Grok
xAI · grok.com
Grok is a hosted, proprietary assistant. It stands out for publishing its system prompts on GitHub and for a full account-data export as JSON, and owners can view and forget memories, opt out of training and delete data within 30 days. The agent itself cannot be exported or run independently, and runtime configuration, action logs, agent controls and advertising in answers are not documented enough to verify.
- System prompts published on GitHub
- Full xAI account-data export as ZIP of JSON
- Memory is visible, can be forgotten and toggled off
- Training toggle ('Improve the model') and Private Chat mode
- Deleted conversations removed within 30 days, with stated exceptions
- No exportable or self-runnable agent; hosted only
- Published prompts cannot be verified as the active configuration
- Privacy policy permits targeted advertising; ads in Grok answers announced by X
- No owner-held record of the agent's actions, and no open-source runtime
- Fixed xAI models; no local model option
- Agent approval gates and credential custody undocumented
All 34 findings
Consumer Grok on grok.com and the iOS/Android apps with an xAI account, including Memory, Private Chat, Tasks, Companions and Google connectors, under the xAI Consumer FAQ and Privacy Policy as published on 2026-09-27. Grok inside X and the xAI API not assessed.
Portable · Can you leave, and take the whole agent with you?
8%- P1Round-trip portability
Incomplete and not restorable: 'Download account data' exports account data and conversations as a ZIP of JSON without logic or configuration, and xAI offers no import.
Fail - P2Complete export
The account export contains account data and conversation history, but not the executable logic, runtime configuration or anything that identifies the agent, so much of what defines it stays with xAI.
Partial - P3Independent execution
Grok runs only on xAI's hosted service and current proprietary models; no exported artifact runs on an open-source runtime.
Fail - P4Identity continuity
The assistant's identity is the user's xAI or X account, and nothing lets others verify it is the same agent without xAI.
Fail - P5No kill switch
The agent exists only as an xAI-hosted service, so xAI controls its availability and features, and nothing exported runs independently.
Fail - P6Capability independence
Memory, Tasks, Companions and connectors are xAI service features and do not survive a move to another model or runtime.
Fail
Transparent · Can you see everything the agent is, with ordinary tools?
25%- T1Open storage format
The account export is JSON, an open format, but Grok's internal state storage is undocumented and the owner cannot access it directly.
Partial - T2No hidden instructions
xAI publishes Grok's system prompts in a public GitHub repository. Content injected at runtime, such as memories and tool results, is not fully shown, and the owner cannot confirm the published prompts are the ones in use.
Partial - T3No shadow memory
xAI's privacy policy lists delivering relevant content and targeted advertising among its uses of data, and allows retaining de-identified or pseudonymized conversation data after deletion. That data is outside the owner's inspectable state.
Fail - T4Complete action history
Conversation history is visible to the owner and included in the export, but xAI documents no complete history of tool calls and Task actions.
Partial - T5Readable logic
Prompts are published, but Grok's executable logic (tool orchestration, Tasks, Companions) is proprietary server-side code.
Fail - T6No third-party influence channel
X announced in 2025 that advertisers could pay for placement in Grok's answers, and xAI's privacy policy permits targeted advertising. No primary documentation confirms whether ads appear in consumer Grok today or whether owners can turn them off.
Unverified
Auditable · Can you reconstruct exactly what the agent did?
10%- A1No unrecorded actions
No durable record of consequential actions is available to the owner; the only visible record is conversation history, which the owner can delete.
Fail - A2Tamper evidence
Conversations can be deleted without any detectable trace, and no other way to detect changes to an action record is documented.
Fail - A3Separation from the audited
xAI does not document whether the agent layer can alter or delete records of its own actions.
Unverified - A4Readable with ordinary tools
The JSON export can be read with ordinary tools, but it is a conversation and account export, not an action audit trail.
Partial - A5Corroborated interactions
No record of the agent's exchanges with other agents or services is available to the owner, so nothing can be matched against a counterpart's record.
Fail
Verifiable · Can you prove the agent runs what it claims?
0%- V1Open, reproducible runtime
The Grok service runtime is proprietary. xAI has released some older model weights and publishes prompts, but not the assistant runtime.
Fail - V2Active config is inspectable config
Published prompts cover part of the configuration, but the owner cannot confirm that the served configuration (prompts, model routing, memory injection) matches what is inspectable.
Fail - V3Attributable messages
Recipients have no documented way to verify that a message came from this agent under its owner's authority, independently of xAI.
Fail - V4Independently checkable record
No action record with checkable integrity is exposed, so nothing can be verified with open tools independently of xAI.
Fail - V5Comparable state
Much of the agent's state (runtime configuration, memory injection, retained derived data) is held by xAI and not exposed, so the owner cannot verify whether it changed between two points in time.
Fail
Modifiable · Can you change anything, without asking?
25%- M1Instructions
The owner can read the published base prompts and add personal customizations and memories, but cannot rewrite the system instructions Grok runs with.
Partial - M2Memory
xAI states that memories are visible and can be forgotten, and memory can be turned off under Data Controls. Editing individual memories is not documented, and data retained outside memory cannot be managed.
Partial - M3Logic
The owner can define Tasks in natural language but cannot change Grok's underlying code or workflows.
Fail - M4Tools and permissions
The owner can connect or disconnect the integrations xAI offers, such as Google apps via OAuth, but cannot add arbitrary third-party tools in the consumer app.
Partial - M5Model choice
The consumer app offers only xAI's own Grok models; local or third-party models cannot be used.
Fail - M6No gatekeeping
Changes beyond the settings xAI exposes require xAI's own action, and some features depend on paid subscription tiers.
Fail
Controllable · Is your word final?
17%- C1Communication boundaries
No public documentation was found on whether owners can decide whom Grok's agentic features contact or through which channels, or how that would be enforced.
Unverified - C2Approval gates
No public documentation was found on approval gates for Grok Tasks or connector actions.
Unverified - C3Immediate halt
Owners can stop responses in the chat interface, but no primary documentation was found on immediately halting running or scheduled Tasks.
Unverified - C4Data sovereignty
Content is processed on xAI servers. Training use is controlled by an 'Improve the model' setting rather than an opt-in xAI documents, unauthenticated users in some regions cannot opt out, and voluntarily submitted feedback may still be used for training.
Fail - C5Credential custody
Google connections use OAuth, which the owner can revoke from their Google account, and xAI commits not to train on Google Apps content. The tokens are held by xAI, cannot be inspected in Grok, and cannot move with the agent.
Partial - C6Full deletion
Deleting conversations or the account removes data within 30 days, except data that has been de-identified or pseudonymized and disassociated from the account, or must be kept for safety, security or legal reasons.
Partial
Vendors and the public can dispute any finding with evidence. Disputes and their resolutions are published.