The direct answer
Instinct’s $1 billion Series C at a $10 billion valuation is a bet that people will delegate more of everyday life to an AI agent. Reuters and TechCrunch report that the company is building a personal assistant that can plan travel, buy groceries, book tickets, cancel subscriptions and, through a concierge feature, call businesses for a user.[^1][^2] That is more than a chatbot story. It is a test of whether an agent that learns a person’s context can remain answerable to that person when it starts to recommend, negotiate and transact.
The value of a personal agent grows with the context it is allowed to use. The same fact makes the governance problem harder. Instinct’s privacy policy says that, depending on what a user chooses to connect or supply, its assistant may access connected-app content, private communications, documents, voice data, payment information, credentials and health-related information.[^3] The policy says users can opt out of certain AI-model-training use in settings, subject to stated qualifications. Those terms do not prove harm or misconduct. They make the decision to delegate consequential.
Modi’s POV: Privacy is only half the personal-agent problem. The harder question is alignment. If an agent knows my budget, preferences, calendar and intentions, and can take action for me, I need to know whose interests it represents at the moment it recommends or buys. A personal agent should act like a personal AI fiduciary by design: user objective first, disclosed commercial relationships, bounded authority and a reviewable record. That is a design principle, not a claim that Instinct has a legal fiduciary duty.
The funding headline is a signal, not the whole story
Reuters reported that Instinct raised $1 billion and reached a $10 billion valuation in a round involving Sequoia Capital, Benchmark Capital and Coatue.[^1] TechCrunch reported that the company had launched an invite-only service in August and had a 14-person team at the time of its September coverage.[^2] The speed of the financing is striking. It tells us investors believe a personal agent could be a major interface layer between a person and the services they use.
It does not establish the product’s revenue, security performance, retention, profitability or long-term consumer value. A private financing price reflects a particular investor view of a future opportunity. That distinction matters in an AI market where ability, adoption and unit economics can develop at different speeds.
The more interesting evidence is behavioural. In a September interview reported by TechCrunch, founder Noah Shinn said more than half of transactions on the platform are travel-related, described the product as approaching $1 billion in annual transactions, and said platform and transaction volume were growing about 10% day over day.[^4] TechCrunch explicitly noted that Shinn did not specify the calculation behind the annual-transaction figure. These are founder-reported indicators, not audited metrics or a basis for extrapolation.
Dynamic control comparison
Instinct vs Muse vs ChatGPT agent: what do the public controls say?
Filter by the control you are assessing. This is a documentation comparison, not a security ranking or independent certification; product behaviour and availability can change.
Research only: Prioritise clear purpose, data choices and a reliable stop or deletion path before expanding access. Compare authority, data and review evidence.
| Control to assess | InstinctPrivacy policy | MuseMeta announcement | ChatGPT agentOpenAI announcement |
|---|---|---|---|
Permission scope A useful agent needs access, but a user needs to know what each connected service permits. | Partly documented Permission-dependent access Its policy says access depends on permissions a user grants, including connected accounts and private materials. The policy does not itself describe a universal per-action permission interface. | Publicly stated App-level access choices Meta says people choose which apps connect and how much access Muse receives; its example distinguishes reading email from also sending it. | Publicly stated Task and browser controls OpenAI says users can interrupt, stop tasks or take over the browser, while the agent requests permission before consequential actions. |
Model-use and data choices A consent setting can be meaningful only when users understand exceptions, connected-data limits and retention behaviour. | Publicly stated Training opt-out with stated limits Its policy offers a settings opt-out from some model-training use, with stated safety-review exceptions; it separately says Google Workspace data is not used for model training or ads. | Publicly stated Training opt-out and ad boundary Meta says users can opt out of interaction training and that conversations and VM data are not shared with Meta’s ad systems. | Publicly stated Browsing and connector controls OpenAI describes one-click deletion of browsing data and log-out of browser sessions. Its safety guidance recommends disabling connectors when they are not needed. |
Review, stop and exit A person should be able to identify what happened, reduce authority and correct a mistake. | Publicly stated Disconnect and deletion routes Its policy describes revoking Google Workspace access, disconnecting integrations and deleting indexed external-source data. Disconnecting alone does not automatically delete data already collected. | Publicly stated Audit-trail claim Meta says Muse shows a complete audit trail of what it has done and plans to do; users can change access, disconnect services or ask it to forget specific memories. | Partly documented Interrupt or take over OpenAI says users can interrupt, stop a task or take over the browser. The cited launch material does not describe a universal, exportable action-receipt feature. |
From assistant to economic representative
The progression is easy to miss because each step sounds familiar:
- An assistant answers questions.
- An agent completes a defined task.
- A trusted delegate acts across connected services.
- A transaction agent spends, books, cancels or negotiates under constraints.
- An economic representative affects what a person sees, chooses and buys.
This is why the debate about agentic commerce should not be reduced to checkout convenience. Our guide to the agentic-commerce consent gap examines the conditions that should exist before an agent can make consequential purchases. Our analysis of AI-agent liability and identity adds a related question: what evidence tells a merchant, user or regulator who authorised an action, what authority was delegated, and how it can be disputed?
| Stage, as this page names it | What the agent is allowed to touch | Loyalty test before that stage is allowed |
|---|---|---|
| Assistant answers questions | The question the user asked | The user can still see the objective |
| Agent completes a defined task | That task only | The constraints are still visible |
| Trusted delegate across connected services | Only what the user connected | Payment, mail, health, or credentials are in scope only because the user put them there |
| Transaction agent | Spend, book, cancel, or negotiate under constraints | There is an action boundary and a receipt before money or a booking moves |
| Economic representative | What the person sees, chooses, and buys | The user can see who benefits commercially before they approve |
The official policy makes the trade visible
Instinct’s policy is unusually direct about the context an autonomous assistant may need. It says the service can use information from connected applications and accounts, text and documents, messages and emails that a user makes available, and optional audio or voice data.1 It also says the assistant may access sensitive information when users provide it for tasks, including payment information to book rides and credentials to sign into third-party accounts. Connected Google Workspace data is described separately, with a statement that it is not used to train or improve AI models.1
This is not an accusation. It is an operating reality for a system designed to act on a person’s behalf. A travel agent needs travel details; a calendar assistant needs calendar details. The important question is whether users can understand the boundaries before they create a broad permission surface.
The policy says users can visit settings to opt out of having their information used to evaluate, fine-tune or train AI models, but notes qualifications for safety review and that prior use cannot be reversed.1 It also says disconnecting a third-party integration does not automatically delete data previously collected from that integration, while providing controls to delete data indexed from external sources.1 Those are the kinds of details that a user should assess before granting high-value access—not after a compelling demo has made delegation feel effortless.
How to join Instinct safely
The official Instinct homepage currently says “Text Instinct to get started” and links to app.instinct.com/login.2 It does not display a verified public referral or standalone waitlist URL. Reporting describes the product as invite-only or early-access, so availability may vary. Use the company’s official flow instead of third-party invite links, then start with a narrow task and a narrow permission set.
A sensible progression is to test a non-sensitive task first, avoid sending confidential material through unprotected channels, check what accounts are connected, set spend or approval constraints where available, and review the current privacy policy before allowing the system to access credentials or payment information. No product page or article can substitute for a user’s own risk assessment.
Security controls are necessary, but they are not the full alignment answer
Reuters reported that Instinct says it is continually improving isolated sandboxes, short-lived local credentials and an active detection system for subtle hallucinations.3 Business Insider reported an apparent data-leak claim made by a user and founder Noah Shinn’s response that it was a hallucination, not a breach; the article says he did not explain how he reached that conclusion.4 It also reported Shinn’s statement that the company uses partitioning, isolated sandboxes, short-lived credentials and identity-signed tool execution.4
The responsible reading is narrow. These are company claims reported by credible outlets; they are not an independent security certification. A sandbox can reduce exposure without guaranteeing that every workflow, integration or third-party tool behaves safely. Hallucination detection can help, but it cannot by itself decide who should bear a loss if an agent makes an incorrect booking, misstates a fact or pursues an instruction that conflicts with user intent.
The principle also applies beyond Instinct. The Astra safety-governance case showed why an agent needs an explicit scope, permission boundary, monitoring and a way to request approval. “It can act” is not a control specification. “It can be stopped, inspected and corrected” is closer.
Sandboxes, short-lived credentials, and a hallucination detector, as Instinct describes them, are vendor statements to investigate. They are not the loyalty test. Loyalty needs a machine-enforced limit on what the agent may read, disclose, contact, publish, and spend, and on which acts are impossible without a person: the Authority Envelope [blocked].
Infographic: a practical alignment hierarchy for personal agents
The hierarchy below is a proposal for product teams, buyers and regulators to test any personal agent. It puts the human’s stated objective and constraints ahead of commercial relationships, then asks the agent to expose the evidence behind a recommendation, disclose who benefits, respect an action boundary and produce a usable receipt.
A receipt should mean more than a chat transcript. For a consequential action, a person should be able to see what was done, which sources or offers were considered, what permissions were used, what was spent or communicated, and how to challenge an outcome. That is how delegation remains reviewable as the system becomes more proactive.
The commercial-incentive problem arrives before advertising does
Many personal-agent discussions centre on security: can a system protect a card, a credential or a private message? Those questions matter. They are often easier to name than the incentive question.
Imagine an agent that knows a user needs a quiet hotel within a £250 budget, has a specific dietary preference, is travelling on a difficult date and has rejected several options before. That is much richer than a search query or a browser cookie. If a hotel, marketplace, payment provider or advertiser pays for a preferred placement, the agent needs a rule that preserves the user’s objective rather than quietly converting it into the platform’s objective.
This is why I would judge a personal agent by six visible elements:
| Control | The question a user should be able to answer |
|---|---|
| User objective | What did I ask the agent to optimise for? |
| User constraints | What budget, privacy, values and permissions limit the task? |
| Evidence | What supports the recommendation or action? |
| Commercial relationship | Does a provider, merchant or platform benefit financially? |
| Disclosure | Can I see that relationship before I approve or delegate? |
| Action receipt | What happened, why, and how can I correct or dispute it? |
That framework does not require a personal agent to be perfect or neutral. It requires it to be legible. Consumers can choose a paid recommendation or a transaction fee when the arrangement is clear. The risk begins when a system with intimate context can steer outcomes without the user seeing the incentive or retaining a practical exit.
What businesses should do before personal agents become a major demand channel
For brands, the immediate task is not to buy placement inside a personal agent. It is to make product information, availability, conditions, pricing, fulfilment rules and support routes accurate enough for a user-controlled agent to evaluate.
That includes clear product data, accessible policy pages, reliable booking or checkout mechanics, honest claims and a route for humans to resolve exceptions. An agent cannot responsibly represent a brand when the underlying information is ambiguous, inaccessible or contradictory. It also cannot build durable trust if an offer appears to be preferred for a reason the end user cannot understand.
For a practical review of whether your website and information architecture are ready for AI-mediated discovery and action, use the free AI Growth Audit or explore our agentic AI implementation service. The goal is not to chase a temporary interface. It is to make the business legible, governed and useful when an agent starts to do research, comparison or workflow tasks on a customer’s behalf.
Further reading
For readers building a responsible view of agentic systems, The Coming Wave and Nexus are contextual Amazon UK resources on the societal, governance and information-network consequences of advanced technology. As an Amazon Associate, Integrated.Social may earn from qualifying purchases; recommendations should be assessed for your own objectives.
The bottom line
Instinct’s funding is a clear market signal: investors see a large opportunity in agents that can handle the personal, fragmented work of everyday life. Its official policy shows the corresponding trade. A more helpful agent can need more context, and more context can raise the cost of a misaligned incentive, an unclear permission, a faulty action or a poor response to an incident.
The winning personal agent will not simply be the one that knows the most about a user. It will be the one that gives the user the clearest way to set constraints, inspect evidence, understand commercial relationships, approve consequential actions and reverse a mistake.
Personal agents should not merely be private. They need to be loyal—and able to show their work.
References
About the Author
Modi Elnadi is founder of Integrated.Social, a London AI growth consultancy. Since 2014 he has combined performance media with answer-engine optimisation and agentic lead systems for B2B and B2C brands. These pieces are his working point of view for CMOs, not a vendor press release.
Footnotes
-
Instinct Privacy Policy, revised 26 August 2026. ↩ ↩2 ↩3 ↩4
-
Instinct official website, accessed 30 September 2026. ↩
-
Reuters: AI agent firm Instinct raises $1 billion in latest funding round, 28 September 2026. ↩
-
Business Insider: Instinct's founder says the viral AI agent's hallucinations can spit out what looks like a stranger's data, 24 September 2026. ↩ ↩2










