A hyper-integrated assistant gets a trial run

Instinct, built by Spear Street Technology and led by former Sierra researcher Noah Shinn, bills itself as a “digital surrogate” that eclipses ordinary chat bots. In private testing, participants talk to the assistant via text, WhatsApp or voice calls while it reads email, messaging apps, calendars and live device telemetry—screen captures, cursor moves, keystrokes. The promise: a frictionless personal assistant that handles any routine task without the user lifting a finger.

How Instinct works

Deep integration sets Instinct apart. By pulling real-time signals from a device, it can spot a flight confirmation, extract calendar details and automatically rebook a missed connection. It can scan a Gmail inbox and summarize unread messages, place orders through Resy, and manage shopping lists.

The same breadth of access fuels controversy. The Terms of Service grant Instinct a “perpetual and irrevocable” license to access, host, reproduce and modify any user material, including the right to use that data to train its models. In practice, the assistant may keep copies of emails long after a user revokes permission.

Early adopters have already hit concrete problems. Tester Claire Vo found that Instinct kept summarizing her inbox after she disconnected the integration, showing the service stored the content in plain text for future search. The ToS also let the assistant enter “agreements, commitments, or transactions” on a user’s behalf, effectively allowing the AI to bind a person to financial or contractual obligations without a human signature. Attempts to delete external records such as Gmail logs met resistance, though Instinct’s team says new data-deletion tools are on the way.

Security concerns

Beyond legal exposure, the assistant opens new attack vectors. Testers have shown Instinct can be fooled by phishing messages; the AI sometimes sends emails or messages without an explicit user confirmation step. Capturing keystrokes and screen content creates a lucrative target for malicious actors seeking raw credentials or personal data.

Industry observers note that the very features that make Instinct attractive—continuous access, autonomous decision-making—also magnify any breach. If an attacker hijacked the assistant, they could read private communications and execute transactions. The potential damage surface expands dramatically compared with traditional password-protected accounts.

What the industry says

Union Square Ventures partner Michael Mignano argues that products like Instinct will “fundamentally change modern security norms.” He points out that handing over passwords and device telemetry to a third-party AI agent shifts away from the long-standing model of user-controlled authentication. The risk, he warns, is that the industry may not yet have safeguards to protect users at scale.

Looking ahead

-

-

-

-

If Instinct can demonstrate reliable safeguards while preserving its experience, it may set a template for the next generation of AI assistants. If not, the backlash could push developers back toward more restrictive, permission-light designs.

Bottom line

Instinct’s ambition to become a truly autonomous personal assistant pits convenience against control. Deep device integration delivers automation that feels almost magical, yet the same integration leaves users exposed to perpetual data harvesting, legally binding AI actions and a broadened attack surface. The coming months will reveal whether the market embraces that trade-off or demands stricter guardrails before handing an AI the keys to a digital life.