Consumer AI Agents Just Went Enterprise.

Agent showdown: Grok Bot, Meta Muse, OpenAI dots, Microsoft Autopilot and OpenClaw as cloud contenders versus Hermes as the local challenger, comparing where each runs, entry cost and enterprise status

Between August 11th and September 29th, 2026, xAI, Meta, and OpenAI each shipped an always-on AI agent that gets its own cloud computer and works 24/7. In the same seven weeks, Microsoft renamed Scout to Autopilot and the OpenClaw project announced an Enterprise Edition. Customers who read my posts on running Hermes on a DGX Spark (here) keep asking me the same question: where does this leave Hermes?

TL;DR, Hermes is not an enterprise product and was never going to be one. It is still the best free, local, private agent I know of, and I'm going to keep using it. But enterprise buyers now have real choices. For most companies, the bigger risk this week is employees connecting their work mailbox to a free consumer agent.

What happened in seven weeks

  1. August 11: xAI released Grok Bot, the first "easy to create" agent. What was new was the dedicated cloud computer the agent uses to do its work.
  2. September 8: Meta released Muse (free to try). It is even simpler to set up, and it hit the top of Apple's US free app chart within days.
  3. September 25: Microsoft announced Autopilot, the new name for Scout, built on OpenClaw. It goes to private preview at the end of September.
  4. September 28: Meta announced a Meta Enterprise Platform for Muse, led by former MongoDB CEO CJ Desai.
  5. September 29: OpenAI released dots, and OpenClaw announced OpenClaw Enterprise (OCE) the same day.

The Scorecard

Agent Released Where it runs Entry cost Enterprise status
OpenClaw Nov 2025 Your own infrastructure Free, open source Enterprise Edition announced 9/29; v1.0 still in development
Grok Bot (xAI) 8/11/2026 Its own cloud computer SuperGrok subscription ($30/month) Enterprise waitlist only
Meta Muse 9/8/2026 Its own cloud computer Free to try Meta Enterprise Platform announced 9/28
OpenAI dots 9/29/2026 Its own cloud computer ChatGPT Pro ($100/month) or Business Premium Enterprise beta when the admin enables it; specialist dots in pilots
Microsoft Autopilot Announced 6/2 as Scout; renamed 9/25 Microsoft-managed cloud computer Usage-based billing Private preview
Hermes Feb 2026 Your hardware, or hosted; Bot Screen gives each bot its own Linux desktop Free (MIT license) None

Every one of them gets its own computer

Grok Bot started it. OpenClaw took me days of setup to get running, and I would not wish that on a business owner. Grok Bot and Muse got it down to a few clicks. Muse has no connector ecosystem yet, so OpenAI's answer with dots was a library of more than 4,000 app connectors. Even Hermes joined in: its new Bot Screen feature gives each bot its own desktop on a Linux server (more on that below).

If you are the CFO, here is what changed: an agent used to be a chat window, and now it is a worker with credentials. A worker with credentials needs an identity, a budget, and an audit trail. The consumer products skip that part, and the enterprise versions are scrambling to add it.

Autopilot is OpenClaw underneath

Microsoft's September 25th announcement says each Autopilot instance gets its own cloud computer, workspace, storage, and identity, and you can trigger it with an @mention in Teams, Outlook, or a document. Peter Steinberger, who created OpenClaw and joined OpenAI in mid-February, posted that day that his team had worked with Microsoft since March "to make the codebase ready for large-scale deployments." Microsoft's Omar Shahine said they are building Autopilot on OpenClaw with the OpenClaw Foundation "to make it a fantastic enterprise grade runtime."

Two things to know:

  1. Autopilot billing is usage-based, not a flat per-seat price. Budget for it the way you budget for Azure.
  2. In the same announcement, you can now @Copilot inside any Microsoft Teams chat. That's a quick way to try it!

In my opinion, this product will be renamed again. Microsoft renames products about every 12 months, and "Autopilot" collides with Windows Autopilot, which enterprise buyers already know as the Intune device-provisioning feature. They are not the same product. Expect confusion on your next licensing call.

Why did OpenClaw need an enterprise edition?

OpenClaw's own enterprise announcement is blunt. OpenAI's Kevin Lin wrote that "the default stance of IT in most organizations is to ban agentic platforms like OpenClaw altogether." Gartner called the original project an "unacceptable cybersecurity risk" for business users. OCE adds multi-tenancy, hard security boundaries, and governance and auditing, and Red Hat describes it as "Kubernetes for agents." Sponsors include OpenAI, Nvidia, Red Hat, and GitHub.

OCE has only been announced. Version 1.0 is still in development, so don't put it in a purchase plan yet.

OpenAI is also working with Microsoft to bring specialist dots under Agent 365, so the Microsoft governance layer may end up managing agents that Microsoft didn't build. If you already run Entra, Intune, and Defender, that's good news, because the controls you have today become the common denominator.

Where does Hermes fit?

Hermes was built by Nous Research and released under the MIT license in February 2026. It is in a different lane than everything above. In my opinion it is similar to OpenClaw but generally considered safer. The comparison I use with customers is Android vs. iPhone: Hermes is the hobbyist, tinker-friendly one, and the vendor products are the managed experience.

What Hermes does that the others don't:

  • It is free when you run it locally, and it can use local AI models, so your data never leaves your network. For incident response and regulated work, that's the reason we run it (here).
  • It learns new skills on its own. Its built-in learning loop writes skills from experience and improves them over time.
  • It is model-neutral. It works with OpenRouter, OpenAI, or your own endpoint, so there is no vendor lock-in.
  • It has a desktop app that feels a lot like Grok Bot, minus the subscription.
  • It now gets its own desktop. Nous Research just shipped Bot Screen (here). If your Hermes agent runs on a Linux server or cloud VM, each bot gets its own desktop with a browser, terminal, and apps, and you can watch it work live in the desktop app. When it hits a login, 2FA prompt, CAPTCHA, or payment step, you take control, finish that step, and hand the screen back. The bot keeps going after you close your laptop. This is a seriously cool upgrade for anyone running always-on agents!

What it does not have is the part enterprises are paying for: a vendor-managed identity, central policy, and an audit trail you can hand to an auditor.

Bot Screen does not change that. Nous Research's own documentation says it plainly: "Screens are work surfaces, not security boundaries." Every bot on the same server shares that server's user account, files, and network, and the browser's debugging port can be reached by any local user on the machine. The docs recommend putting bots on separate hosts if that isolation matters to you. I agree. Also keep in mind that when you sign in to a site for the bot, the bot keeps that session afterward.

Also, on Windows, Defender will probably flag it. The alert is on uv.exe, the Python package manager that Hermes bundles. The project's GitHub issue (here) documents it as a false positive, but your SOC will still see the alert. Exclude the Hermes folder deliberately, and write down why.

If your priority is... Best fit today
Microsoft 365 shop, governance and audit Autopilot, with Agent 365 as it matures
ChatGPT-centric team, wide app coverage OpenAI dots (enterprise beta)
Data must stay on your network, lowest cost Hermes with a local model
Open standard you can host and control Watch OCE once v1.0 ships

What I would do this quarter

  1. Assume shadow agents already exist. Muse is free and hit the top of the App Store. Your people can connect their work email and calendar to it today. Decide your policy before you discover the exceptions, and enforce it with the Intune and Defender controls you already own.
  2. If you are a Microsoft shop, pilot Autopilot with a small group once you have access. Set a usage budget first, because the billing is metered.
  3. Keep Hermes for the lab and for local-model work, which is how we use it at Patriot. Treat it as unmanaged software: a dedicated identity, least privilege, and no access to production mailboxes. If you use Bot Screen, give each bot its own server, and do not use the takeover button to sign the bot in to anything you would not hand a new intern.
  4. Re-evaluate in 90 days. OCE v1.0, Autopilot general availability, and enterprise pricing from OpenAI, xAI, and Meta will all have moved by then.

Need help building an AI Governance policy? Try Patriot's AIShield365 for free at https://www.aishield365.ai, or Email us at Hello At PatriotConsultingTech.com

Sources and references:

About the author. Joe Stocker is the Founder and Chief Technical Officer of Patriot Consulting, a former Microsoft Security MVP (2020-2026), and author of the book "Securing Microsoft 365." In his spare time Joe volunteers with several Microsoft programs including Microsoft's Defending Democracy (AccountGuard) program, Microsoft Tech for Social Impact, and the Microsoft Software and Systems Academy (MSSA), which serves military service members desiring to transition into the civilian workspace.

Note: The author created this article with assistance from AI. Learn more