Instinct, an autonomous personal AI assistant currently in private beta, has drawn scrutiny across the developer and security community regarding its data collection policies and broad operational permissions.
The service is developed by San Francisco-based Spear Street Technology Inc., led by former Sierra research scientist and Reflexion paper co-author Noah Shinn. Operating via SMS and WhatsApp interfaces, Instinct executes multi-step personal workflows by directly interfacing with user devices and third-party services.
System Integration and Autonomous Execution
Unlike standard conversational interfaces, Instinct requires deep access to connected devices and application accounts. The assistant is designed to handle tasks such as inbox management, travel bookings, calendar coordination, and local file organization.
To achieve this level of execution, the agent's architecture integrates:
- Full read and write access to personal email, messaging platforms, and calendar services.
- Real-time monitoring of device peripherals, including screen captures, keyboard inputs, cursor coordinates, and audio streams.
- Autonomous execution hooks capable of scheduling rides, placing retail orders, and confirming travel reservations.

Terms of Service and Liability Trade-Offs
Security researchers and early testers have raised concerns regarding clauses in Instinct's user agreement governing data retention, training rights, and legal agency:
- Training Rights on User Data: The terms grant Spear Street Technology a perpetual, irrevocable, worldwide, and sublicensable license to cache, store, modify, and utilize user-submitted materials—including screen recordings and transcribed inputs—to train future machine learning models.
- Binding Transactional Authority: The agreement explicitly permits the AI agent to enter into legally binding contracts, commitments, and financial transactions on the user's behalf without requiring secondary human confirmation for each individual API or checkout call.
The controversy highlights an unresolved structural tension in agentic AI deployments: consumer agents requiring comprehensive system context to execute autonomous tasks frequently request broad data access and execution authority that conflict with standard enterprise data-isolation and privacy norms.



