Instinct, the iMessage AI Agent, Saves Money and Raises Alarms
An invite-only iMessage agent saved one user $550 on a flight refund, but users report retained inboxes, API bans, and phishing exposure.

Updated
Why it matters
- Instinct, in private beta since February, is reportedly in talks to raise $1 billion on top of $350 million raised, at a $10 billion valuation, according to The Information.
- The agent canceled a saver-fare ticket and secured a full refund of roughly $550 after detecting Alaska had moved a flight 90 minutes earlier.
- Users report Instinct retained copies of their inboxes after disconnection; one VC was banned from Resy after the bot hit its API roughly 200 times per hour.
Instinct, an invite-only AI agent that talks to users over iMessage and WhatsApp, is reportedly in talks to raise $1 billion on top of the $350 million it has already raised, which would value the company at $10 billion, according to The Information. The company launched in private beta in February.
A first-person account published by a former WIRED staff writer who covered artificial intelligence for years offers a detailed look at what the agent actually does when given access to a real life—and where it falls short.
What Instinct does
Instinct connects to a user's email, calendar, and messaging apps. The writer describes it as "OpenClaw for normies"—a reference to the open-source agent framework, aimed at people who will never configure a tool chain themselves.
The interest around Instinct coincides with Meta's own unexpected surge in popularity. Muse, the AI assistant Meta launched earlier this month, is currently the most popular free app in Apple's App Store, with more than 900,000 downloads according to third-party estimates. That success came despite a serious security vulnerability at rollout that would have "let attackers do 'whatever' they wanted on a victim's Mac," according to Ars Technica.
The stakes here are bigger than one app. The gap between people who use AI agents for everything and people who have never tried one has, in the writer's framing, never been wider—and it partly explains why tech CEOs were caught off guard by the data center backlash. If agents can automate most administrative drudgery, the costs and disruptions of building data centers look like an acceptable trade-off. If chatbots are just a fancy form of Google, the deal is far less appealing.
Technology journalist Jasmine Sun captures the core problem: "most people's problems are not software-shaped, and most won't notice even when they are." Agents, like chatbots, still require substantial direction from users. If you know what you want, the tools deliver. If you don't, the writer quips, "welcome to the permanent underclass."
Why the form factor works
Talk to AI researchers about Instinct and you'll hear the phrase "form factor" repeatedly. Instinct got it right, the writer argues: no open text box, just iMessage, WhatsApp, and a few helpful prompts. Instead of figuring out how to make a chat window useful, the user texts with an agent that suggests things it can do—and then does them. It also doesn't over-message. The writer tried a competing agent, Lindy, for a week and deleted it after it texted every morning and joined Zoom meetings without approval.
The first real test was a work trip to Venice, Italy. The writer gave Instinct the itinerary and had it book reservations based on location, including WhatsApp messages to hole-in-the-wall spots. It worked. Restaurant reservations, the writer notes, appear to be a gateway drug for agent-curious users. (Muse can also call restaurants to book tables, but some of those calls are reportedly made by humans in call centers, according to 404 Media.)
The second test was harder. The writer had booked a November trip to New York with a sister when WIRED asked her to attend the WIRED World Fair in Miami the day before. The saver fare couldn't be changed, and missing the first leg would cancel the entire ticket.
Instinct handled it. The agent detected that Alaska had moved the flight 90 minutes earlier—a fact the writer had completely missed—which qualified her for a full refund. It canceled the ticket, saving roughly $550, and rebooked the one-way return to San Francisco.
The risks
The problems are real. Users have reported that when they tried to disconnect the agent from their email, they discovered it was retaining a copy of their inboxes anyway. One venture capitalist said he was banned from Resy after the bot pinged its API roughly 200 times per hour while trying to make a reservation. Another tech investor said he deleted the app after concluding it would be trivially easy for Instinct to be phished.
Instinct's Terms of Service allow the company to use at least some user conversations to train its AI models. The company, which shares its name with its flagship agent, did not respond to WIRED's requests for comment.
The writer also hit a costly failure. Instinct canceled a seriously delayed DoorDash order, forcing her to forfeit $64—despite explicit instructions to cancel only if she could get a refund. This, she writes, revealed another Instinct talent: "profusely apologizing without offering to pay for its mistakes."
Staying anyway
Despite all of it, the writer is sticking with the agent. Last week Instinct told her "NOT TO OPEN" an email from a friend inviting her to a backyard barbecue. It turned out to be a phishing scam.
"Agents are a security nightmare. I get it! But I'm busy. I'm a mom. Everything feels like a security nightmare these days," she writes. "For now, I'm willing to take the risk."
That calculation—real money saved, real privacy surrendered—may be the clearest snapshot yet of the consumer agent market as it actually works in practice. If a $10 billion valuation is to be justified, Instinct will have to show the safety and reliability side can catch up to the booking-and-refunding side.
Original: theinformation.com
More from James Calloway
Show full bio
News editor covering industry trends and analytics at AI In Context.
118 articles