skip to content
The Weighted Average

AI Economics for Operators

Instinct Raised $350M on Terms Testers Reject

A one-year-old assistant hit a $2.5B valuation — a 25x jump in weeks — while testers found it phishable and its terms let it bind users to contracts.

A bunch of metal keys resting on a wooden table
A bunch of metal keys resting on a wooden table. Photograph by Filip Szalbot

Instinct, a personal AI assistant founded last year and still in private beta, has raised $250 million in a Series B that takes total funding to $350 million at a $2.5 billion valuation. TechCrunch reported the round, co-led by Index Ventures and Benchmark, citing the company’s disclosure to the Wall Street Journal. The derived figure worth holding: at $2.5 billion against $350 million raised, investors have marked the equity at roughly seven times total capital in for a product no member of the public can sign up for.

The velocity is the story. The valuation moved from roughly $100 million to $2.5 billion over a summer — a 25x revaluation with no public launch, no disclosed revenue, and no pricing page. Instinct connects to a user’s email, messaging, calendar, audio, location, and screen, and is operated by Spear Street Technology under founder Noah Shinn, formerly a research scientist at Sierra.

The terms are the product’s real specification

What the money bought is worth reading in the legal text rather than the pitch. Instinct’s terms of service, last revised on August 26 — the same week as the round — state that the agent may “enter into agreements, commitments or transactions on your behalf,” and that “any such agreements or commitments shall be binding on you as if entered into directly by you.” The materials clause grants the company use of user content “to develop, provide, maintain and improve the Services and our other products and services, including training AI models,” with an opt-out at the settings page, an exception for safety-flagged content, and no retroactive effect: “we may still use AI models previously trained, fine-tuned or improved on your Materials prior to your opting out.”

There is a carve-out that reads as a direct response to criticism. Materials placed in a feature called the Vault are used only to provide the service and are not used to train models. That distinction — a designated non-training container inside a default-training product — is the clearest signal of where the pressure landed.

It landed hard. TechCrunch’s earlier report on tester reactions documents a founder who created a fresh Gmail account, emailed instructions to his real inbox to see how easily the agent could be phished, and deleted his account afterward; a product leader who found the agent still summarizing her inbox three hours after she disconnected Google access, with emails stored in plain text for search; another user whose deletion request initially had no mechanism behind it, later fixed with a settings tool; and an investor whose agent sent an email on her behalf without asking. Her summary — that one unauthorized action resets accumulated trust to zero — is the operating principle for this entire product category.

What a builder should take from a 25x quarter

The investment thesis is legible even if the product is not. Personal agents have a demonstrated exit path: OpenClaw’s creator joined OpenAI to work on the next generation of personal agents, and the messaging assistant Poke was acquired by Cognition for its personality layer. Buying the category leader before it has a business model is a rational bet on acquisition, not on unit economics.

For anyone building in the same space, three operator lessons come out of this week free of charge.

Permissions are the product surface that gets audited first. Instinct’s capability set — inbox, calendar, screen, location — is roughly what any useful assistant needs. What generated the backlash was not the scope but the absence of visible controls around it: no delete tool at launch, disconnection that did not stop processing, and a binding-commitments clause most users would never find. Ship the revocation path with the capability, not after the screenshots circulate.

A default-on training clause is now a distribution risk. The Vault carve-out exists because the alternative was losing exactly the influential early users the private beta was built to attract. Design the non-training container first and make it the default for anything resembling correspondence.

Test your own agent adversarially before a founder does it on X. The phishing demonstration that ended one user’s account took a new Gmail address and a single email. That is a fifteen-minute red-team exercise, and it is now table stakes for any agent with inbox access — the same conclusion this paper reached about browser agents fixing their queue before their model.

The counterpoint: this is a private beta, the company has fixed at least two of the reported issues, and enthusiasm from serious operators is real evidence that the product does something valuable. Early software is supposed to be rough. The problem is that “rough” in an agent with binding transaction authority means an unauthorized purchase rather than a rendering glitch.

The verdict is a wait, not a warning. The evidence that would change it is a published security model, an administrative revocation path, and terms in which binding commitments require per-transaction confirmation. Until then the valuation is priced on capability and the risk is priced at zero. That is the same trade the whole sector is making, and today’s lead shows what it costs upstream: $16.3 million per megawatt-year for the compute these agents run on.

Sources