Skip to content
Agents for Humanity
Public draft. All results are preliminary desk assessments against criteria v1.0, updated 27 Sept 2026. No agent has been certified yet. How we assess
AssistanthostedProprietary

Grok

xAI · grok.com

Grok is a hosted, proprietary assistant. It stands out for publishing its system prompts on GitHub and for a full account-data export as JSON, and owners can view and forget memories, opt out of training and delete data within 30 days. The agent itself cannot be exported or run independently, and runtime configuration, action logs, agent controls and advertising in answers are not documented enough to verify.

Strengths
  • System prompts published on GitHub
  • Full xAI account-data export as ZIP of JSON
  • Memory is visible, can be forgotten and toggled off
  • Training toggle ('Improve the model') and Private Chat mode
  • Deleted conversations removed within 30 days, with stated exceptions
Gaps
  • No exportable or self-runnable agent; hosted only
  • Published prompts cannot be verified as the active configuration
  • Privacy policy permits targeted advertising; ads in Grok answers announced by X
  • No owner-held record of the agent's actions, and no open-source runtime
  • Fixed xAI models; no local model option
  • Agent approval gates and credential custody undocumented
Evidence

All 34 findings

Consumer Grok on grok.com and the iOS/Android apps with an xAI account, including Memory, Private Chat, Tasks, Companions and Google connectors, under the xAI Consumer FAQ and Privacy Policy as published on 2026-09-27. Grok inside X and the xAI API not assessed.

Portable · Can you leave, and take the whole agent with you?

8%
  • P1
    Round-trip portability

    Incomplete and not restorable: 'Download account data' exports account data and conversations as a ZIP of JSON without logic or configuration, and xAI offers no import.

    Fail
  • P2
    Complete export

    The account export contains account data and conversation history, but not the executable logic, runtime configuration or anything that identifies the agent, so much of what defines it stays with xAI.

    Partial
  • P3
    Independent execution

    Grok runs only on xAI's hosted service and current proprietary models; no exported artifact runs on an open-source runtime.

    Fail
  • P4
    Identity continuity

    The assistant's identity is the user's xAI or X account, and nothing lets others verify it is the same agent without xAI.

    Fail
  • P5
    No kill switch

    The agent exists only as an xAI-hosted service, so xAI controls its availability and features, and nothing exported runs independently.

    Fail
  • P6
    Capability independence

    Memory, Tasks, Companions and connectors are xAI service features and do not survive a move to another model or runtime.

    Fail

Transparent · Can you see everything the agent is, with ordinary tools?

25%
  • T1
    Open storage format

    The account export is JSON, an open format, but Grok's internal state storage is undocumented and the owner cannot access it directly.

    Partial
  • T2
    No hidden instructions

    xAI publishes Grok's system prompts in a public GitHub repository. Content injected at runtime, such as memories and tool results, is not fully shown, and the owner cannot confirm the published prompts are the ones in use.

    Partial
  • T3
    No shadow memory

    xAI's privacy policy lists delivering relevant content and targeted advertising among its uses of data, and allows retaining de-identified or pseudonymized conversation data after deletion. That data is outside the owner's inspectable state.

    Fail
  • T4
    Complete action history

    Conversation history is visible to the owner and included in the export, but xAI documents no complete history of tool calls and Task actions.

    Partial
  • T5
    Readable logic

    Prompts are published, but Grok's executable logic (tool orchestration, Tasks, Companions) is proprietary server-side code.

    Fail
  • T6
    No third-party influence channel

    X announced in 2025 that advertisers could pay for placement in Grok's answers, and xAI's privacy policy permits targeted advertising. No primary documentation confirms whether ads appear in consumer Grok today or whether owners can turn them off.

    Unverified

Auditable · Can you reconstruct exactly what the agent did?

10%
  • A1
    No unrecorded actions

    No durable record of consequential actions is available to the owner; the only visible record is conversation history, which the owner can delete.

    Fail
  • A2
    Tamper evidence

    Conversations can be deleted without any detectable trace, and no other way to detect changes to an action record is documented.

    Fail
  • A3
    Separation from the audited

    xAI does not document whether the agent layer can alter or delete records of its own actions.

    Unverified
  • A4
    Readable with ordinary tools

    The JSON export can be read with ordinary tools, but it is a conversation and account export, not an action audit trail.

    Partial
  • A5
    Corroborated interactions

    No record of the agent's exchanges with other agents or services is available to the owner, so nothing can be matched against a counterpart's record.

    Fail

Verifiable · Can you prove the agent runs what it claims?

0%
  • V1
    Open, reproducible runtime

    The Grok service runtime is proprietary. xAI has released some older model weights and publishes prompts, but not the assistant runtime.

    Fail
  • V2
    Active config is inspectable config

    Published prompts cover part of the configuration, but the owner cannot confirm that the served configuration (prompts, model routing, memory injection) matches what is inspectable.

    Fail
  • V3
    Attributable messages

    Recipients have no documented way to verify that a message came from this agent under its owner's authority, independently of xAI.

    Fail
  • V4
    Independently checkable record

    No action record with checkable integrity is exposed, so nothing can be verified with open tools independently of xAI.

    Fail
  • V5
    Comparable state

    Much of the agent's state (runtime configuration, memory injection, retained derived data) is held by xAI and not exposed, so the owner cannot verify whether it changed between two points in time.

    Fail

Modifiable · Can you change anything, without asking?

25%
  • M1
    Instructions

    The owner can read the published base prompts and add personal customizations and memories, but cannot rewrite the system instructions Grok runs with.

    Partial
  • M2
    Memory

    xAI states that memories are visible and can be forgotten, and memory can be turned off under Data Controls. Editing individual memories is not documented, and data retained outside memory cannot be managed.

    Partial
  • M3
    Logic

    The owner can define Tasks in natural language but cannot change Grok's underlying code or workflows.

    Fail
  • M4
    Tools and permissions

    The owner can connect or disconnect the integrations xAI offers, such as Google apps via OAuth, but cannot add arbitrary third-party tools in the consumer app.

    Partial
  • M5
    Model choice

    The consumer app offers only xAI's own Grok models; local or third-party models cannot be used.

    Fail
  • M6
    No gatekeeping

    Changes beyond the settings xAI exposes require xAI's own action, and some features depend on paid subscription tiers.

    Fail

Controllable · Is your word final?

17%
  • C1
    Communication boundaries

    No public documentation was found on whether owners can decide whom Grok's agentic features contact or through which channels, or how that would be enforced.

    Unverified
  • C2
    Approval gates

    No public documentation was found on approval gates for Grok Tasks or connector actions.

    Unverified
  • C3
    Immediate halt

    Owners can stop responses in the chat interface, but no primary documentation was found on immediately halting running or scheduled Tasks.

    Unverified
  • C4
    Data sovereignty

    Content is processed on xAI servers. Training use is controlled by an 'Improve the model' setting rather than an opt-in xAI documents, unauthenticated users in some regions cannot opt out, and voluntarily submitted feedback may still be used for training.

    Fail
  • C5
    Credential custody

    Google connections use OAuth, which the owner can revoke from their Google account, and xAI commits not to train on Google Apps content. The tokens are held by xAI, cannot be inspected in Grok, and cannot move with the agent.

    Partial
  • C6
    Full deletion

    Deleting conversations or the account removes data within 30 days, except data that has been de-identified or pseudonymized and disassociated from the account, or must be kept for safety, security or legal reasons.

    Partial
Something wrong or out of date?

Vendors and the public can dispute any finding with evidence. Disputes and their resolutions are published.

Dispute a finding