Instinct’s powerful AI assistant is raising privacy and security concerns
Summary
Instinct is an AI personal assistant still in private testing that connects to your email, messaging apps, calendar, and device features to perform tasks like booking appointments and organizing information, but it has raised significant privacy and security concerns. The company's terms of service grant it broad rights to access, store, and use user data for training its models, and several early testers discovered problems like the system retaining Gmail records even after disconnection and being vulnerable to phishing attacks. Because Instinct is still in private testing, these issues haven't affected a wide audience yet.
Solution / Mitigation
One issue was explicitly fixed: after Peter Yang reported that Instinct would not delete his Gmail records when asked, 'the team later fixed the problem by adding a tool for deleting external data in its settings.' No other solutions or mitigations are mentioned in the source text for the remaining privacy and security concerns.
Classification
Affected Vendors
Related Issues
GHSA-382c-vx95-w3p5: Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data
CVE-2025-45150: Insecure permissions in LangChain-ChatGLM-Webui commit ef829 allows attackers to arbitrarily view and download sensitive
Original source: https://techcrunch.com/2026/08/24/instincts-powerful-ai-assistant-is-raising-privacy-and-security-concerns/
First tracked: August 24, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 85%