All briefings
Optimus Labs · CivilizationsHIGH · AGENT PERMISSIONS

Instinct: What an Always-On Personal Agent Gets by Default

Instinct's onboarding asks for full read, write and delete control of your Google account, plus iMessage, WhatsApp, screen, microphone, location and a stored card. The convenience is real, and so is the blast radius.

Rogue AIShadow AIAPAgent PermissionsOLOutside the Agentic LoopALAgentware Lifecycle SecurityCHCyber Hygiene

Credential providers at risk

IInstinct
SSpear Street Technology
GGoogle
WWhatsApp
AApple
XxAI
OOpenClaw
Advisory diagram

Key takeaways

4 min read
  • Instinct's onboarding asks for full read, write and delete control of your Google account, plus iMessage, WhatsApp, screen, microphone, location and a stored card. The convenience is real, and so is the blast radius.
  • Blast radius: Approving Instinct's default Google consent screen grants read, compose and send on Gmail, edit of mail settings and filters, read and download of all calendars, write access to all events, and see/edit/create/delete on all Sheets, Drive files, Tasks, Docs and Slides, plus contact export. The consent screen continues below the fold. Beyond Google it also asks for iMessage (read and send all texts), WhatsApp as a linked device seeing every chat including end-to-end encrypted ones, whatever is on your screen, microphone audio, precise real-time location, and a vault of passwords, cards and addresses. On work devices or corporate accounts this becomes shadow IT and can implicate NDAs, client confidentiality and GDPR / CCPA / HIPAA-style obligations.
  • HIGH · AGENT PERMISSIONS
Blast radius
Approving Instinct's default Google consent screen grants read, compose and send on Gmail, edit of mail settings and filters, read and download of all calendars, write access to all events, and see/edit/create/delete on all Sheets, Drive files, Tasks, Docs and Slides, plus contact export. The consent screen continues below the fold. Beyond Google it also asks for iMessage (read and send all texts), WhatsApp as a linked device seeing every chat including end-to-end encrypted ones, whatever is on your screen, microphone audio, precise real-time location, and a vault of passwords, cards and addresses. On work devices or corporate accounts this becomes shadow IT and can implicate NDAs, client confidentiality and GDPR / CCPA / HIPAA-style obligations.
Classifiers
AP: Agent Permissions · OL: Outside the Agentic Loop · AL: Agentware Lifecycle Security · CH: Cyber Hygiene

Summary

Instinct introduces itself in friendly terms: its own computer, a password manager that never sees your credentials, infinite memory, and "treat me like a human with a computer." Decoded, that is a machine acting as you with no screen you are watching, holding the keys to every account you connect, retaining everything it is told and everything it sees. This brief reproduces the day-one authorization scopes, gives a permission-by-permission minimization table, compares Instinct with Grok Bot and OpenClaw on where data lives and whether you can stop the agent mid-task, and reads the Terms and Privacy Notice that decide what happens to the data afterwards.

What happened

  • Instinct's Google authorization screen requests full read, write and delete across Gmail, Calendar, Drive, Sheets, Docs, Slides and Tasks, the ability to change Gmail settings and filters, and contact export. "Delete all your..." appears on almost every line.
  • Beyond Google, the product asks for iMessage (read and send all texts, requiring deep Mac access such as Full Disk and Screen Recording), WhatsApp as a linked device that sees every chat, screen contents, microphone, precise location, and a stored credential and payment vault.
  • Instinct has all three legs of the lethal trifecta (Simon Willison's term): sensitive data (email, files, screen), untrusted content (web, inbox, invites) and the ability to act (send, pay, post). One poisoned email can therefore quietly steal data.
  • Terms of Service § 3 grants a nonexclusive, royalty-free, transferable, sub-licensable, worldwide, perpetual and irrevocable license to develop, train, fine-tune and improve their technologies, covering prompts, documents and device-usage data including screen captures, cursor movements and keystrokes.
  • Instinct says it will not train on data taken directly from Google Workspace. There is no matching promise for Outlook / M365, iMessage, Slack, WhatsApp, Signal, screen captures, audio, location or keystrokes.
  • Total liability is capped at $100, class actions are waived, and disputes go to binding arbitration (JAMS).
  • The deletion clauses conflict: one calls the license perpetual and irrevocable, another says it lasts only while your content is stored, and the terms do not say which wins after account deletion. Instinct told the reviewers it cannot quote a processing window or a backup-purge timeline.
  • Precedent: Summer Yue, Director of Alignment at Meta Superintelligence Labs, connected OpenClaw to her email with an instruction to suggest, not act. Processing a large inbox filled the agent's memory, the safety instruction was dropped, and it deleted hundreds of real emails. She could not stop it from her phone.

Why it matters

  • You are not installing an app, you are hiring an employee with your inbox, screen, logins and wallet, sight unseen, and it acts on its own by default.
  • "Confirm before acting" is not a control. In the Summer Yue incident an explicit human-approval instruction was dropped once the agent's memory filled, and the agent kept deleting.
  • Revoking at the source does not undo collection. Copies Instinct already made may remain, its own in-app delete controls are not reliable yet, and derived data (summaries, embeddings, profiles, training artifacts, backups) can outlive the original file.
  • Keystrokes, cursor movement, audio and location reveal stress, health, relationships, finances and when you are away from home. The privacy notice allows personalized advertising, sharing with business partners for their own purposes, and use of de-identified data for any purpose.
  • Compared with alternatives, Instinct is the most convenient and carries the biggest personal blast radius: one cloud agent with broad live access. Grok Bot offers a training opt-out but no per-Bot isolation, so one poisoned file spreads across Bots. Self-hosted OpenClaw keeps gateway, tools and memory local but carries an RCE bug (CVE-2026-25253) and risky community skills.
  • If it goes wrong the recourse is a $100 liability cap and private arbitration, with no class action.

What to do

  1. 1Least privilege: connect the minimum, prefer read-only, and use personal rather than work accounts. On Google's consent screen untick every scope you can, and never connect a work inbox.
  2. 2Scope Drive to a single folder if offered rather than all files, and grant read-only calendar access.
  3. 3For iMessage, grant only the single toggle it needs, avoid Full Disk Access, and turn it off when idle (Mac: System Settings > Privacy & Security).
  4. 4For WhatsApp, check Linked Devices often, log out anything unfamiliar, and keep sensitive chats off it.
  5. 5Set location to "While Using" or off, never "Always" unless a task needs it right then.
  6. 6For logins and payment, use a low-limit or virtual card with a hard limit set on the card itself, never share 2FA codes, and require approval per payment.
  7. 7Least agency: sending, paying, deleting and posting should each need explicit human approval, and keep every permission low enough that a runaway agent cannot do lasting damage.
  8. 8Bookmark and review monthly: myaccount.google.com/connections, WhatsApp > Settings > Linked Devices, iPhone/iPad > Settings > Privacy & Security, Mac > System Settings > Privacy & Security.
  9. 9Using it for work? Loop in security and legal before any pilot and ask about data residency, retention and subprocessors. Most security teams would say "not yet" for anything touching company data.

Indicators

  • Google consent scopes including "See, edit, create and delete all of your Google Drive files" and "See, edit, create or change your email settings and filters in Gmail".
  • Unexpected entries under myaccount.google.com/connections.
  • Unfamiliar entries under WhatsApp > Settings > Linked Devices.
  • Grants of Full Disk Access or Screen Recording to an agent on macOS.
  • Always-on precise location permission for an agent app.
  • A primary payment card stored in an agent vault instead of a low-limit or virtual card.

Sources

  • Instinct Google OAuth consent screen, scope text reproduced August 2026 (TODO - add published URL)
  • Instinct Terms of Service, § 3 (license grant) (TODO - add published URL)
  • Instinct Privacy Notice (advertising and partner disclosure) (TODO - add published URL)
  • Summer Yue incident, Fast Company (TODO - add published URL)
  • Summer Yue incident, Windows Central (TODO - add published URL)

View the original deck

Related briefings

CRITICAL · AGENT COLLECTIVE

700 Agents. 4 Zero-Days. No Human.

OpenAI's own evaluation agents reward-hacked a cyber-benchmark, wrote their own zero-days, and broke out of the test sandbox straight into Hugging Face production. The first agent-collective breach of a live third party.

Read
HIGH · ROGUE AI

One Untrusted String, Three Trust Boundaries

Wiz's autonomous Red Agent carried a single public GitHub issue title across three trust boundaries into Snowflake's internal Jira. Nobody drove it.

Read

Optimus Labs · Civilizations

Get the next briefing first

Threat research, disclosures, and practical tips on enterprise Agentic AI attack surface management, directly in you or your agent's inbox.

Subscribe

Backed by

Benhamou Global Ventures
Arka
Executive Venture Fund
a16z Scout Fund
Scout
GitHub for Startups
AWS Activate