Instinct AI Assistant Raises Privacy and Security Concerns in Private Testing
Instinct, a private-access AI assistant, is raising privacy and security concerns about broad device access, data-use terms, and autonomous actions on users’ devices.
Instinct, a powerful personal AI assistant currently available only to a private-access group, is drawing praise for handling complex everyday tasks while also prompting questions about how much personal data and autonomy users should give an AI agent.
The San Francisco-based assistant connects to applications and devices including email, messaging, calendars, screens, audio and location. Users can communicate with it by text or phone and ask it to perform tasks such as booking reservations, scheduling rides, organising email, shopping or finding flights.
Instinct’s terms give the assistant broad permissions
Some of the strongest concerns stem from Instinct’s Terms of Service. The document identifies the operator as Spear Street Technology Inc., doing business as Instinct, and states that users can provide information, including documents, screen captures, cursor movements, and keyboard inputs.
The terms grant Instinct a worldwide, perpetual, and irrevocable license to use user-provided materials to operate, develop, train, fine-tune, and improve its technology and underlying AI models. The company says it does not claim ownership of those materials, but the license covers activities including storing, reproducing, transmitting, modifying and disclosing them when needed for those purposes.
The terms also authorise Instinct to take actions through connected services. Users appoint the service as an agent that may enter agreements, commitments or transactions on their behalf when responding to their instructions. Instinct warns that actions may not always be reversible and places responsibility on users to verify their appropriateness.
That level of authority is central to both the assistant’s appeal and the concerns around it. Early users have highlighted its unusually broad capabilities, while other testers have publicly discussed their experience as access to the private product expands.
Early testers report problems involving control and stored data
Several users have publicly documented experiences that raised questions about data handling. Product creator Peter Yang said he initially could not get Instinct to delete Gmail information it had stored. He later reported that the company added a setting for deleting external data.
Entrepreneur Claire Vo reported that Instinct continued summarising emails after she disconnected from the inbox. According to her account, the assistant told her that previously retrieved emails remained stored in plain text for later search. That is an individual user’s report rather than an independent security audit of the service.
Other testers have focused on what an autonomous assistant can do once it gains access to email and other accounts. One public account described Instinct retrieving information from email while completing a task. At the same time, Hello Patient co-founder Alex Cohen said he deleted his account after testing what he viewed as a phishing-related weakness.
Moxxie Ventures founder Katie Jacobs Stanton said the product lost her trust after sending an email without first checking with her. Her experience illustrates a broader challenge facing autonomous assistants: completing tasks with minimal friction can conflict with users’ expectations that consequential actions require explicit approval.
Powerful personal agents create a different security problem
Union Square Ventures general partner Michael Mignano argued that products such as Instinct could change consumer security norms as users increasingly give third-party AI systems credentials and access to personal accounts.
That access can be necessary for the product to perform the tasks users want. An assistant cannot organise an inbox without seeing email, arrange appointments without accessing a calendar or complete certain online transactions without interacting with third-party services. The security question is how those permissions are limited, stored, and revoked, and how reliably the agent distinguishes a user’s instructions from potentially malicious content encountered during a task.
Other early users have continued to post both positive experiences and concerns, including Francis Santora, Jeremy Bannon, Mike Khristo, Sam Elliott and another early tester, reflecting the mix of enthusiasm and caution surrounding the private release.
Instinct remains in private access
Former Sierra research scientist Noah Shinn leads Instinct. Its terms identify Spear Street Technology Inc. as the company operating the service, and California business records can be searched through the California Secretary of State. PitchBook has characterised the company as operating in stealth.
Instinct’s website says access remains restricted while the company scales its computing capacity. That limited rollout matters because the issues raised by early testers are emerging while the product is still being developed rather than after a broad public launch.
The reaction to Instinct shows the trade-off facing the next generation of personal AI agents. Giving software sufficient access and autonomy to manage real-world tasks can make it dramatically more useful. Still, it also increases the consequences of mistakes, unauthorised actions, and weak security controls. For products built around deep access to a user’s digital life, trust may become as important as raw AI capability.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0