Personal AI Assistant Instinct Draws Privacy Backlash Over Sweeping Data and Transaction Permissions
Early testers of Instinct, a private-access personal AI agent from a small San Francisco startup, are raising alarms over terms that grant a perpetual license to their data and let the agent enter binding transactions on their behalf.
A buzzy new personal AI assistant called Instinct is facing scrutiny from its own early users over just how much access and authority it demands, according to reporting from TechCrunch published August 24. Instinct, still limited to private access, is built by a small San Francisco-based team operated under the name Spear Street Technology and led by Noah Shinn, a former research scientist at customer-service AI company Sierra.
What Instinct does — and what it asks for
Instinct positions itself as a proactive, autonomous personal assistant: it connects to a user's email, messaging apps and calendar, and can also draw on a device's screen, cursor movements, keyboard input, audio and location data to act on the user's behalf. That breadth of access is what has drawn praise from early testers impressed by its capability, and alarm from others over how far its permissions extend.
The terms that worried testers
According to TechCrunch's review of Instinct's Terms of Service, the company requires a "perpetual and irrevocable" license to "access, use, host, cache, store, reproduce, transmit, display, publish, distribute, and modify" a user's materials — including using that data to develop, train and fine-tune its underlying AI models. The terms reportedly place no limits on the categories of data covered, encompassing screen captures, keystrokes, audio and location alongside ordinary app content.
Beyond data licensing, Instinct's terms also allow the assistant to enter into "agreements, commitments, or transactions" on a user's behalf, with those actions described as binding — meaning an autonomous error or misjudgment by the agent could carry real financial or contractual consequences for the person who granted it access.
Part of a wider pattern
TechCrunch's report notes that autonomous agents which act independently on a user's behalf carry novel risks beyond typical software privacy concerns, including the possibility of unintended payments or communications sent without a human checking first. One venture capitalist quoted in the coverage predicted that products like Instinct will "change modern security norms for consumers," as people grow accustomed to handing agentic apps the kind of access — and trust — previously reserved for humans.
Instinct has not publicly responded to the criticism, and it remains unclear whether the company plans to narrow its data-licensing terms as it moves toward a wider release. The episode adds to a running debate this year over how much autonomy and data access personal AI agents should be granted by default, and how clearly that access should be disclosed to the people granting it.
Sources
AI-assisted reporting, overseen by the AgentsAI team. Spotted an error? Let us know.
More agents news
Synchrony Brings Store Financing and Rewards Into ChatGPT in Agentic Commerce Push
Consumer finance giant Synchrony announced an enterprise collaboration with OpenAI on August 17, launching a ChatGPT plugin that surfaces its store-card financing and rewards inside conversational shopping while adopting OpenAI's models internally.
Binance Launches Agent OS, Letting AI Agents Trade Crypto on Users' Behalf
Binance launched Agent OS on August 20, bundling its APIs, wallet infrastructure and a new MCP server so AI agents like ChatGPT, Claude Code and Cursor can analyze markets and execute trades within user-set dollar limits.
Google Moves A2A Agent-Interoperability Protocol Under the Agentic AI Foundation
Google is transferring governance of its Agent2Agent (A2A) protocol from the Linux Foundation's general umbrella into the Agentic AI Foundation, putting the two leading agent standards, A2A and Anthropic's MCP, under one roof.
Microsoft Merges Its Two Copilot Apps and Pushes Deep Research Behind a $19.99 Paywall
Microsoft is unifying its consumer Copilot and Microsoft 365 Copilot apps into a single product and retiring Group Chats, Copilot Podcasts and free Deep Research on August 18, replacing Deep Research with a more capable 'Researcher' agent locked behind a $19.99/month Microsoft 365 Premium plan.