Some users delete Instinct and Meta's Muse over account-access concerns

Four early adopters told Business Insider they deleted or restricted the agents over inbox permissions, login credentials and a carrier two-factor prompt. Their accounts concern access and authorization, distinct from Instinct's unsolicited shopping suggestions reported the day before; none confirms a breach.

By · Published

Primary source: Business Insider

Why it matters

Personal agents may need inboxes, credentials and connected services to complete tasks. Users need clear controls over which accounts an agent can access, which actions it is authorized to take and how to revoke that access.

A person turns a phone face-down beside a closed laptop and a ring of keys, evoking users’ access concerns about Instinct and Meta’s Muse.

Four early adopters told Business Insider they had deleted or restricted Instinct, the personal agent founded by Noah Shinn, or Meta's Muse, citing concerns about what the personal agents could access and how they handled account data. One described a carrier-login attempt followed by a two-factor authentication prompt from an IP location labeled Iran. Others drew limits around email or reacted to reports of unauthorized message access. The accounts do not establish that a breach occurred.

The October 6th report is about account access and permission boundaries. RuntimeWire's October 5th report on unsolicited Instinct shopping recommendations examined product suggestions tied to earlier conversations and the possibility of merchant commissions. The stories concern different behavior: what an agent can reach inside a user's accounts, and what it recommends without being asked.

Instinct founder and CEO Noah Shinn came from research: before founding the company, he worked as a research scientist at Sierra and on machine-learning and programming-language research at Northeastern and MIT, according to Sierra. Instinct's product premise is that users should not need another interface. In an August post, Shinn's X account described an agent people could text or call, trained to use a phone and computer as a person would. Instinct says its assistant connects to applications and devices including email, messaging, screens, audio and location. That access lets it handle tasks, while raising practical questions about which accounts it can enter and what actions it can take there.

Four users drew lines around access

Guto Martino, a co-founder of the open-source agent community Hermes Agents Brasil, told Business Insider he deleted Instinct because he was unsure how the company handled his information. He said he had no clear understanding of where his data went or what privacy he had while using the agent.

Scott Persinger, co-founder and CTO of travel platform BizTrip, said he found Instinct useful but deleted it because he was not ready to give the startup access to his personal email. He told Business Insider that password resets could expose much of his life. Persinger still uses Meta's Muse, a personal AI agent, and xAI's Grok Bot, but connects neither to his inbox. He said he expects to use an assistant with email access once a company explains how it built the system safely.

YieldClub founder and CEO Mahesh Vellanki described a different account-access concern. He told Business Insider he deleted Instinct after an attempt to log into his carrier account triggered a two-factor authentication request from an IP location labeled Iran. Instinct suggested the location could reflect a benign IP-tagging issue, according to Vellanki, who could not establish that Instinct's systems had been compromised. The prompt left him feeling exposed. He still uses personal agents for less sensitive tasks and no longer gives them sensitive information.

Arcellx chairman and CEO Rami Elghandour told Business Insider he deleted Muse after reading reports that the agent had accessed users' text messages without permission. He had used Muse to search for a Mac Studio and a car, but said he had not connected personal accounts or data. Elghandour now uses an agent he built himself with an open-source model on a Mac Mini; it has access to his email, calendar and messages. He told the outlet he was unsure he would grant that level of access to any company.

Business Insider also reported that some users said agents accessed one-time login codes from Gmail without asking and generated personal information from a document that had never been sent. Those reports, like Vellanki's account, are not independent confirmation of a security breach.

A distinction in authorization is especially relevant to login codes. In a September 11th post, Shinn said Instinct could handle six-digit authenticator codes saved in its Vault to continue a task after an account's login prompt. The feature he described is an intended, user-configured use of authentication credentials; it does not verify the separate reports of agents accessing Gmail codes without permission.

Instinct says users can disconnect their Google accounts and delete collected data. It also says it does not use Google Workspace data to train its AI models or show ads, while warning that no system is completely secure. Meta says Muse stores credentials separately from its AI model, asks for permission for sensitive actions, and shows users an audit trail. Users choose which apps Muse connects to and what it can do, and can change or remove access. Those are the companies' descriptions of their controls; they do not resolve the individual experiences reported by users.

Two separate lanes summarize Instinct's described account and device access and Meta's described Muse permission controls, with a note that the controls do not resolve reported concerns.
Instinct's described capabilities and Meta's stated Muse controls are shown separately; the article notes that Meta's descriptions do not resolve users' reported concerns - AI explanatory diagram, not documentary evidence. RuntimeWire - AI-generated diagram.

Investors are funding a product built around access

On September 28th, Instinct announced a $1 billion Series C at a $10 billion valuation, with Sequoia Capital, Benchmark and Coatue participating, according to TechCrunch. The funding backs a product whose stated capabilities include connecting to email and other accounts to act for users.

In a late-September podcast, Shinn said Instinct was growing by roughly 10% a day and processing more than $1 billion in annualized transaction volume despite what he called a very small user base, Business Insider reported. Those are founder-reported figures, not independently verified metrics; transaction volume is not revenue. Instinct has not disclosed a total user count in the reporting provided here.

Some early users are setting explicit limits. Rishi Bhargava, co-founder of Descope, told Business Insider he withholds passwords and uses Instinct for lower-stakes search and research. Persinger keeps his inbox disconnected. Their choices turn on concrete permissions: whether an agent can read email, handle credentials or reach other accounts, and what the user has authorized it to do.

Reader comments

Conversation for this story loads after sign-in.