Elon Musk is once again shocking the public, this time by promising full compensation for losses if his AI agent Grok makes a mistake managing a client's bank account. However, a careful review of xAI's documents paints a different picture: the company's legal liability is capped at a laughable $100.
At the center of the discussion is an experiment that an investor under the handle Teslaconomics decided to conduct. He asked a direct question: has anyone already connected the Grok bot to their bank account? According to him, such an agent can track expenses, pay bills, and flag suspicious charges. The investor's enthusiasm was so great that he even questioned the need for a personal banker. However, his interlocutor expressed legitimate concerns: giving AI access to finances is a direct path to disaster.
Musk, unfazed, responded to the doubts and promised to refund the money if the bot makes a mistake. The beta version of the product launched on August 11. xAI explained that each agent operates around the clock on its own cloud server, visits websites like a regular person, and continues to act while the owner sleeps. This is an ambitious step that fits into Musk's global financial strategy, including the launch of the X Money service with direct transfers in June.
Legal Reality: Promises vs. Contract
Musk's promise sounds like insurance, but xAI's user agreement states it plainly: the results and actions of agents are provided "as is." The maximum claim amount cannot exceed the fees paid or $100—whichever is greater.
Given that access to the bot costs $30 per month under the SuperGrok plan, and the annual subscription is $360, that money looks like pocket change compared to potential account losses. Musk's response on X does not change the terms. Until xAI formalizes the guarantee in writing, any compensation remains at Musk's discretion.
The risks are compounded by U.S. banking regulations. Regulation E, which protects customers from unauthorized charges, does not apply if the owner themselves gave the bot access to the account. In that case, the charge is considered authorized, and fraud protection mechanisms will not kick in.
Real Threats: Prompt Injection and Attacks
Skeptics point to recent incidents. In May, a malicious NFT "hid" instructions that forced an AI to transfer money—a classic example of "prompt injection." As a result of an attack on the Bankr wallet linked to Grok, about $150,000 was drained. Later, roughly 80% of the stolen funds were recovered. A few weeks later, 14 more wallets on the same platform were affected, and Bankr promised to fully reimburse the losses. However, there is still no proven case of the Grok bot making a mistake with a real bank account.
The experiment with the Grok bot is partly advertising too: xAI wants to integrate the product into everyday financial management. Notably, the very first real mistake will show what Elon Musk's words are worth. The company can respond in two ways: either quietly refund all the money or publicly compensate that very $100 cap.
My analysis: This is a classic case where marketing outpaces legal and technical reality. Until AI agents have reliable mechanisms to defend against sophisticated attacks, trusting them to manage bank accounts is like playing Russian roulette with your own finances. Musk's words are merely a PR stunt not backed by any obligations. A sensible investor should assess risks, not promises.