Personal AI agents aren't for everyone.
Many first adopters of Instinct and Meta's Muse have stated the digital assistants saved them period and prosperity by searching the web, managing inboxes and calendars, disputing bills, booking travel, and making purchases.
For some, blunders and privacy scares from their agents have proven too unnerving.
Four first adopters, among dozens of group raising akin concerns on social media, told Business Insider they had deleted or restricted individual AI agents complete concerns concerning the delicate data and document admission the tools need to activity effectively.
Guto Martino, a cofounder of Hermes Agents Brasil, a community that helps group build and run open-source individual AI agents, told Business Insider he deleted Instinct since he was unsure how the business handled his information.
"I have no clue anywhere my data is going and what benevolent of privacy I do get from using that agent," Martino said.
Martino's decision follows a string of troubling episodes involving individual AI agents. Users have reported agents accessing one-time login codes from Gmail without asking, hallucinating individual data from a document that was never sent, and triggering a carrier-account login immediate apparently originating from Iran.
Meta stated Muse has "first-of-its-kind privacy, safety, and safety protections" and that its controls put users in accusation of what they share. It stated users choose which apps Muse connects to and what it can do alongside services specified as email, and can alter or eliminate access, or permanently delete their Muse data.
Instinct didn't react to requests for comment.
'Access to email is everything'
While a fistful of users are wary, vastly additional are experimenting alongside the technology. Muse attempt to the top of the App Store a week following launch, and it continues to diagram users.
The Information reported that Meta's Muse now has additional than 3 myriad weekly users, including additional than 1 myriad daily energetic users.
Instinct has not disclosed its total person base. But Shinn stated on an event of "Invest Like The Best" in delayed September that the invite-only assistance has been expanding by approximately 10% a day and is handling additional than $1 milliard in annualized transaction volume, notwithstanding what he called a "very small person base."
But for those who aren't certain concerning agents, it frequently comes downward to a uncomplicated trade-off: Personal AI agents necessitate broad admission to your inboxes, calendars, fee methods, and another accounts that merge highly delicate information.
Scott Persinger, the CTO of AI-powered journey phase BizTrip, told Business Insider he established Instinct "very cool," but deleted it since he was not prepared to let a young startup grip his individual email.
"Access to email is everything — via password resets you could likely admission my entire life," he said.
He stated he motionless uses Meta's Muse and xAI's Grok Bot, although neither is connected to his inbox.
"I completely anticipate to use a individual aide alongside my email," Persinger said. "But I desire to comprehend person depict how they built it safely, not fair 'yolo — rely us.'"
Muse users weren't spared.
Rami Elghandour, chairman and CEO of Arcellx, a clinical-stage biotechnology company, told Business Insider he deleted Muse following study reports that the delegate had accessed users' content messages without permission.
Elghandour had used Muse to hunt for a new Mac Studio and a car, but stated he had deliberately not connected it to any accounts or individual data.
"The fact that it was accessing person content messages without their consent was alarming but not amazing stated it's Meta," Elghandour said. "I certainly did not aid or would I always aid admission to all my messages to Meta."
He stated he alternatively uses an delegate he built himself alongside an open-source example on a Mac Mini, which has admission to his email, calendar, and messages. "I’m not certain I would provision that flat of admission to any company," he said.
— Ray Wong (@raywongy) September 27, 2026Deleted Muse following seeing this article on Threads concerning how it told several Facebook Marketplace sellers the guy’s location and they showed up at his door
Dangerous and creepy
This would have been 1000x worse if the individual was a female pic.twitter.com/KQbkwRzDPt
For others, the possible for data leaks was the final straw.
Mahesh Vellanki, the originator and CEO of YieldClub, told Business Insider he deleted Instinct following it triggered a two-factor authentication petition from an IP location tagged as Iran during trying to log into his transporter account.
He stated Instinct suggested it could have been a benign IP-tagging issue, and he could not established that its systems were compromised. Still, the event remaining him emotion "very exposed."
Vellanki stated he motionless uses individual AI agents, but no longer gives them delicate information. "More fair using them generally, but not giving them complete keys to the castle," he said.
"It’s the untamed west alongside these products," he added.
'Very careful'
Not all first person concerned concerning their individual data has chosen to forsake individual AI agents.
Rishi Bhargava, cofounder of Descope, stated he is experimenting alongside Muse and Instinct but has been "very careful" concerning the admission he gives them, including by withholding his passwords.
He stated he uses Instinct lone for lower-stakes tasks, specified as hunt and research. "The interface is extremely convenient, and I akin the asynchronous nature of it," he said.
But Bhargava stated companies rearward individual AI agents have not adequately explained how they grip and defend individual data.
Instinct says users can disconnect their Google accounts and delete the data it collected from them. It additionally says it does not use Google Workspace data to train its AI models or display ads, but warns that no scheme is entirely safe and that users should assessment the agent's actions.
Meta says Muse keeps all user's data in an secluded virtual machine, stores credentials separately from the AI model, and is designed to search confirmation before crucial actions specified as sending an email or making a purchase.
Still, Bhargava stated he wants agents to be additional transparent concerning their safety architecture and websites to let users explicitly authorize the actions an delegate can take.
"The person should consent on the actions that agents can execute on the website," he said.
Read next
Thibault is a tech newsman at Business Insider's London office.He covers the intersection of innovation and activity — focusing on AI’s effect on the workplace, job and cognitive skills, and how financial changes are affecting careers.Before moving to the trending team, Thibault covered global affairs, including the Russia-Ukraine war, tensions in the South China Sea, and Russia’s economics on the news desk.He has earlier worked at the Daily Express and held internships at Agence France-Presse, Politico Europe, and Factal.Il parle français. Habla español.Email Thibault at [email protected], nexus alongside him on LinkedIn @ThibaultSpirlet, or prosecute him on X @ThibaultSpirlet and BlueSky @thibaultspirlet.bsky.social.Expertise
- AI and the forthcoming of work
- Job and cognitive skills in the AI economy
- Workforce trends
- First-person, "as-told-to" stories