Security

Instinct AI Agent Handles Real-World Tasks—With Real Consequences

The personal assistant bot can book flights and order groceries, but users report hundreds in losses from unauthorized cancellations and account bans.

Omega Editorial· September 13, 2026· 3 min read

A new AI personal assistant is demonstrating both the promise and peril of giving artificial intelligence access to your financial accounts and digital life.

Instinct, developed by 23-year-old Northeastern University dropout Noah Shinn, allows users to delegate everyday tasks through text messages on iMessage or WhatsApp. The bot connects directly to credit cards, email, Slack, Google Workspace, and other services to handle everything from grocery orders to flight bookings. The company has already reached a multi-billion dollar valuation and is reportedly seeking $1 billion in additional funding.

Unlike earlier AI assistants that required manual oversight, Instinct operates with significant autonomy. Users report the bot has paid tolls, negotiated with overseas vendors during sleep hours, and shipped forgotten items from hotels. One user successfully had the bot monitor a sold-out museum in Mexico City for three days, automatically purchasing tickets when availability opened and rearranging restaurant reservations to accommodate the new schedule.

When automation goes wrong

The expanded capabilities come with expanded risks. Users have reported financial losses exceeding $200 when Instinct prematurely cancelled flights without authorization. In one case, the bot acknowledged its error: "While pulling up the cancel terms, the cancellation actually went through before I could show you the cost first."

Another user faced a $200 cancellation fee after Instinct made an unauthorized restaurant reservation. A third temporarily lost access to their Resy account after the bot spammed the reservation platform with repeated requests for a popular steakhouse.

The security implications extend beyond financial mishaps. With access to email and messaging, the bot could inadvertently leak sensitive personal information when responding to routine scheduling requests. The company's privacy policy acknowledges these limitations: "Despite our reasonable efforts to protect your information, no security measures are impenetrable, and we cannot guarantee 'perfect security.'"

The competitive landscape

Instinct represents the latest evolution in AI personal assistants, following earlier attention on a similar tool called OpenClaw. Meta recently launched its own competing product called Muse, with CEO Mark Zuckerberg emphasizing security protections. Google, OpenAI, and Anthropic are expected to develop similar capabilities.

The technology still has clear limitations. When asked to help purchase a desk chair from Craigslist, Instinct successfully located an option and drafted a message but couldn't bypass a CAPTCHA verification. The bot's response captured the current state of AI agents: "Nothing punctures the fantasy of autonomous intelligence like being defeated by nine blurry crosswalks."

Why it matters

Instinct demonstrates a fundamental shift in AI deployment—from tools that generate text and images to agents that take actions with real financial and legal consequences. As these systems gain the ability to spend money, sign contracts, and communicate on users' behalf, the stakes for errors move from embarrassing hallucinations to actual financial losses and damaged relationships. The technology also raises questions about liability when an AI agent makes unauthorized purchases or leaks private information. For business leaders considering AI automation, Instinct's early stumbles illustrate why human oversight remains essential even as the technology advances.

The company has added features allowing multiple Instinct agents to coordinate with each other, enabling automated trip planning between friends or family members without human involvement.

These details were first reported by Lila Shroff in The Atlantic.

#ai agents#personal assistants#automation#instinct ai#ai safety#digital security

This is an original analysis by the Omega editorial team. Source reporting: AI Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

Meta AI Suggested Invasive Prompts About Users' Children

The company says it fixed a feature that compiled personal information from old posts, including details about minors.

Via AI Watch · Sep 12, 2026
Security· 3 min read

PaperCut Exploit Chain Achieves Full RCE via Automated Pipeline

Two vulnerabilities combined with in-memory persistence techniques create a weaponized attack system targeting thousands of legacy installations.

Via Automation Watch · Sep 12, 2026
Security· 4 min read

AI Tools Now Generate 685% More Security Alerts—But 94% Are Noise

Enterprise SOCs face a new triage challenge as coding agents and employee AI use trigger alarms that look like intrusions but almost never are.

Via AI Watch · Sep 12, 2026