Blog · 8 October 2026

Bots vs agents: what's the difference and why bots are the future

An agent is a model in a loop inside your session. A bot is an agent with its own computer, memory, schedule and identity. Why we think bots win.

AIAgentsDeveloper toolingGovernance

Short answer: an AI agent is a model running tools in a loop, usually inside someone's session: a terminal, an IDE or a chat tab. A bot is an agent that has been given its own computer. It has a machine or sandbox of its own, a file system, a browser, a scoped set of credentials, memory that outlives the conversation, a schedule and an identity. That means it can keep working after you close the laptop, hold a task for days and take delegation like a teammate.

At Spectrum Web Co, our position is that bots are where agentic AI is heading, especially for teams. Here's the case, the evidence from 2026, our ranking of CLI coding agents, the governance a bot needs and where our argument is weakest.

01 / 09

What is an AI agent?

The most useful short definition we know is Simon Willison's: "An LLM agent runs tools in a loop to achieve a goal." Anthropic draws a similar line in Building effective agents, separating workflows, where "LLMs and tools are orchestrated through predefined code paths", from agents, which "dynamically direct their own processes and tool usage".

In practice, most agents people use today live inside a session. You open Claude Code or Codex CLI in a terminal, give it a task, and it reads files, runs tests and edits code until it's done or stuck. The agent borrows everything from you: your machine, your shell, your credentials and your attention. When the session ends, most of its working context goes with it.

That isn't a criticism. Session agents are the right tool for a lot of work. But an agent in a session is a power tool, and someone has to be holding it.

02 / 09

What is a bot, and how is it different from an agent?

"Bot" is an old word that used to mean a scripted chatbot. We use it differently, and increasingly so does the industry: SpaceXAI (formerly xAI) calls its always-on agents Grok Bots, Manus sells a cloud machine that "runs your bots" around the clock, and Hermes Agent ships a Bot Mode.

Our definition: a bot is a persistent, always-on agent with its own computer. Concretely, it owns seven things a session agent usually borrows:

  1. A machine: its own virtual machine, container or sandbox, not your laptop.
  2. A file system that persists between tasks.
  3. A browser it can drive, ideally separate from your personal logins.
  4. A credential scope: tokens issued to the bot for the systems it needs, and nothing more.
  5. Memory that outlives a single conversation.
  6. A schedule and triggers, so work starts on a timer, a webhook or a message, not only when you type.
  7. An identity: a name, an account and an audit trail, so its actions are attributable to it rather than to you.
Agent (in a session) Bot (with its own computer)
Where it runs Your terminal, IDE or chat tab Its own VM, container or cloud sandbox
Lifetime Until the session ends Persistent, resumes across tasks
What starts work You, typing a prompt A schedule, webhook, message or you
Credentials Yours, borrowed Scoped to the bot
Memory Mostly the context window Durable memory and files
Identity Acts as you Its own account and audit trail
Supervision You watch in real time Approval gates and review afterwards
Best for Exploratory, interactive work Recurring, long-running, delegated work

The difference isn't the model. The same model can power both. The difference is the environment, and the environment is what turns a power tool into a teammate.

03 / 09

What does "a bot with its own computer" look like in practice?

This isn't hypothetical. Over 2026, almost every major lab shipped some version of it:

  • SpaceXAI Grok Bot (announced in beta on 11 August 2026, and now generally available for Enterprise and for teams on Cursor and Grok plans). SpaceXAI describes it as "your team of always-on agents" and says plainly that "Bots have their own computer". Per the product page, every Grok Bot on an account shares one persistent cloud computer, so bots can share files, a browser and logins and hand work to each other. You can show a bot a task once and it saves the steps as a routine, and it comes back when something needs your approval.
  • Google Gemini Spark. Google says Spark "works in the background 24/7, even if your phone and laptop are turned off", with native connections to Gmail, Calendar, Drive and Docs, reusable skills and schedules, and a design that checks with you before major actions. Google announced its Australian rollout to Google AI Pro subscribers on 29 July 2026.
  • OpenAI workspace agents (22 April 2026). Codex-powered agents that "run in the cloud, so they can keep working even when you're not", run on a schedule and can be deployed in Slack. The lineage goes back to ChatGPT agent in July 2025, which OpenAI said did work "using its own virtual computer".
  • Anthropic. Claude Code routines run on Anthropic-managed cloud infrastructure "so they keep working when your laptop is closed", triggered by a schedule, an API call or a GitHub event (currently a research preview). For teams building their own, Claude Managed Agents provide a hosted harness with an Anthropic-managed or self-hosted sandbox, persistent file systems and cron-scheduled deployments (in beta).
  • Manus, which Meta acquired in December 2025. Its Cloud Computer, launched on 30 April 2026, is "a dedicated machine in the cloud that runs your bots, Python scripts, and software around the clock", and it's persistent. With Manus 2.0 in late September, Manus previewed Cue, an early-access app where agents get their own email, phone number, wallet and computer. That's the identity piece of the puzzle.
  • Perplexity Computer runs each task "in an isolated compute environment" with a real file system and browser, and Perplexity's Mac app pitches a Mac mini as an always-on device where agents work 24/7.

Read side by side, the convergence is obvious. Everyone is adding the same four things to the agent loop: a persistent environment, a trigger other than a human typing, memory, and an approval path back to a person. That's a bot.

04 / 09

Which open-source bots and agent frameworks should you know?

You don't need a vendor to run a bot. These are the open-source projects we'd look at first (GitHub stars rounded, 8 October 2026).

Project Licence What it is Bot traits
OpenClaw (~390k stars) MIT Personal assistant that runs on your own hardware and talks through WhatsApp, Telegram, Slack, Discord, iMessage and more Cron jobs, a dedicated browser, memory, optional Docker sandboxing
Hermes Agent (~250k) MIT Nous Research's self-improving agent, with memory and skills it writes for itself Built-in cron, one gateway for 20+ chat platforms, seven terminal backends including Docker, SSH, Modal and Daytona
OpenCode (~212k) MIT Open-source terminal coding agent Any LLM provider, a read-only plan agent, server and SDK
OpenHands (~90k) MIT Self-hosted control centre for coding agents A Docker container per conversation; can run Claude Code, Codex, Gemini or any ACP agent
oh-my-pi (omp) (~34k) MIT Coding agent forked from Mario Zechner's Pi LSP checks on every write, subagents in isolated worktrees, 60+ providers

OpenClaw is the clearest open-source example of the bot pattern. It went through several names, including Clawdbot and Moltbot, before settling on OpenClaw in late January 2026. In February its creator, Peter Steinberger, announced he was joining OpenAI and that a non-profit foundation would steward the project (Wikipedia). It's also a cautionary tale, which we come back to below.

Hermes Agent is where we'd send a developer who wants to understand bots. Its docs describe it as "not tied to your laptop": it can run on a cheap cloud server, a GPU cluster or serverless infrastructure, hibernating when idle.

Disclosure: our own open-source Omega desk is built on the Hermes Agent runtime and the oh-my-pi harness, and Agent Swarm is open source too.

05 / 09

How do the CLI coding agents rank in October 2026?

This is Spectrum Web Co's opinionated ranking as of October 2026, not a benchmark. We haven't run controlled evaluations. It reflects public documentation checked on 8 October 2026 and our experience building tooling on several of these agents. Our own tools support Claude Code, Grok Build, Hermes Agent and Omp, so weigh our view accordingly.

We judged each agent on six criteria, weighted by judgement rather than formula, with the first two counting most:

  1. Path to a bot: can it run headless, in the cloud, on a schedule or on a trigger?
  2. Safety controls: sandboxing, permission modes and approval gates.
  3. Tool use: MCP, ACP, hooks, skills and subagents.
  4. Model choice: one vendor's models, or many?
  5. Openness: licence and self-hosting.
  6. Ecosystem: IDE, desktop, chat and CI surfaces.
# Agent (maker) Open source? Why it ranks here Watch out for
1 Claude Code (Anthropic) No MCP, subagents, hooks, skills and plugins; an OS-enforced Bash sandbox; the clearest path from terminal to bot via cloud sessions, routines, Slack and the Agent SDK Proprietary licence, built for Claude models; routines are a research preview
2 Codex CLI (OpenAI) Yes, Apache-2.0 The safest defaults we've seen: sandboxed by default with network off, OS-level isolation on macOS, Linux and Windows, plus MCP, subagents and Codex Cloud Cloud features tie you to OpenAI's plans
3 Hermes Agent (Nous Research) Yes, MIT The most bot-native open agent: durable memory, self-written skills, cron, 20+ chat platforms, seven terminal backends and many model providers You run and secure it yourself, and the surface is broad
4 Grok Build (SpaceXAI) Yes, Apache-2.0 Plan mode, parallel subagents in their own worktrees, MCP, hooks, skills, headless -p, full ACP, sandboxing and custom models Launched as an early beta in May 2026 and still changing fast, with frequent releases
5 OpenCode (anomalyco) Yes, MIT Any provider, a read-only plan agent beside a build agent, MCP, LSP, ACP and a server for embedding Pair it with your own sandbox
6 Copilot CLI (GitHub) No Anthropic, OpenAI and Google models, GitHub's MCP server built in, parallel subagents, plan mode and admin policy Autopilot mode skips approval stops
7 omp (oh-my-pi, can1357) Yes, MIT LSP on every write, typed results from worktree subagents, 60+ providers, and it inherits MCP servers from other tools Young and fast-moving
8 Antigravity CLI (Google) Not stated (Gemini CLI is Apache-2.0) Gemini CLI's successor: skills, hooks, subagents, plugins and background multi-agent runs Google warned it wouldn't have 1:1 feature parity with Gemini CLI at first
9 OpenHands Yes, MIT A Docker container per conversation and the ability to run other agents More control centre than CLI
10 Aider Yes, Apache-2.0 Still a great pair programmer: auto-commits, a repo map and almost any model, including local ones Human-paced by design; latest release 0.86.2 in February 2026

Two notes. Google stopped serving Gemini CLI requests for Google AI Pro and Ultra subscribers on 18 June 2026 (it stays available through paid Gemini API keys), so Antigravity CLI takes its place here. And the gap between first and fifth is smaller than a table suggests: any of the top five can do serious work.

06 / 09

What are the risks of giving an AI bot its own computer?

Everything that makes a bot useful also makes it dangerous. Simon Willison's "lethal trifecta" is the clearest way to see it: "access to your private data", "exposure to untrusted content" and "the ability to externally communicate". A bot with its own browser, inbox and schedule has all three, all the time, often with nobody watching.

The vendors say so themselves. Anthropic's computer use docs recommend "a dedicated virtual machine or container with minimal privileges", a domain allowlist and human confirmation for consequential decisions. Its Cowork safety guide says unattended scheduled tasks need extra care "because you can't monitor these tasks in real time". In open source, The Register's report on OpenClaw 2.0 (31 August 2026) noted that its new sandbox for untrusted code is "turned off by default" and that Secret Store values "are not encrypted at rest", and a Cisco blog post warned that "a malicious or poorly vetted skill could lead to data exfiltration, token theft, or supply chain issues".

There's an identity gap, too. Anthropic's docs are candid that anything a Claude Code routine does through your connected GitHub identity or connectors "appears as you". Until a bot has its own identity, its actions look like yours in the audit log.

The controls we'd insist on:

  • A sandbox per bot. One VM or container per bot, disposable where possible. Agent Substrate gives every agent its own sandbox while sharing memory, skills and a ledger.
  • Least-privilege identity. Give the bot its own accounts and short-lived tokens. Never hand it your personal session.
  • Default-deny egress. Open only the domains the job needs.
  • Fail-closed gates. In Agent Swarm, a gate opens only when a result can be proven; failed work gets at most two automatic retries, then escalates to a human. Autonomy levels L0 to L4 are enforced by runtime policy, not by prompt.
  • Humans on irreversible actions: merges, releases, payments, deletions and external emails.
  • An audit trail outside the terminal. Every claim, dispatch and result written to a ledger, so you can answer "which bot did this, and why?"
  • A review rhythm. Read transcripts. Claude Code's docs note that a green run status "does not mean the task in your prompt succeeded".

For Australian organisations, the National AI Centre's Guidance for AI Adoption sums up governance in six practices. Two matter most here: "Decide who is accountable" and "Maintain human control". A bot can do the work. A named person still owns it.

07 / 09

When is an agent better than a bot?

Our thesis has real counterpoints, and we'd rather state them than have you find them in production:

  • Most work is still interactive. Debugging, exploring a codebase and designing a feature all benefit from a human steering in real time. In a session, that's a feature, not a limitation.
  • Always-on means always exposed. A bot that never sleeps is an attack surface that never sleeps.
  • Costs run while you sleep. Anthropic notes that multi-step Cowork tasks use more of your usage than a quick question, and that auto mode consumes more of your limit than the other modes. A busy bot can burn budget quietly.
  • Long horizons drift. The longer a bot runs unsupervised, the more a small misunderstanding compounds. Planning up front and gating every handoff reduce this, but don't remove it.
  • Lock-in. Hosted bots tie memory, routines and identity to one vendor. Open protocols (MCP, ACP) and open-source runtimes are the hedge.
  • Accountability doesn't delegate. "Treat it like a teammate" is a metaphor, not an org chart.

So our claim is narrower than "bots replace agents". Agents are how you work with AI; bots are how you delegate to it. For teams, delegation is where the leverage is.

08 / 09

How should a team start with bots?

  1. Start with agents in sessions. Get comfortable with one CLI agent and list the tasks you keep handing it.
  2. Pick one bot-shaped job. Recurring, well defined, low risk and reversible: a nightly dependency audit, docs drift checks or overnight test triage.
  3. Plan before it runs. A vague brief is fine in a session and dangerous unattended. Ultrathink turns prompts into specs and asks the clarifying questions up front.
  4. Give it a computer and an identity. Its own sandbox, its own scoped credentials and default-deny network access.
  5. Gate the output. Route everything through review. Humans keep the merge and release buttons.
  6. Make it attributable. Shared memory and a ledger, so every result traces back to the bot and the request that produced it.
  7. Measure, then widen. Run it for a few weeks, check what it got right and wrong, and only then raise its autonomy.

KanbanOS puts planning, a shared substrate, a gated SDLC swarm and a board humans can operate in one system. If you'd like a team to design the gates and roll out your first bots with you, that's what Ship a Product is for: book a meeting and bring the job you'd delegate first. More on agentic delivery is on the blog.

FAQ

Questions, answered.

01

What is the difference between an AI bot and an AI agent?

An AI agent is a model that runs tools in a loop to reach a goal, usually inside someone's session, such as a terminal, an IDE or a chat tab, using that person's machine and credentials. An AI bot, as we use the term, is a persistent agent with its own computer. It has its own sandbox or virtual machine, file system, browser, scoped credentials, durable memory, schedule and identity. The same model can power both. The difference is the environment, which lets a bot keep working when you close your laptop and take delegated work like a teammate.

02

Is an AI bot just a chatbot?

No. A chatbot answers messages in a conversation and stops when the conversation stops. An AI bot in the 2026 sense is an always-on agent that does work. It runs on its own machine, starts tasks from a schedule, webhook or message, keeps files and memory between tasks, and comes back to a person when it needs approval. Products such as SpaceXAI's Grok Bot, Google's Gemini Spark and Manus's Cloud Computer follow this pattern. Many still have a chat interface, but chat is how you talk to them, not what they are.

03

What does it mean for an AI bot to have its own computer?

It means the bot runs in an environment that belongs to it rather than borrowing yours. Usually that is a cloud virtual machine, container or sandbox with a persistent file system, a browser the bot can drive, and network access limited to what the job needs. SpaceXAI (formerly xAI) says every Grok Bot on an account shares one persistent cloud computer, and Anthropic's Claude Managed Agents run sessions in an Anthropic-managed or self-hosted sandbox with persistent file systems. Because the work happens there, it continues when your device is off.

04

Is it safe to let an AI bot run unattended?

It can be, if the controls are designed for unattended work. An always-on bot often has private data, untrusted input and a way to communicate externally at the same time, which makes prompt injection a real risk. Give each bot its own sandbox and its own least-privilege credentials, restrict network egress to an allowlist, make quality gates fail closed, keep humans approving irreversible actions such as merges, payments and deletions, and record every action in an audit trail. Start with low-risk, reversible jobs and raise autonomy only as the bot earns trust.

05

Which CLI coding agent is best in October 2026?

In Spectrum Web Co's opinionated ranking as of October 2026, Claude Code ranks first, followed by OpenAI's Codex CLI, Nous Research's Hermes Agent and SpaceXAI's Grok Build. We weighed six criteria, favouring each tool's path to running as a bot and its safety controls, then tool use, model choice, openness and ecosystem. This is a judgement based on public documentation and our own use, not a benchmark. The best agent for your team depends on your models, security requirements and whether you need open source.

06

Are there open-source AI bots I can self-host?

Yes. OpenClaw is an MIT-licensed personal assistant that runs on your own hardware and works through chat apps such as WhatsApp, Telegram and Slack, with cron jobs and an optional Docker sandbox. Nous Research's Hermes Agent, also MIT-licensed, adds durable memory, self-improving skills, a built-in cron scheduler and backends from Docker to SSH and serverless sandboxes. OpenHands runs each conversation in its own Docker container. Self-hosting gives you control, but you also own the security work, so enable sandboxing and review third-party skills before installing them.

07

When should I use an agent instead of a bot?

Use a session agent for interactive, exploratory work where you want to steer in real time, such as debugging, exploring an unfamiliar codebase or designing a feature. You see every step, approve commands as they happen and catch misunderstandings early, at low cost and low risk. Use a bot for recurring, well-defined work that should happen whether or not you are at your desk, such as nightly dependency audits, alert triage or weekly reports. Most teams need both: agents for working with AI, bots for delegating to it.

08

How should a team start using AI bots?

Start with one recurring, low-risk and reversible job that you already do by hand, such as a weekly docs check or overnight test triage. Write the task down as a self-contained brief, give the bot its own sandbox and its own scoped credentials, and route its output through review rather than straight to production. Keep humans on merges and releases, log every action, and measure results for a few weeks before widening its scope. If you want help designing the gates and the rollout, Spectrum Web Co's Ship a Product service covers it.