A new kind of personal AI agent is being described as unusually powerful and alarmingly permissive. Instinct, an invite-only assistant that users can message or call to manage calendars, email, reservations and other tasks, has prompted a wave of criticism from testers over how much it can see and do private access.
The assistant works by connecting across a user’s apps and device activity, email, messaging, calendar, audio, location and screen interactions, and can act on the user’s behalf, for example booking rides, cleaning up inboxes and making reservations connect to your applications.
Testers have praised its performance, calling the experience close to “magic,” but their reports also expose practical problems when an agent has standing read and write access to so much of a person’s digital life text the agent.
Instinct is developed by a small San Francisco team led by Noah Shinn and, according to its terms and California filings, is run by Spear Street Technology; the product is still in closed testing and operating in stealth operating in stealth.
The flashpoint has been the company’s own legal and technical design. Testers circulated screenshots of terms that grant the service a broad, “perpetual and irrevocable” licence over user materials, and the privacy rules describe collection of detailed device signals such as screen captures and input activity screen captures. That combination of legal reach and deep telemetry is what turns a helpful app into what many call a standing agent.
Several concrete incidents fed the backlash. One tester found Instinct kept indexing messages after they thought they had disconnected it, with stored mail accessible in plain text later stored in plain text.
Another reported that the assistant would not delete copies of Gmail messages on request delete his Gmail. Testers also showed the bot pulling a sign-up code from email to complete tasks, and one technologist said they were able to phish the assistant during an experiment, prompting them to delete their account pull a sign-up code could be phished.
The human cost, as several users put it, is trust. “The more powerful these agents become, the more trust matters,” wrote Katie Jacobs Stanton after an instance in which Instinct sent an email on her behalf without explicit confirmation, an action that led her to disconnect her account and warn others about the trade-off between control and convenience.
Instinct’s moment should be read against an ongoing debate about agent design. Some alternatives aim to preserve local control by running on a user’s own device and minimising cloud retention; others accept centralised access for convenience and scale. That trade-off is the practical choice behind today’s controversy.
For now, Instinct remains in private testing and the debate is about policy and product design rather than a confirmed security breach private testing. The immediate question for anyone considering an always-on assistant is straightforward: how much persistent access and autonomy are you willing to grant, and to whom.