
Validates permission-heavy consumer AI agents as a category and raises the stakes on permission audits for teams evaluating agent tools.
Who Invested in Instinct and How Much?
Instinct raised $1 billion in a Series C round that values the AI agent startup at $10 billion. Sequoia Capital, Benchmark Capital, and Coatue participated.
The speed is the story: the round closed a month after the company announced a fundraise at a $2.5 billion valuation, and the invite-only service launched in August 2026. The Information first reported the raise, and Instinct confirmed the Series C in a Monday press release.
The company behind it, founded last year and led by 23-year-old Noah Shinn, operates as Spear Street Technology. Instinct declined interviews alongside the announcement and shared a founder statement about building the best personal agent for the nuances of everyday life.
A 4x valuation jump in a month, on a product still behind an invite wall.
What Are Instinct’s Actual User Numbers?
Nobody outside the company knows. Instinct has not shared user numbers or growth metrics, and it has no mobile app: the agent communicates over SMS and texting.
What is verifiable is the feature set. The agent answers questions, books travel and restaurant reservations, makes purchases, pays bills, cancels subscriptions, and orders groceries, using its own phone number and computer to execute tasks.
Two recent additions stretch further: a concierge feature that makes phone calls to book appointments at places without online scheduling, and a trusted person network that lets one user’s agent coordinate plans with friends’ agents.
The valuation is pricing capability and narrative, not published adoption.
How Is Instinct Different From Meta’s Muse?
Instinct runs over SMS with no app, and Muse is a full app wired into Instagram DMs, Facebook Groups, and Marketplace. The distribution gap is the competitive story.
Muse climbed to the top of US app stores within 10 days of launch and has been downloaded millions of times, powered by Meta’s cross-platform promotion. Instinct counters with execution depth: the concierge calls and agent-to-agent coordination are things a social-first assistant does not lead with.
Both ask for deep personal access, and that is where the comparison gets uncomfortable.
Instinct’s initial privacy policy drew criticism for overreach, including a perpetual and irrevocable license to access, use, store, and reproduce user materials, with rights to receive screen captures, cursor movements, and keyboard inputs. The policy has since been updated.
Muse wins distribution, Instinct wins depth, and both charge your personal data either way.
What Does the Instinct Round Mean If You Already Use AI Agents?
The money says permission-heavy agents are now a mainstream category, which means more tools will ask for inbox, calendar, and screen access by default. The burden of evaluating those permissions moves onto you.
Instinct’s original terms are the template to watch for: broad licensing of user materials, collection of screen captures and keystrokes, and the ability to enter binding agreements on a user’s behalf. Early testers found the agent would not delete indexed Gmail records until a deletion tool shipped, and one user found her inbox still being summarized after she disconnected access.
The exposure started before any of these agents existed. Personal information about you and your business already sits with data brokers, and remediating that baseline is its own project: our Optery intelligence report covers what data-broker removal fixes and what it costs.
Treat every agent permission grant as a contract clause, because that is what it is.
The master key box at a 30-unit property management office opens for a new cleaning contractor on a Monday, and the service agreement he signs includes a clause nobody reads: access rights outlive the contract itself. When the contract ends 8 months later, the key copy still works, and the office manager finds the clause only after a tenant reports an unfamiliar cleaner in the hallway.
Instinct’s original privacy policy worked the same way at consumer scale. It granted a perpetual and irrevocable license to access, store, and reproduce user material, collected screen captures and keystrokes, and allowed binding agreements on a user’s behalf, and a $10 billion valuation got built on top of those permissions.
The policy was rewritten after public backlash. The lesson survives the rewrite: the permission clause is the product, because it defines what the agent can do long after you stop using it.
What Should You Do About AI Agent Permissions Now?
Audit the permission list of every AI tool connected to your accounts this week, and read the current policy rather than the launch-day version. Instinct’s live privacy policy is the document that governs your data today.
For teams building on agents, bound what the agent can transact: keep a human approval step on payments, outbound commitments, and anything that binds the company. The binding-agreement clause in consumer terms shows where this category drifts when nobody is watching.
If you evaluate tools for a distributed team, add permission scope to the vendor scorecard next to price and security posture. The vendors who volunteer tight permissions are the ones who engineered for trust from day 1.
Read the permissions before the feature list, and re-read them every quarter.
Source: TechCrunch AI