Instinct’s powerful AI assistant is raising privacy and security concerns

Instinct’s powerful AI assistant is raising privacy and security concerns

Instinct 强大的 AI 助手引发了隐私与安全担忧

Everyone is buzzing about Instinct, an AI personal assistant still in private access, not only for its incredible capabilities, but also for its potential privacy concerns. The agent, a veritable taskmaster, has been praised as feeling “like magic” and being one of the “most exciting launches” since OpenClaw. However, some testers have also raised concerns about the AI agent’s security model and its worrisome terms of service. To be fair, Instinct is still in private testing for now, so these concerns haven’t yet scaled to the wider public at this time.

大家都在热议 Instinct,这是一款目前仍处于内测阶段的 AI 个人助手。它不仅因其强大的功能备受关注,也因其潜在的隐私问题引发了讨论。这款代理工具堪称“任务大师”,被赞誉为“如同魔法一般”,是自 OpenClaw 以来“最令人兴奋的产品发布”之一。然而,一些测试人员也对该 AI 代理的安全模型及其令人担忧的服务条款提出了质疑。平心而论,Instinct 目前仍处于内测阶段,因此这些担忧尚未在大众层面大规模爆发。

Created by a small team led by former Sierra research scientist Noah Shinn, San Francisco-based Instinct is operated by Spear Street Technology, per its terms and California business filings. It’s currently operating in stealth, per PitchBook. The AI agent itself works by connecting to your applications and devices, including your email, messaging apps, calendar, and your device’s audio, location, screen, and more. You can text the agent or call it via text message or WhatsApp, asking it to perform various tasks for you, like booking your appointments and reservations, scheduling a ride to the airport, cleaning up your inbox, organizing important information, handling your shopping, finding you cheap flights, and much more.

Instinct 由前 Sierra 研究科学家 Noah Shinn 领导的小团队开发。根据其服务条款和加州商业备案,该产品由 Spear Street Technology 运营。据 PitchBook 显示,它目前处于隐身运营状态。该 AI 代理的工作原理是连接你的应用程序和设备,包括电子邮件、通讯软件、日历,以及设备的音频、位置、屏幕等信息。你可以通过短信或 WhatsApp 给它发消息或打电话,要求它为你执行各种任务,例如预约行程、预订餐厅、安排去机场的车辆、清理收件箱、整理重要信息、处理购物需求、寻找廉价机票等等。

Though Instinct is described by testers as outperforming their expectations, some have also raised concerns about the company’s approach to customer privacy and security. This raises a timely question: Are the trade-offs of giving AI this level of access and autonomy actually worth it? For instance, several people are circulating screenshots from the company’s Terms of Service, which grant Instinct a broad “perpetual and irrevocable” license to “access, use, host, cache, store, reproduce, transmit, display, publish, distribute, and modify” any of the user’s materials, including for training its AI models. The terms also detail how Instinct can receive information from users’ devices, including screen captures, cursor movements, and keyboard inputs. The terms also allow Instinct to enter into “agreements, commitments, or transactions” on users’ behalf, which would be binding.

尽管测试人员称 Instinct 的表现超出了预期,但也有人对该公司处理客户隐私和安全的方式提出了质疑。这引发了一个适时的问题:为了获得这种程度的 AI 访问权限和自主性,所付出的代价真的值得吗?例如,一些人正在传播该公司服务条款的截图,其中授予了 Instinct 一项广泛的“永久且不可撤销”的许可,允许其“访问、使用、托管、缓存、存储、复制、传输、展示、发布、分发和修改”用户的任何资料,包括用于训练其 AI 模型。条款还详细说明了 Instinct 如何从用户设备接收信息,包括屏幕截图、光标移动和键盘输入。此外,条款还允许 Instinct 代表用户达成具有约束力的“协议、承诺或交易”。

One early adopter, Peter Yang, pointed out that Instinct would not delete his Gmail records when asked. (The team later fixed the problem by adding a tool for deleting external data in its settings, he said.) Another person, Claire Vo, found that Instinct was still summarizing their inbox after disconnecting its access. When she asked Instinct what happened, the bot confirmed that the emails were stored in plain text for later searches.

早期采用者 Peter Yang 指出,当他要求删除 Gmail 记录时,Instinct 并没有执行。(他表示,团队后来通过在设置中添加删除外部数据的工具修复了该问题。)另一位用户 Claire Vo 发现,在断开访问权限后,Instinct 仍在总结她的收件箱内容。当她询问原因时,机器人确认这些邮件以纯文本形式存储,以便日后搜索。

Many others questioned the security model, too. One tester was a bit worried when they found that Instinct was able to pull a sign-up code from their email inbox to complete a particular task — in their case, booking a table at a restaurant via Resy. And Hello Patient co-founder Alex Cohen wrote that once he found out how easily Instinct could be phished, he deleted his account. In addition, Moxxie Ventures founder Katie Jacobs Stanton shared that Instinct broke her trust when it sent an email on her behalf without first checking with her.

许多人也对该安全模型提出了质疑。一位测试人员发现 Instinct 能够从其收件箱中提取注册验证码以完成特定任务(例如通过 Resy 预订餐厅座位)时,感到有些担忧。Hello Patient 的联合创始人 Alex Cohen 写道,当他发现 Instinct 如此容易被钓鱼攻击后,便删除了自己的账户。此外,Moxxie Ventures 的创始人 Katie Jacobs Stanton 分享说,Instinct 在未经她确认的情况下擅自以她的名义发送了一封邮件,这破坏了她对产品的信任。

“We’re trading privacy and control for hyper-personalized AI tools (AI notetakers, personalized AI agents, etc), often without fully understanding the trade,” she remarked on X, summarizing the dilemma posed by personal AI agents. “The more powerful these agents become, the more trust matters. Every successful action earns a little more trust. One unauthorized action can reset that trust to zero.”

“我们正在用隐私和控制权来换取超个性化的 AI 工具(如 AI 笔记工具、个性化 AI 代理等),但往往没有完全理解这种交换的代价,”她在 X 上评论道,总结了个人 AI 代理带来的困境。“这些代理越强大,信任就越重要。每一次成功的操作都能赢得一点信任,而一次未经授权的操作就可能让信任归零。”

Michael Mignano, the founder of Anchor, which was acquired by Spotify, and now a GP at Union Square Ventures, noted that products like Instinct are going to “change modern security norms for consumers,” adding that “people will increasingly hand over passwords to 3p [third-party] apps, unaware of how or what they are storing for them.”

曾被 Spotify 收购的 Anchor 创始人、现任 Union Square Ventures 合伙人的 Michael Mignano 指出,像 Instinct 这样的产品将“改变消费者的现代安全准则”,并补充说:“人们将越来越多地把密码交给第三方应用程序,却不知道这些应用是如何存储或存储了什么信息。”