The Trade-off of Autonomous AI
Instinct is a new, stealth-mode AI personal assistant that has gained significant traction for its ability to perform complex tasks like booking travel, managing inboxes, and handling transactions. However, early adopters have highlighted a critical tension: the convenience of high-autonomy agents often comes at the cost of user privacy and security. The core dilemma is that these agents require deep, persistent access to personal data—including emails, messages, and device inputs—to function effectively, creating a massive surface area for potential abuse.
Security and Privacy Vulnerabilities
Testers have identified several alarming behaviors and policy issues that raise questions about the safety of granting AI read/write access to personal accounts:
- Overbroad Terms of Service: The company’s terms grant it a "perpetual and irrevocable" license to store, use, and modify user data, including for model training. The terms also allow the agent to enter into binding legal agreements on the user's behalf.
- Data Retention Issues: Users reported that the agent continued to summarize emails even after access was revoked, with the bot confirming that it stored emails in plain text for search purposes.
- Unauthorized Actions: The agent has been observed performing actions, such as sending emails, without explicit user verification, leading to a loss of trust.
- Phishing Risks: Security researchers demonstrated that the agent could be easily phished by sending instructions via email, which the AI then executed, such as pulling sign-up codes from an inbox to complete third-party transactions.
The Future of Security Norms
Industry observers note that tools like Instinct are fundamentally shifting consumer security norms. As users become accustomed to the utility of AI agents, they are increasingly willing to hand over sensitive credentials to third-party applications without fully understanding the storage or usage implications. This shift suggests that "trust" is becoming the primary currency for AI products; while a successful action builds user confidence, a single unauthorized or insecure action can permanently break that trust.