Instinct user alleges assistant surfaced another person's financial details

Pritak posted screenshots on September 21st showing Instinct discussing a financial document and saying a photo had crossed into the chat. Founder Noah Shinn denied a data breach, but the screenshots do not establish whether another user's information was exposed or the assistant generated the details.

By · Published

Primary source: Business Insider

Why it matters

Instinct wants access to personal messages, devices and accounts so it can act for users. The incident tests whether Shinn can make the assistant's privacy boundaries credible through evidence and product safeguards.

A person closely examines abstract, complex data visualizations on a large computer monitor in a modern office.

Noah Shinn, Instinct's 23-year-old founder, faces questions about the assistant's privacy boundaries after a user posted screenshots showing it discuss a financial document and claim a photo had crossed into the conversation. The user said he had never supplied the photo. Shinn denied that user data had been shared, but the public evidence does not establish what happened behind the scenes.

Shinn has worked on the reliability problem from the research side. Before starting Instinct, he was a research scientist at Sierra and worked on tau-bench, a benchmark for testing how AI agents interact with users and tools while following domain-specific rules. That background puts the incident against the promise behind Instinct: an assistant that can act across a person's digital life has to keep information associated with the right person.

The user, Pritak (@prit4k), posted screenshots on September 21st. As described by Business Insider, Instinct appeared to provide a middle name and discuss a Gerber financial document and photo that Pritak said he had never supplied. The assistant then apologized and said the photo had "got crossed into" the chat, calling it a serious glitch.

Pritak's post on X

Pritak asked whether the exchange showed a data leak or a hallucination. On September 23rd, Shinn denied that user data had been shared or that an isolation boundary had been violated.

Shinn's post on X

The available evidence does not establish whether information crossed between accounts or the assistant generated the details. The screenshots show what the assistant said, not the source of the information; Shinn did not publicly describe evidence supporting his denial. For a product designed to work with personal messages, screens, audio, location and connected applications, either possibility raises a different concern. RuntimeWire's review of the incident found that the underlying cause remains unresolved.

An assistant with access to personal context

Instinct's website describes an assistant that connects to applications and devices, including email, messaging, screens, audio and location. Users can text or call it rather than opening a separate assistant interface. Its intended jobs include following up on conversations, arranging rides and booking services. The design asks users to give the system broad context and, in some cases, the ability to take action.

Shinn has described Instinct's privacy architecture as using isolated sandboxes, short-lived local credentials and identity-signed tool execution. Those are claims from the founder; they do not independently verify how the system behaved in the exchange shown in the screenshots. The assistant's own confident explanation of an error cannot serve as a security log: here, it reportedly described a transfer that Shinn denied had occurred.

Shinn also said his team had spent the prior 48 hours working on an "active hallucination detection system." He described it as a layer that can steer or intercept Instinct before a subsequent reasoning trace or tool call is generated or executed. He said he would share more about it in the coming weeks. He provided no technical details, evaluation results or measure of how often the detector catches errors. The system is a stated response to the incident, not a demonstrated fix.

The stakes behind the agent bet

Instinct is built around delegation rather than a chat window: it is meant to remember context and carry tasks across services. Correct handling of identity and information boundaries is part of that product. A conversational mistake can be corrected in a reply; a tool-enabled assistant also has to avoid acting on invented context or presenting one user's material as another's.

Shinn's earlier research offers a useful lens on the reliability question, without proving anything about Instinct's current safeguards. Tau-bench evaluates agents' performance and reliability in real-world settings with dynamic user and tool interactions. Instinct's incident puts that reliability question in front of users, where the supposed source of truth is their own private information.

The financing behind Instinct has raised expectations around the product. In August, Instinct reportedly raised $250 million at a $2.5 billion valuation in a round co-led by Index Ventures and Benchmark, taking reported total funding to about $350 million. RuntimeWire also reported on the financing in August. The capital gives Shinn room to build an assistant that handles more tasks, while making user trust more consequential as Instinct expands access and asks people to connect more of their lives.

Shinn's immediate task is to make the explanation legible in product terms. He denied that the apparent disclosure came from a cross-user data leak and said detection work was underway. The public record still leaves users without a way to distinguish fabricated personal details from information retrieved across accounts.

Reader comments

Conversation for this story loads after sign-in.