A private AI assistant that books flights, manages inboxes, and buys groceries has become one of Silicon Valley's loudest stories. Most people still cannot try it.
Instinct seems to have appeared everywhere at once.
One user said it planned a cross-country road trip. Others reported using it to buy groceries and concert tickets, cancel subscriptions, and book restaurants. Someone is reportedly planning a wedding with it.
The product is still private while the company scales compute. Its website is almost empty. There is no public launch, no standard pricing, and no feature list. Yet Instinct is reportedly raising $250 million at a $2.5 billion valuation.
Then, just as the excitement peaked, early users began posting a different kind of story. One said the assistant retained indexed email after Google access was disconnected. Another said it sent an email without asking first. A third tested whether instructions hidden inside an incoming message could influence what the agent did.
Within days Instinct became three stories at once: a new personal assistant, one of the fastest funding rounds in AI, and a live test of how much access people will hand to an autonomous system. Here is the public record so far.
The short version
- Instinct is an invite-only personal assistant. You text or call it, and it operates a phone and computer for you.
- It connects to email, messaging, screen, audio, and location, and finishes tasks instead of describing them.
- It is reportedly raising $250 million at a $2.5 billion valuation, roughly $350 million across all rounds.
- The early controversy is about control as much as privacy: retained data, prompt injection, deletion, and actions taken without confirmation.
What Instinct actually does
Instinct calls itself a personal assistant that understands what you are working on and what matters to you. It connects to email, messaging, screen, audio, location, and other application or device data. There is no interface to learn: you text or call it, and it drives phones and computers to get things done.
That sounds simple. The access underneath it is not.
To arrange your ride, it needs your location and travel details. To manage your inbox, it must read your messages. To make a reservation or a purchase, it may need account credentials, verification codes, and payment information.
That access is what moves Instinct past the usual chatbot. Instead of writing instructions for a task, it attempts the task.
Instinct's own site and accounts reported by TechCrunch describe the same pattern: travel booked and rebooked, tables reserved, inboxes cleaned, subscriptions cancelled.
The funding story
Instinct is operated by Spear Street Technology and led by Noah Shinn, a former research scientist at Sierra.
On August 26, 2026, TechCrunch reported that the company told The Wall Street Journal it had raised a $250 million Series B led by Index Ventures and Benchmark, putting total funding at $350 million and the valuation at $2.5 billion.
One qualification matters. The Information reported that the round was expected to close within the following weeks, and no formal announcement from the company or its lead investors had appeared as of August 30. The careful version is that Instinct is reportedly raising the round, not that it has closed it.
For a four-month-old product most people cannot open, that price turned Instinct from a curiosity into a public marker for the personal-agent race.
Why it went viral
The stories ended with finished work. People did not post that Instinct wrote a good answer. They posted that a flight was booked, groceries arrived, or a subscription disappeared from the next credit-card statement. A completed errand is more persuasive than a benchmark.
The interface needed no explanation either. No canvas, no workflow builder, no prompt library. Text it. Call it. Ask for something.
Scarcity did the rest. A small group of users produced most of the public evidence, and invitations became social currency.
Even the backlash helped. The security discussion was never separate from the excitement; it confirmed the product had enough access to cause consequences. That is the defining trade in agentic AI: more access creates more usefulness and more ways for trust to break.
What the trust debate is really about
Several early users described incidents that made the tradeoff concrete.
- Claire Vo reported receiving an email summary after disconnecting Instinct from Google. The assistant said previously indexed messages remained available for search.
- Peter Yang said he initially could not delete Gmail records collected by the service, then reported that the team shipped a deletion tool.
- Alex Cohen tested whether instructions inside an incoming email could influence the agent. After the test succeeded, he deleted his account.
- Katie Jacobs Stanton said Instinct sent an email on her behalf without asking for confirmation.
These reports, documented by TechCrunch, were not accounts of an external breach. They show what happens when a system has standing access to private information and the authority to act.
Instinct revised its legal documents on August 26 and clarified its user controls. Four things in the current Terms of Service and Privacy Policy shape the decision to connect an account. Disconnecting a service does not remove information already indexed from it, since deletion is a separate action in workspace settings. The terms authorize Instinct to enter agreements, commitments, or transactions on the user's behalf, and those commitments can bind the user. Materials may be used to train models unless the user opts out, with Vault materials excluded and Google Workspace data exempt. And while Instinct may add confirmation requirements, the terms do not guarantee that safeguards prevent unintended actions. Responsibility stays with the user.
None of this is specific to Instinct. It is an agent-design problem. OWASP identifies excessive agency as a risk created by too much functionality, permission, or autonomy, and points to least privilege, narrow tools, and human approval for high-impact operations.
The more an agent can do, the more deliberately its authority has to be designed.
Personal intelligence versus organizational intelligence
Instinct is a consumer story. But persistent context and finished actions inside a familiar channel are already shaping what people expect from AI at work.
Instinct is built around one person's world. Your messages, your calendar, your preferences, your accounts, your decisions.
A company has no single equivalent of "you." A CRM holds part of a customer relationship, email holds another part, meeting notes hold the decisions, documents hold the formal knowledge, and experienced teammates hold everything nobody wrote down.
The access model differs too. A person decides whether their assistant may send an email. Inside a company, the answer depends on the employee, the customer, the policy, and the blast radius of the action.
That changes the product.
| Personal AI | Organizational AI |
|---|---|
| Knows what the user tells it | Knows the organization's context |
| Personal setup | Shared infrastructure |
| One user's memory | Organizational memory |
| User asks, AI answers | AI can execute workflows |
| Individual productivity | Team capability |
| Configuration lives with user | Workflows belong to the organization |
| Generic | Tailored |
Giving every employee a separate copilot does not solve this. It makes each person faster while the organization stays fragmented.
Where Ventos fits
Ventos builds the organizational version of persistent, action-oriented AI.
It connects CRM, Drive, SharePoint, email, calendars, messaging, and meeting notes into an organizational brain. That shared layer gives agents the context to answer questions and move work across systems. A Ventos agent can prepare a meeting brief from relationship history spread across tools, generate recurring pipeline reports, surface who on the team knows a company and what was promised, and trigger workflows when conditions are met. Teams reach those agents through web, Slack, WhatsApp, email, and Microsoft Teams.
The difference that matters is governance. Access mirrors the permissions already present in the organization's systems. Teams define what each agent can read, what it can do, and where a human must confirm. Each organization runs in an isolated deployment with its own encryption keys, and customer data is not used to train AI models.
Ventos also pairs the platform with AI experts who map how a team actually works and configure agents on real company data. Organizational knowledge is rarely clean enough to activate with one button.
So is Ventos "Instinct for organizations"? In spirit, yes. Both point toward AI that remembers context, lives in familiar channels, and acts instead of stopping at a suggestion. In design, no. Instinct needs to understand me. Ventos needs to understand us: our relationships, permissions, workflows, and approval rules.
For a side-by-side look at where each product fits, read Ventos vs Instinct.
The same shift, built for the whole organization
Instinct is evidence that the interface for AI is changing: users want systems that already know the context and carry tasks to completion. The same demand exists inside organizations, where the value is larger than booking one person's flight, but the organizational version has to be shared, permission-aware, and governed.
If an important workflow still depends on one person remembering where every piece of context lives, that is a good place to start.
Book a 20-minute Ventos call and bring one workflow. We will map how organizational AI could handle it using the systems your team already has.
Research current as of August 30, 2026. Availability, financing, and legal terms may change. Instinct statements come from its official site and current legal documents; Ventos statements from its public site.
