Instinct Raised $325M Before Launching. Its Real Story Is About Trust.

Instinct, an invite-only AI personal assistant, hit a reported $2.5B valuation in weeks. The personal AI agent race is heating up — and so are the privacy and trust problems that come with it.

Silicon Valley has a new obsession, and most people can't even use it yet.

Instinct, an AI personal assistant still in invite-only testing, reportedly raised a $75 million Series A in early August at a valuation just above $500 million — then, weeks later, a $250 million Series B co-led by Benchmark and Index Ventures at a $2.5 billion valuation. That's a 5x markup in under a month, for a product the public has never touched. Total disclosed funding now sits around $325 million.

Numbers like that aren't really a judgment on the product. They're a bet on a thesis: that the next major consumer AI product won't be a chatbot you talk to, but an agent that acts on your behalf. And Instinct is the purest expression of that thesis so far — including its problems.

What Instinct actually does
The setup is unusual. Before you use Instinct, you hand over access to your email, calendar, texts, WhatsApp, and — on device — your screen, audio, and location.

Then you stop opening the app. You interact with it the way you'd interact with a human assistant: by text or phone call.

"Handle my inbox." "Book me a Chinese restaurant tonight." "Find me a cheaper flight to Africa."

The company says it doesn't tell you how to do these things — it just does them. According to founder Noah Shinn, early testers have used it to plan a cross-US road trip, do weekly grocery runs, buy concert tickets, cancel forgotten subscriptions (one user reportedly saved hundreds of dollars), and even help plan a wedding.

None of these tasks is individually new. What's new is the compression: work that used to mean opening your email, calendar, an airline site, a booking platform, and a ride-hailing app now collapses into one text message.

That compression is exactly what the two previous years of "AI agent" demos promised and mostly failed to deliver. Those demos were impressive on video and brittle in practice: complex setup, constant confirmation prompts, tasks failing halfway through. Instinct's bet is that hiding all of that complexity — and meeting users inside an interaction pattern (texting an assistant) that has existed for decades — is what finally makes agents consumer-grade.

The founder studied why agents fail
Shinn, 23, has an unusually relevant background for this problem. He did ML and programming-language research at Northeastern and MIT, then joined enterprise agent company Sierra as an early employee.

In 2023, he was first author on Reflexion (later accepted at NeurIPS 2023), a paper asking a question that has become central to agent design: when an AI fails at a task, can it record what went wrong and do better next time, instead of starting from zero?

At Sierra, he worked on τ-bench, a benchmark that tests agents on realistic, multi-step tasks — like changing a flight booking, which requires understanding the request, checking airline rules, calling the booking system, confirming with the user, and actually modifying the order in the database.

The results were sobering, and worth quoting precisely because Shinn is now selling an agent: on these realistic tasks, even the most advanced models succeeded on a single attempt less than 50% of the time. Requiring the same task to succeed 8 times in a row dropped the pass rate to roughly 25%.

That's a researcher-published number, not a competitor's hit piece — and it defines the honest state of the art. Agents that act in the real world are still unreliable in ways that chatbots are not.

The real trade: context, permissions, and agency
Traditional software waits for you. Search engines find the flight; you buy it. Your inbox receives the email; you decide how to reply.

Agents invert this. To be useful, a personal agent must first understand your habits, relationships, schedule, and preferences — and then use software as you. Which means the valuable personal AI of the next few years will likely hold three things at once: your context, your permissions, and the power to act.

Instinct is the aggressive end of that trade, but it's not the only company making it. Macaron, for example, positions itself as a "personal AI agent" built around life rather than work, leaning on persistent memory so the agent accumulates knowledge of what matters to you over time. The approaches differ — Instinct wants to be reachable by SMS and do everything; Macaron builds small, purpose-fit tools from a single request — but the direction is the same: whoever holds the deepest personal context owns the next consumer AI entry point.

And that's where the uncomfortable questions start.

The trust problems are already showing
Instinct's appeal and its risk are the same thing: it knows a lot about you, and it can act.

Its terms of service at one point granted the company a strikingly broad license over user data — including storing user material for model training, and device data potentially covering screenshots, mouse movement, and keystrokes. The terms also allowed Instinct to enter certain "agreements, commitments, or transactions" on the user's behalf.

Then came the tester incidents:

Data persistence. Entrepreneur Claire Vo disconnected Instinct from her Google account — and hours later still received an Instinct-generated inbox digest. Previously read emails had been copied into Instinct's own records; cutting the connection didn't remove what was already indexed. Another tester, Peter Yang, found he couldn't directly delete his indexed Gmail data at all. (Instinct added an external-data deletion feature after these cases became public.)
Prompt injection. Hello Patient co-founder Alex Cohen created a fresh mailbox, sent his real inbox an email containing hidden instructions aimed at the agent, and watched whether Instinct would treat the text as commands. He deleted his account afterward. For a chatbot, a malicious email is mostly noise; for an agent with your inbox, payment info, and web access, the phishing email of the future doesn't trick you into clicking — it tricks your assistant into acting.
Acting without confirmation. Moxxie Ventures founder Katie Jacobs Stanton found that Instinct sent an email on her behalf without asking first. Nothing bad came of it; she revoked email access anyway. Her summary is the cleanest framing of the whole problem: an AI earns trust by getting many tasks right in a row — and loses all of it with a single unauthorized action.
To be fair, these are the failure modes an invite-only beta exists to surface, and Instinct has been patching them. But the structural issue isn't fixable with a settings toggle: an agent useful enough to trust with your life is, by definition, powerful enough to betray that trust at scale.

Before you hand an AI your keys
Whether it's Instinct or any other personal agent, a few questions cut through the pitch:

Where does my data actually live? Disconnecting an account is not the same as deleting what was already copied. Ask whether you can purge indexed data, not just revoke access.
When must it ask me first? Look for hard confirmation gates on anything irreversible — sending messages, spending money, booking or canceling.
Can it distinguish content from commands? If the agent reads your email or the web, prompt injection is your problem now, not just the vendor's.
What does the ToS allow? "May store and use your materials to train models" and "may enter transactions on your behalf" are worth reading twice.
FAQ
What is Instinct? An invite-only AI personal assistant that connects to your email, calendar, messaging, and device data, and completes real-world tasks (bookings, purchases, inbox triage) via text or phone call, rather than a chat interface.

Is Instinct available to the public? No. It remains in private, invite-only testing as of its reported August 2026 funding rounds.

What is prompt injection, and why does it matter for AI agents? It's an attack where malicious instructions are hidden in content the AI reads — an email, a web page. Chatbots might just say something wrong; an agent with your accounts and payment methods might do something wrong.

Are personal AI agents reliable enough to trust? Published benchmarks suggest caution. On realistic multi-step tasks, top models succeed under 50% of the time per attempt in the τ-bench evaluation — research, ironically, co-authored by Instinct's own founder.

The bottom line
Instinct's $2.5B valuation prices a story, not a business. The story — that personal AI agents will become the next consumer entry point by holding your context, permissions, and agency — is genuinely plausible. The early evidence also shows the cost of admission: today's agents are unreliable at published rates, leak data across "disconnected" accounts, and can be steered by the content they read.

The winners in this category won't be the agents that can do the most. They'll be the ones that make the trust trade legible: clear data deletion, hard confirmation gates, and honesty about failure rates. If you want to see what a personal agent built around memory looks like in practice, Macaron is one of the more accessible ways to try the idea today — no invite list, and it builds small, dedicated tools from a single request rather than asking for your whole digital life up front.