Instinct, an AI assistant that launched in limited beta earlier this month, has quickly gained a reputation for its remarkable capabilities. Testers report that it can compose emails, schedule meetings, manage files, and even make purchases on behalf of its users, all by integrating with a user's email, calendar, cloud storage, and financial accounts. The assistant reportedly uses a large language model to understand context and execute multi-step instructions with minimal human oversight.
But the same features that make Instinct powerful are also raising alarms. The company's terms of service grant the AI broad access to any connected service, and users must agree to allow Instinct to "act on their behalf" across those platforms. Privacy experts note that such permissions could be exploited if the assistant's security is compromised, or if the company itself uses the data in ways users do not expect.
"The convenience is undeniable, but the trade-off is that you're essentially handing over the keys to your digital life," said Dr. Elena Morris, a cybersecurity researcher at the University of California, Berkeley. "If an attacker were to compromise Instinct's backend, they could gain access to everything the assistant can see and do, which is potentially catastrophic."
Instinct's developers have responded by emphasizing their commitment to encryption and user control. In a statement, the company explained that all data is encrypted in transit and at rest, and that users can revoke access at any time. They also noted that the assistant's actions are logged and transparent, so users can review what Instinct has done.
Yet some critics remain unconvinced. The Electronic Frontier Foundation (EFF) flagged Instinct's broad permissions as a concern, particularly the ability to execute actions automatically without explicit confirmation for each step. The EFF recommended that users only connect non-sensitive accounts during the beta period.
Instinct is not the first AI assistant to face such scrutiny. Competitors like Google Assistant and Amazon Alexa have also been criticized for their data practices, but Instinct's level of access—spanning multiple services with the ability to take real-world actions—represents a new frontier in the debate over AI autonomy and user privacy.
As the beta continues, the company is expected to refine its security model and clarify its data policies. For now, users are advised to carefully weigh the benefits against the risks before granting Instinct full access.