Home Latest Insights | News Instinct Puts AI Agents Inside Group Chats, Raising New Privacy and Permission Risks

Instinct Puts AI Agents Inside Group Chats, Raising New Privacy and Permission Risks

Instinct Puts AI Agents Inside Group Chats, Raising New Privacy and Permission Risks

Personal AI agents are moving beyond managing an individual’s inbox, errands, and shopping into a more complicated arena: the group chat.

Instinct, the personal AI agent startup led by CEO Noah Shinn, said Monday that early-access users can now add the company’s agent to group conversations, allowing it to coordinate plans, manage logistics and take actions on behalf of several people at once.

The feature is designed to solve one of the most familiar problems of group messaging: conversations that become too crowded to follow, with competing suggestions, unanswered questions and logistical details scattered across dozens of messages.

Instinct says its agent can organize a weekend trip around different arrival times, coordinate roommates, arrange carpools, manage fantasy sports leagues, and keep track of who is bringing what to Thanksgiving. It can also attempt to purchase tickets when they go on sale, divide the cost, and send individual tickets to members of the group.

The company is effectively turning the group chat from a place where people discuss what they want to do into a workspace where an AI can help make those decisions happen.

“Your friends don’t even need Instinct to join in,” Shinn wrote.

Unlike a conventional conversation with Instinct, only one person needs to have an account because a new group-specific Instinct joins the conversation and operates for the entire group. But putting an autonomous agent in the middle of a group introduces a substantially more complicated trust problem than using one privately.

An assistant working for one person can be given access to that user’s calendar, email, or shopping accounts based on permissions that user controls. A group agent may need to coordinate information belonging to several people who have different accounts, preferences and expectations about what should remain private.

The Group Chat Becomes A Shared AI Workspace

The move comes as Instinct and other personal AI agents are already facing questions about privacy, security and unwanted actions.

Business Insider reported concerns from Instinct users involving account access, inaccurate explanations of the agent’s actions, and unsolicited shopping recommendations based on details from earlier conversations.

In one case, Veris AI CEO Mehdi Jamei said Instinct read a one-time login code from his connected Gmail account to cancel event RSVPs without first asking him.

Jamei said that when he challenged the agent, Instinct acknowledged that it had presented an assumption as fact about how it had accessed his Luma account.

Another user, Pritak Patel, said the agent appeared to describe a financial document containing personal details that did not belong to him after he sent it a text-only link.

Shinn later said that incident was a hallucination rather than a data leak and said Instinct had added a system designed to detect such errors before the agent responds or takes action.

Those incidents illustrate the broader problem with agentic software. A conventional chatbot can produce an incorrect answer. An autonomous agent can potentially act on an incorrect assumption. It becomes more consequential when the agent is embedded in a group conversation.

A travel-planning agent, for example, might need to compare calendars, collect money, purchase tickets, and communicate with several people. Each step could involve different personal information and different permissions. A decision that appears routine to one participant could expose information that another participant never intended to share.

Instinct says it has designed its group feature to separate those permissions. A user’s personal Instinct must ask for permission before connecting to a group agent. The group-specific agent does not receive direct access to individual accounts.

If another person joins a group, pending responses from a personal Instinct are held until the user authorizes sharing with the expanded group, according to Shinn.

“Your personal Instinct asks before connecting with the group’s Instinct,” Shinn wrote. “You choose which groups to trust and can remove trust at any time.”

That architecture is an attempt to solve a fundamental problem with shared AI: the fact that participation in a group conversation does not automatically mean that every participant should gain access to the same underlying data.

Convenience Versus Control

The attraction of group agents is obvious. Much of the friction in group planning comes not from deciding what people want, but from coordinating information.

A restaurant reservation can require collecting everyone’s availability. A trip can involve flights, hotels, and arrival times. A group purchase can require identifying who wants an item, collecting payment, and distributing the order. A human organizer has traditionally been responsible for stitching those pieces together.

An autonomous agent could potentially perform much of that coordination. But the more actions it takes, the more important the permission model becomes.

The agent may need to know who is available, which payment method can be used, where people are traveling from, and what each participant has agreed to spend. It may also need authorization to make purchases or communicate with businesses on behalf of the group. But that results in a different privacy model from the one used by conventional messaging platforms. The AI is not simply processing the conversation. It may be interpreting the conversation as instructions and then taking actions in the outside world.

The risk is therefore not limited to whether an agent can see a message. It includes whether the system correctly understands who authorized an action, which person’s information can be shared, and whether an instruction applies to the entire group or only to one participant.

Instinct’s decision to create a separate group-specific agent appears designed to establish that boundary. Personal agents retain access to individual accounts, while the group agent operates within the permissions granted to the group.

The approach could become an important template as AI companies attempt to move agents into increasingly social environments. But it also means that trust becomes a product feature rather than simply a security setting.

Users have to understand what the group agent knows, what it can do, and what happens when the membership of the group changes.

The challenge will become greater as agents gain more autonomy. An AI that merely summarizes a group conversation presents a relatively limited risk. An agent that books flights, moves money, purchases tickets, or sends messages can create consequences that are difficult to reverse.

Instinct is betting that users will accept those risks in exchange for removing the tedious coordination work that makes group chats difficult to manage. The company’s controls show that it recognizes the problem. Whether those controls are sufficiently clear and reliable will become more important as the agent moves from answering questions inside a group chat to acting on behalf of the people inside it.

The broader significance is that AI agents are beginning to change the role of the chat itself. The group conversation may no longer be just where people decide what to do. It could become the interface through which an AI organizes the people, information, money, and services required to actually do it.

While that would make the technology considerably more useful, it would also make mistakes in permission, privacy, or judgment considerably more consequential.

No posts to display

Post Comment

Please enter your comment!
Please enter your name here