AI StrategyChoosely EditorialEvidence-based analysis

The Always-On AI Assistant Is Here. What Should You Actually Let It Do?

AI is moving from something you prompt to something that keeps working after you leave. The question is no longer only how smart the assistant is, but how much access you are prepared to give it.

← Back to AI Radar
Choosely chimp controls a glowing permissions boundary between approved AI tasks and restricted financial, security and destructive actions.

Instinct, OpenClaw, Grok Bot, OpenAI's experimental Persistent mode and Meta's reported Project Hatch all point in the same direction: AI is moving from something you prompt to something that keeps working after you leave. The bigger question is no longer how smart the assistant is. It is how much access you are prepared to give it.

For most of the AI era, the bargain has been fairly simple.

You ask. The model answers.

Agents changed that slightly. They could browse, write files, use tools and finish multi-step jobs. But even then, the interaction usually began with you telling the AI what to do.

That boundary is now moving.

Open-source assistant OpenClaw can run on your own machine, maintain state and work through email, calendars and messaging services. Its pitch is unusually direct: the assistant lives on your machine, while its memories, skills, models and data remain under your control.

Private-beta startup Instinct represents almost the opposite approach. Users connect it deeply to their digital lives, then communicate with it through calls or messages while it handles appointments, travel, shopping, inbox administration and other personal tasks. Instinct has now raised $350 million in total funding, including a $250 million Series B, at a reported $2.5 billion valuation despite remaining in private beta.

Grok Bot is already a shipped example on the work side of the same shift. Its named agents operate on a persistent cloud computer, can keep working while the user's laptop is closed, use browsers, files, terminals and connected services, and run recurring routines. The convenience comes with an important architectural detail: a user's Bots share the underlying computer environment, including browser sessions, files and credentials.

OpenAI, meanwhile, is testing a Persistent mode for Codex. WIRED reports that the experimental mode can keep working until deliberately put to sleep, generate follow-up tasks from previous interactions and proactively contact the user under controlled conditions. OpenAI confirmed the testing but has not announced a public launch.

Meta appears to be heading toward the same destination. An internal memo reported by Business Insider describes Project Hatch, a personal agent designed to operate its own computer, retain memory and handle tasks including shopping, reservations, calendars, email and online forms. Meta has not publicly launched Hatch or confirmed its final pricing, although reported internal discussions have considered pricing as high as roughly $200 per month.

Different products. Different architectures.

Same direction.

The assistant is starting to outlive the prompt.

And once that happens, choosing an AI assistant becomes a permissions decision as much as a model decision.

The shift at a glance

ApproachExampleWhere it runsThe real tradeoff
Local personal agentOpenClawYour deviceMore infrastructure control, more setup
Cloud life assistantInstinctVendor-managedMaximum convenience through deep personal access
Persistent work agentGrok BotManaged cloud computerPowerful delegated work with shared credential and approval boundaries
Platform agentOpenAI Codex Persistent modeOpenAI, currently experimentalAgent continues and creates work rather than stopping at the original task
Consumer personal agentMeta Project HatchMeta, reportedly in testingBroad life administration through an autonomous computer

This distinction is more useful than another model leaderboard.

A persistent assistant does not become valuable simply because it can reason for longer. It becomes valuable because it remembers what matters, has access to where work happens and can act without rebuilding the entire context every time.

Those are also precisely the things that increase the downside when something goes wrong.

What actually makes an AI assistant "always-on"?

The term is already becoming loose enough to need some discipline.

An always-on assistant does not necessarily mean a model generating tokens 24 hours a day. It means the system can preserve enough state, memory, access and scheduling to remain useful between individual conversations.

Four things matter.

Persistent context

A chatbot knows the conversation in front of it.

A persistent assistant needs enough ongoing context to understand previous work, recurring tasks, preferences and commitments.

OpenClaw explicitly makes this central to its architecture. State can live on the user's own machine rather than entirely inside a vendor-managed cloud.

Persistent context is what turns:

"Book a restaurant."

into:

"Find somewhere similar to the places we usually choose, make sure Friday evening is free, and remind me before we need to leave."

Useful.

Also considerably more intimate.

Persistent access

Memory alone cannot run anything.

The assistant needs hands.

That increasingly means inboxes, calendars, browsers, files, messaging services, business applications, shopping accounts and logged-in sessions.

Instinct is an unusually clear preview of the appeal. Users have reported delegating travel, restaurant bookings, email follow-ups, shopping, CRM work and inbox administration to it.

Grok Bot takes the work-oriented version further. Its agents can use browser sessions, files, terminals and connected services from a persistent cloud computer, including while the user's own machine is offline.

The important point is not that one architecture is automatically safe and another unsafe.

It is that access is the product.

A brilliant assistant that cannot touch anything remains mostly an advisor.

A merely good assistant that can read your inbox, open your CRM, fill forms, send messages and make purchases can become enormously useful.

It can also become enormously consequential.

Proactivity

This is the bigger change.

Instead of waiting for:

"Check whether anything needs doing."

a persistent assistant eventually needs to recognize:

"Something needs doing."

WIRED's reporting on OpenAI's experimental Persistent mode describes that direction directly. Codex can reportedly create follow-up tasks, carry work forward and notify the user without a fresh prompt under its experimental proactivity instructions.

That changes the relationship with the software.

You are no longer operating a tool every time you want an outcome.

You are setting boundaries for a system that may decide when another piece of work should begin.

Approval

This may matter more than the model underneath.

Should the assistant read automatically but ask before writing?

Draft an email but ask before sending?

Prepare a checkout but ask before paying?

Move a calendar event without asking?

Retrieve a verification code from your inbox?

Delete something it decides is obsolete?

Keep consuming compute until someone remembers to stop it?

The smartest personal agent with a poor approval model is still a poor personal agent.

Instinct shows why permissions are becoming the product decision

Instinct's private beta offers one of the clearest early examples of what happens when impressive capability meets unresolved trust questions.

TechCrunch reports that Instinct's current terms grant it a broad "perpetual and irrevocable" license covering user material, including rights to access, store, transmit, modify and use that material for AI-model training. The same terms contemplate Instinct entering agreements, commitments or transactions on the user's behalf that can be binding.

That is materially different from allowing a chatbot to remember your preferred writing style.

Early testers have also raised concerns about retained email data, the handling of disconnected accounts and actions taken without the approval users expected. One user reported Instinct sending an email without first checking. Another found the service continuing to summarize previously indexed email after Gmail access had been disconnected. Instinct has since made changes to some data-deletion controls and has said it is taking the security concerns seriously.

Instinct is still a private-beta product. Its controls, terms and architecture may continue to change substantially.

That makes these examples more useful as a warning about the category than as a final verdict on one startup.

The fundamental trade is becoming clearer:

the more useful the assistant becomes, the more carefully access needs to be divided.

There is also an unresolved commercial question. Forbes has reported that Instinct could eventually become a subscription product or explore advertising informed by connected personal data, although no final business model has been announced.

That possibility matters because an assistant with access to your inbox, messages, purchasing behavior and other personal information creates a very different advertising proposition from a conventional chatbot.

The business model should be part of the permission decision too.

Browser agents show what better separation can look like

This permissions problem is not unique to Instinct.

Anthropic made Claude in Chrome generally available across paid Claude plans on August 26. It can work inside the user's existing browser session, including existing logins, and can take browser actions autonomously while a safety classifier checks each action against the request.

Anthropic simultaneously introduced a different architecture inside Cowork.

Claude's built-in browser is separate from the user's own browser. Anthropic says Claude cannot see the user's tabs, bookmarks or passwords by default. Login information can be imported selectively, while banking, email and single sign-on sites are excluded unless the user deliberately includes them.

Availability is still rolling out. Enterprise organizations can enable the built-in browser now, while Pro, Max and Team access is rolling out over the week of August 26 across the desktop app on macOS, Windows and Linux, with Linux marked beta.

That separation is a useful design clue.

Sometimes the agent genuinely needs your logged-in browser.

Sometimes it merely needs a browser.

Those should not automatically receive the same permissions.

Prompt injection remains part of the risk. A malicious instruction embedded in a webpage, email or other content can attempt to redirect a browser agent away from the user's intended task.

Anthropic says its latest safeguards materially reduce that exposure. In Anthropic's own evaluation, no attacks succeeded against Sonnet 5, Opus 5 or Mythos 5 when probes and its automatic approval safety classifier were enabled; Fable 5 recorded a 0.3% attack success rate, with Anthropic describing the successful cases as low severity. Those are vendor-run results rather than independent validation, and Anthropic still describes prompt injection as an evolving threat.

That is the right way to read the state of play.

Better controls are arriving. The problem is not solved.

The Choosely Permission Line

MCP connections, individual agent products and always-on assistants all involve permissions, but they answer different questions.

MCP asks what an external connection may access.

A product such as Grok Bot asks what one agent platform should be allowed to do.

The always-on assistant creates the category-level question:

How much authority should any persistent AI have over your digital life?

The answer should depend on the consequence of failure.

PermissionChoosely viewWhy
Research and monitoringGreenLow consequence and easy to verify
Reminders and personal briefingsGreenUseful persistent behavior with limited external effect
Calendar recommendationsGreenGood automation target when the user controls the actual change
Drafting messagesGreenAgent does the labor; user controls the external action
Changing calendar eventsConditionalUseful with confirmation or tightly bounded rules
Sending messages or emailConditionalMistakes affect other people, not just the user
Logged-in browser accessConditionalPowerful, but materially expands the attack and data surface
PurchasesConditionalRequire approval and explicit spending limits
Production-system changesConditional / RedOnly within tightly scoped environments and approval rules
Password or security changesRedHigh consequence and difficult to reverse
Financial transfersRedToo much downside for broad autonomous authority
Destructive deletionRedIrreversible action deserves explicit human control
Unlimited unattended spendingRedPersistence needs a budget as much as it needs a stop button

Grok Bot's own guidance lands in roughly the same neighborhood. Choosely's recent analysis found its documentation recommends approval boundaries around sending, publishing, purchasing, transferring money, deleting data, changing permissions and modifying production systems.

This is deliberately conservative.

The most dangerous agent failure may eventually stop looking like a hallucinated answer.

It may be a perfectly competent action that the user never intended to authorize.

Local versus cloud is becoming a real buying decision

OpenClaw makes this market considerably more interesting because the alternative to a deeply connected cloud assistant is no longer simply "do everything manually."

OpenClaw runs on the user's own machine, is open source and allows users to choose models and integrations while keeping its state locally.

That changes the trust boundary.

A local-first assistant makes more sense when control over stored context matters heavily, the user is comfortable maintaining infrastructure, model choice matters, and permissions need to remain around systems the user controls.

A managed cloud assistant makes more sense when convenience matters more than infrastructure control, polished integrations are important, and the user is comfortable with the provider's security, data and permission model.

Neither architecture earns an automatic safety badge.

An agent running locally with broad filesystem, shell, browser and credential access is still an agent with broad filesystem, shell, browser and credential access.

Local changes where the trust sits. It does not remove the trust requirement.

Always-on agents are already moving into work

It would also be a mistake to frame this entirely as a consumer-assistant story.

Grok Bot already offers persistent cloud agents for professional workflows. OpenAI's Persistent-mode experiment begins inside Codex. Claude Cowork increasingly combines files, tools and browser operation inside a persistent work environment.

The use cases are different, but the design problem is the same.

A work agent that can research overnight is useful.

One that can publish, send customer messages, change production infrastructure or spend money overnight is a different proposition.

Persistence amplifies both productivity and mistakes.

The more autonomous the worker becomes, the more important its workplace rules become.

Pricing changes when the AI keeps working

Always-on agents also change AI economics.

A conventional chatbot usually consumes resources when someone interacts with it.

A persistent agent may browse, monitor, retry, research, schedule, communicate and continue working long after the original prompt.

That makes budget control part of the permission system.

Meta has not announced Hatch pricing publicly, although Business Insider reports internal consideration of prices reaching roughly $200 per month.

OpenAI has not announced pricing for Persistent mode because the feature remains experimental.

Grok Bot already illustrates the broader issue. Persistent work runs against paid plan and usage limits, meaning the relevant metric is no longer simply the monthly subscription price. It is how much useful completed work the agent returns for the usage consumed.

Every persistent agent should therefore have the financial equivalent of permissions: visible consumption, bounded spending, approval before unusual cost, clear stop conditions and a hard ceiling the user understands.

"Continue until put to sleep" is compelling product language.

It becomes slightly less charming when nobody remembers who was supposed to turn the light off.

Who should actually use one now?

Always-on assistants make the most sense today for users with substantial amounts of reversible digital administration.

Founders managing inboxes and calendars, consultants coordinating research and follow-ups, operators running recurring monitoring work and power users who already supervise several AI tools have enough repetitive work to justify the setup.

The category is much less convincing where the work depends on unrestricted financial authority, highly confidential or regulated data, irreversible actions, poorly protected accounts or users who have no intention of reviewing activity and permissions.

An always-on assistant should reduce cognitive overhead.

If using one requires blindly trusting every connected account, the cognitive overhead has merely been converted into hidden risk.

Choosely verdict

The always-on assistant looks like a genuine next step for AI, not another label attached to the same chatbot.

Persistent context solves the repeated-context problem.

Tool access turns intelligence into action.

Proactivity can remove entire categories of administration rather than merely making them faster.

The winning product will not necessarily be the assistant that books dinner fastest.

It may be the one with the best trust architecture.

Where does it run? What does it remember? What can it access? Which actions require approval? Can permissions be separated? Can retained data actually be removed? Does the user get an audit trail? What happens when malicious instructions appear inside something the agent reads? What can it spend? And where is the kill switch?

OpenClaw, Instinct, Grok Bot, OpenAI's experiments and Meta's reported Hatch project offer different answers.

For now, the safest rule is straightforward:

Delegate reversible work aggressively. Delegate irreversible authority reluctantly.

The assistant can remember the restaurant.

It probably does not need the keys to the bank.

Frequently asked questions

What is an always-on AI assistant?

An always-on AI assistant maintains useful state between individual prompts and can continue or initiate work through memory, scheduled activity, connected tools or proactive behavior. It does not necessarily mean the underlying model is continuously generating output.

Is OpenAI Persistent mode available now?

No. OpenAI confirmed that it is testing Persistent mode for Codex, but it has not announced general availability.

What is Meta Project Hatch?

Project Hatch is a reported Meta personal-agent project described in an internal memo obtained by Business Insider. It reportedly uses its own computer, persistent memory and connected services to perform personal administrative work. Meta has not publicly launched Hatch or confirmed final pricing.

Is Instinct publicly available?

No. Instinct remains in private beta. It has nevertheless raised $350 million in total funding at a reported $2.5 billion valuation.

Is Grok Bot an always-on assistant?

It is a persistent work-agent platform rather than a general personal life assistant. Its Bots can operate on a managed cloud computer, run while the user's machine is closed and execute scheduled routines, making it one of the clearest currently shipped examples of persistent agent architecture.

Is a local AI assistant automatically safer than a cloud assistant?

No. Local operation can give the user greater control over state and infrastructure, but software with broad access to local files, browsers, credentials or command execution can still cause harm. Local architecture changes the trust boundary rather than eliminating it.

Should an AI assistant have access to my email?

Read access can be useful for search, summarization and monitoring. Sending, deleting or acting on messages creates a materially higher-risk permission level. For most users today, progressively granting access and keeping consequential external actions behind approval is the more defensible approach.

Keep your AI stack current

AI tools are changing faster than most people can reasonably monitor.

Choosely Stack Intelligence helps you save the tools you rely on and keep track of the changes that could affect whether they still belong in your stack.

Save your stack with Choosely →

The Change Brief

Get the week’s AI changes in one clear read

Pricing moves, tool launches, free-tier changes and practical stack updates, filtered for people who actually use these tools.

Stay ahead of AI without following it all day. We’ll send you what matters each week.

Continue reading

Related reads