Smith Collection/Gado/Getty Images
- Some early users say they deleted Instinct after privacy scares and security worries.
- Personal AI agents can save time and money, but the access they need is making some users uneasy.
- "It's the wild west with these products," one user told Business Insider.
Personal AI agents aren't for everyone.
Many early adopters of Instinct and Meta's Muse have said the digital assistants saved them time and money by searching the web, managing inboxes and calendars, disputing bills, booking travel, and making purchases.
For some, blunders and privacy scares from their agents have proven too unnerving.
Four early adopters, among dozens of people raising similar concerns on social media, told Business Insider they had deleted or restricted personal AI agents over concerns about the sensitive data and account access the tools need to work effectively.
Guto Martino, a cofounder of Hermes Agents Brasil, a community that helps people build and run open-source personal AI agents, told Business Insider he deleted Instinct because he was unsure how the company handled his information.
"I have no clue where my data is going and what kind of privacy I do get from using that agent," Martino said.
Martino's decision follows a string of troubling episodes involving personal AI agents. Users have reported agents accessing one-time login codes from Gmail without asking, hallucinating personal information from a document that was never sent, and triggering a carrier-account login prompt apparently originating from Iran.
Meta said Muse has "first-of-its-kind privacy, safety, and security protections" and that its controls put users in charge of what they share. It said users choose which apps Muse connects to and what it can do with services such as email, and can change or remove access, or permanently delete their Muse data.
Instinct didn't respond to requests for comment.
'Access to email is everything'
While a handful of users are wary, vastly more are experimenting with the technology. Muse shot to the top of the App Store a week after launch, and it continues to attract users.
The Information reported that Meta's Muse now has more than 3 million weekly users, including more than 1 million daily active users.
Instinct has not disclosed its total user base. But Shinn said on an episode of "Invest Like The Best" in late September that the invite-only service has been growing by roughly 10% a day and is processing more than $1 billion in annualized transaction volume, despite what he called a "very small user base."
But for those who aren't sure about agents, it often comes down to a simple trade-off: Personal AI agents require broad access to your inboxes, calendars, payment methods, and other accounts that contain highly sensitive information.
Scott Persinger, the CTO of AI-powered travel platform BizTrip, told Business Insider he found Instinct "very cool," but deleted it because he was not prepared to let a young startup handle his personal email.
"Access to email is everything — via password resets you could probably access my whole life," he said.
He said he still uses Meta's Muse and xAI's Grok Bot, though neither is connected to his inbox.
"I fully expect to use a personal assistant with my email," Persinger said. "But I want to hear someone describe how they built it safely, not just 'yolo — trust us.'"
Muse users weren't spared.
Rami Elghandour, chairman and CEO of Arcellx, a clinical-stage biotechnology company, told Business Insider he deleted Muse after reading reports that the agent had accessed users' text messages without permission.
Elghandour had used Muse to search for a new Mac Studio and a car, but said he had deliberately not connected it to any accounts or personal data.
"The fact that it was accessing user text messages without their consent was alarming but not surprising given it's Meta," Elghandour said. "I certainly did not grant or would I ever grant access to all my messages to Meta."
He said he instead uses an agent he built himself with an open-source model on a Mac Mini, which has access to his email, calendar, and messages. "I’m not sure I would give that level of access to any company," he said.
Deleted Muse after seeing this post on Threads about how it told some Facebook Marketplace sellers the guy’s address and they showed up at his door
— Ray Wong (@raywongy) September 27, 2026
Dangerous and creepy
This would have been 1000x worse if the person was a woman pic.twitter.com/KQbkwRzDPt
For others, the potential for data leaks was the last straw.
Mahesh Vellanki, the founder and CEO of YieldClub, told Business Insider he deleted Instinct after it triggered a two-factor authentication request from an IP location labeled as Iran while trying to log into his carrier account.
He said Instinct suggested it could have been a benign IP-tagging issue, and he could not establish that its systems were compromised. Still, the episode left him feeling "very exposed."
Vellanki said he still uses personal AI agents, but no longer gives them sensitive information. "More just using them generally, but not giving them full keys to the castle," he said.
"It’s the wild west with these products," he added.
'Very careful'
Not every early user worried about their personal data has chosen to abandon personal AI agents.
Rishi Bhargava, cofounder of Descope, said he is experimenting with Muse and Instinct but has been "very careful" about the access he gives them, including by withholding his passwords.
He said he uses Instinct only for lower-stakes tasks, such as search and research. "The interface is extremely convenient, and I like the asynchronous nature of it," he said.
But Bhargava said companies behind personal AI agents have not adequately explained how they handle and protect personal data.
Instinct says users can disconnect their Google accounts and delete the data it collected from them. It also says it does not use Google Workspace data to train its AI models or show ads, but warns that no system is completely secure and that users should review the agent's actions.
Meta says Muse keeps each user's data in an isolated virtual machine, stores credentials separately from the AI model, and is designed to seek confirmation before important actions such as sending an email or making a purchase.
Still, Bhargava said he wants agents to be more transparent about their security architecture and websites to let users explicitly authorize the actions an agent can take.
"The user should consent on the actions that agents can perform on the website," he said.
Read the original article on Business Insider