI Act: the omnibus of July 2026 moved the main high-risk deadline to December 2027. The transparency duties of article 50 were not postponed and have applied since 2 August 2026. If a dot writes to your customers under an employee's name, ask your legal team whether the recipient needs to be told, and how.

Which one fits which situation?

There is no winner, because these are not the same purchase.

  • You run on Microsoft 365 and governance comes first. The model you want is Scout's, and OpenAI says specialist dots will become manageable through Microsoft Agent 365. Both are previews. The honest advice is to write the policy now and buy later.
  • You want to learn this quarter at low risk. One Business Premium workspace or one Claude Team workspace, a handful of named users, read-only connections, no mailboxes, approval on everything that sends or pays.
  • Data must stay on your own infrastructure and you have engineers. Hermes Agent in a container, with a model you host or contract yourself. You gain control and take on patching, monitoring and incident response.
  • Someone proposes OpenClaw on a work laptop. Point to the AP warning. If you want it at all, it belongs in an isolated environment without production credentials.
  • Someone asks for Muse or Spark. Not available here, and Spark does not accept work accounts.

Five things to do this week

  • Find the doors. Who can create or upgrade a ChatGPT Business workspace, and who holds Cursor or SuperGrok subscriptions? That is where agents come in.
  • Set the default before somebody asks. In Enterprise the beta is off until an admin enables it. Write down who decides and on what grounds.
  • Pick one process, not one person. Choose work with a clear start, a clear end and an owner, and begin with read-only access.
  • Write the approval rules centrally. Sending, paying, deleting and sharing outside the organisation need a human. Do not leave that to each user's own wording.
  • Test the exit. Connect an app, disconnect it, reset the dot and check what is left. Do it once, on test data, before it matters.

Where a firm like ours fits, and where it does not

Crux Digits builds AI systems for organisations, as the AI partner next to your ICT partner or your internal IT team. We do not manage tenants, identity providers or laptops, and for a personal agent you mostly do not need us. Switching on Dots for twenty people is a licence and a policy decision. Your IT team, your ICT partner and your FG can make it with the questions above.

A specialist becomes useful at the point where the work stops being one person's to-do list and becomes a process: matching invoices against the ERP, intake of service requests, checking documents against a rule. That work needs an identity of its own, a test set that proves it still behaves after a model update, and logging your auditor can read. That is a built system with an owner, and it is the kind of implementation we do. A personal dot and a process agent can live side by side. They should not be mistaken for each other.

The short version

  • Dots launched on 29 September 2026. In the EEA, Switzerland and the UK it comes through Business Premium and the Enterprise beta, not through Pro.
  • Muse and Spark are not available in Europe. Grok Bot and Cowork list no regional limits. Scout is in preview. Hermes Agent and OpenClaw run wherever you install them.
  • A personal agent acts under the employee's name. That is the weak spot for segregation of duties and for offboarding.
  • Disconnecting an app does not delete what a dot already learned from it. Only a reset does.
  • The AP's warning of February 2026 and the GDPR put the responsibility on the organisation that deploys the agent.
Want this built into production?

We build custom AI and LLM systems that run in production: a clickable MVP by the second call, fixed steps, and you own the code.

AI development agency in the Netherlands →

Frequently asked questions

Is OpenAI Dots available in the Netherlands and Belgium?

Yes, but only through work plans. According to OpenAI's help centre, Pro users get dots everywhere except the European Economic Area, Switzerland and the United Kingdom. Business Premium users get dots in every region where ChatGPT is supported, and Enterprise workspaces get a beta that stays off until an admin enables it. Texting with a dot is limited to Pro users in the United States.

What is the difference between OpenAI Dots and Grok Bot?

Both are hosted, always-on agents that work on a cloud computer and come back to you for approval. Dots comes from OpenAI, runs on GPT-6 Astra and lives in ChatGPT, Slack and Teams, with one cloud computer per dot. Grok Bot comes from xAI, is bundled with SuperGrok Heavy and two Cursor plans, and can learn a routine by watching you do it once. Per its documentation, all Bots on one account share the same persistent cloud computer, so separate Bots are not a security boundary.

Is OpenClaw safe to use in a business?

Not on systems with sensitive data, according to the Dutch regulator. On 12 February 2026 the Autoriteit Persoonsgegevens warned against using OpenClaw and similar experimental agents where privacy-sensitive or confidential data is present, citing malicious plugins, hidden instructions in websites and emails, and critical vulnerabilities. If you evaluate it, do so in an isolated environment with strict access control and no production credentials. Hermes Agent ships with stricter defaults, but it is self-hosted, so patching and monitoring are yours.

What is the difference between a personal dot and a specialist dot?

A personal dot works on behalf of one user, through the apps and the email account that user connected, so its actions are logged under the user's name. A specialist dot is set up by the company with its own identity, its own credentials and one defined responsibility, such as invoice processing or procurement. Personal dots are rolling out now. Specialist dots exist only as enterprise pilots run with OpenAI's engineers, and the integration with Microsoft Agent 365 is still being built.

Does a dot use our company data to train OpenAI's models?

Not by default on work plans. OpenAI states that content from ChatGPT Business, Enterprise and Edu workspaces is not used to improve its models by default, and that it does not train directly on proactive research or on a dot's notes to itself. Training is a different question from retention, though. Disconnecting an app does not delete what a dot already obtained from it. To remove that, the dot has to be reset, which deletes its conversations, memories and scheduled tasks.
Our AI services AI consultancy AI automation AI agents AI implementation Pricing

Want any of this applied to your business?

We turn these concepts into working tools: grounded, safe and measurable. Start with a free consultation.

Book a free consultation →