Instinct
Viral $2.5B AI personal assistant with hypergrowth ARR but unresolved privacy and security red flags
Instinct is a $2.5B consumer AI assistant with extraordinary ARR momentum but material privacy, security, and governance risks that make the valuation stretched at current evidence quality.
Cover facts
Company profile
Instinct, operated by Spear Street Technology Inc. (California, 2025), is a consumer AI personal assistant accessed exclusively via SMS and WhatsApp. The product connects to users' email, calendar, messaging apps, audio, location, and screen, and executes tasks—booking, email management, scheduling, shopping— autonomously without requiring per-action user confirmation. Founded by Noah Shinn, a 23-year-old former Sierra research scientist and lead author of Reflexion (NeurIPS 2023), Instinct achieved viral traction in early 2026, growing ARR from ~$5 million in January 2026 to ~$80 million by August 2026. The company raised $250 million at a $2.5 billion post-money valuation in a Series B co-led by Index Ventures and Benchmark. The product remains in private beta and has attracted both significant user enthusiasm and serious adverse attention over privacy, security, and data-governance concerns.
- Website
- instinct.co
- Founded
- 2025-01-01
- Founders
- Noah Shinn
- Founding location
- San Francisco, CA
- Headquarters
- San Francisco, CA
- Product
- A consumer AI personal assistant delivered over SMS and WhatsApp. No app download required. Connects via OAuth to email (Gmail, Outlook, Apple Mail), calendar, and messaging apps; accesses device audio, location, and screen. Executes tasks autonomously: booking appointments, managing email, scheduling travel, and shopping—including entering binding transactions on the user's behalf.
- Customers
- Tech-savvy consumers seeking autonomous task management; private beta invite-only as of August 2026.
- Business model
- Not publicly disclosed. Revenue likely subscription or per-task model; $80M ARR from private beta cohort suggests paid access or credit-based pricing, though terms have not been publicly announced.
- Stage
- Series B
- Funding status
- $250 million Series B (August 26, 2026) co-led by Index Ventures and Benchmark at $2.5 billion post-money valuation; $100 million Series A (January 2026) led by Kleiner Perkins; total capital raised $350 million.
Executive summary
Top strengths
- Extraordinary ARR velocity: ~16× growth in 8 months ($5M → $80M ARR) signals strong product-market fit among early adopters.
- Technically differentiated founder (Reflexion NeurIPS 2023) with a defensible agentic-memory architecture not easily replicated by general-purpose models.
- Tier-1 investor syndicate (Index Ventures, Benchmark, Kleiner Perkins) provides strong validation, governance support, and follow-on capital access.
- SMS/WhatsApp distribution eliminates app-store friction and drives viral growth via the existing messaging install base.
- First-mover position in fully autonomous consumer AI agent category at meaningful scale ahead of big-tech entrants.
Top risks
- Perpetual irrevocable data license and plain-text email retention after OAuth revocation expose Instinct to GDPR, CCPA, and FTC enforcement actions.
- Demonstrated prompt-injection vulnerability allows malicious emails to hijack Instinct's autonomous actions, posing severe security and liability risk.
- $2.5B valuation (~31× ARR) is rich for a pre-launch consumer product with no disclosed unit economics; privacy backlash could sharply compress multiples.
- First-time CEO (age 23) at extraordinary scale creates execution and governance risk during rapid headcount growth and product launch.
- Competitor risk from Google, Apple, OpenAI, and Microsoft who have native platform integration advantages and deep consumer distribution.
Open gaps
- Pricing model and unit economics not publicly disclosed; $80M ARR basis unverifiable.
- Headcount, burn rate, and path to profitability entirely opaque.
- Regulatory response (FTC, EU AI Act) to autonomous binding-transaction capability unclear.
- Cap table, dilution history, and secondary-sale activity not available.
- Enterprise pivot potential and B2B roadmap (if any) not publicly signaled.
Contents
01Company Overview
1.1 Identity, product, and operating model
Instinct is an AI-powered personal assistant that operates entirely through text messages and phone calls—users interact via SMS or WhatsApp, asking the assistant to book appointments, manage email, organize calendars, arrange travel, handle shopping, unsubscribe from services, and act autonomously on their behalf across connected accounts and devices. The company's legal entity, Spear Street Technology Inc., was incorporated in California in 2025. The product brand is "Instinct" and the official web presence is instinct.co. The operating model is deeply permissive: Instinct connects to users' email accounts, messaging platforms, calendar, device audio, location data, and screen captures. Once integrated, the assistant acts without per-action confirmation, executing tasks autonomously. The terms of service grant Instinct a "perpetual and irrevocable" license to access, store, use, and modify all user materials, including for AI training purposes—a provision that generated sustained public criticism in August 2026. The company added a data deletion tool after early backlash, but retained the broad terms structure. As of August 2026, Instinct remains in private beta—access is by invitation or waitlist only. The company has not publicly disclosed pricing, headcount, or a commercial launch date. The product has nonetheless attracted $350 million in venture capital and reached approximately $80 million in annual recurring revenue, a scale achieved without broad public availability. Instinct's headquarter address is San Francisco, California; no specific office address has been publicly disclosed. The company describes itself as having a small team, primarily drawn from advanced AI research backgrounds at MIT and the enterprise AI firm Sierra.[CO001, CO002, CO004, CO014, CO015, CO016]
| Metric | Value / status | Date / period | Confidence | Gap / note |
|---|---|---|---|---|
| Legal entity | Spear Street Technology Inc. | historical | high | California registration; no filing number publicly confirmed |
| Brand name | Instinct | current | high | Official website instinct.co; confirmed across reporting |
| Headquarters | San Francisco, CA, USA | current | high | Reported by TechCrunch and TechFundingNews; no street address disclosed |
| Founded | 2025 | historical | medium | Year confirmed; exact month not publicly disclosed |
| Product status | Private beta (invite-only) | 2026-08-28 | high | Confirmed by TechCrunch funding and privacy articles |
| Latest valuation | $2.5B post-money | 2026-08-26 | high | Co-confirmed by TechCrunch, TechFundingNews, Index Ventures/Benchmark press |
| Total capital raised | $350M | 2026-08-26 | high | TechCrunch primary source; $100M seed+Series A + $250M Series B |
| Series B amount | $250M | 2026-08-26 | high | TechCrunch; co-led Index Ventures and Benchmark |
| ARR (annual recurring revenue) | ~$80M | 2026-08 | medium | Management-stated via TechCrunch; not independently audited |
| ARR at founding phase | ~$5M | 2026-01 | medium | Management-stated; represents approximate January 2026 ARR |
| Headcount | Not disclosed (estimated <50) | 2026-08-28 | low | Described as "small team"; no public figure |
| Customer count | Not disclosed | 2026-08-28 | low | Private beta; waitlist metrics not released |
| Founder | Noah Shinn (age 23, CEO) | 2026-08-28 | high | Confirmed across TechCrunch, TechFundingNews, multiple sources |
Revenue and headcount are management-supplied or estimated; no independent audit. Valuation and funding figures are confirmed by multiple high-reputation sources. Null entries represent confirmed information gaps as of the run date.
[CO001, CO002, CO005, CO006, CO007, CO016]Shows how Instinct's identity, product interface, underlying integrations, capital structure, and key dependencies connect in its current operating model.
[CO001, CO004, CO006, CO007, CO014, CO017]1.2 Founder background, technical lineage, and team composition
Noah Shinn is the sole publicly identified founder of Instinct and serves as CEO of Spear Street Technology. He was 23 years old at the time of the August 2026 Series B announcement. Shinn dropped out of Northeastern University in 2023, having also conducted machine learning and programming language research at MIT. He subsequently became one of the earliest employees at Sierra, an enterprise AI agent company, where he worked as a research scientist. Shinn is best known academically as the lead author of the Reflexion paper, presented at NeurIPS 2023. The Reflexion framework introduced a method for language agents to "verbally reflect" on task failures, store learnings in episodic memory, and improve on subsequent attempts without model fine-tuning. The approach achieved a 91% pass@1 rate on the HumanEval coding benchmark, substantially above GPT-4's reported 80% at the time. Co-authors included Federico Cassano, Ashwin Gopinath, Karthik Narasimhan, and Shunyu Yao. Shinn also co-developed τ-bench, a benchmark evaluating agents' ability to handle real-world user interactions, tool invocations, and business-rule compliance. This technical lineage—from academic agent research through enterprise deployment at Sierra to a consumer product—is a distinguishing credential for a founder of Shinn's age. The rest of the team is publicly undisclosed. Company materials describe a "small San Francisco team" with backgrounds from MIT and Sierra, but no other team members have been identified by name in any public reporting reviewed for this run. Board composition, investor observers, and governance structure are entirely undisclosed. The concentrated leadership creates a significant key-person dependency: the company's technical credibility, investor relationships, and product vision are publicly tied to a single individual with no succession clarity.[CO007, CO008, CO009, CO010, CO011, CO012]
| Person | Role | Source-backed background | Founder-market fit or functional note | Key-person dependency / diligence note |
|---|---|---|---|---|
| Noah Shinn | Founder & CEO | Lead author Reflexion (NeurIPS 2023); research scientist at Sierra; MIT AI research; Northeastern dropout 2023 | Deep AI agent research background directly applicable to autonomous assistant product | Extreme key-person dependency; sole publicly identified founder; no named executive team |
| Sierra (former employer) | N/A — context for founder background | Enterprise AI agent company; Shinn was earliest employees and research scientist | Provided Shinn with enterprise-grade agent deployment experience before consumer pivot | Indirect context; not a current employee |
| Unnamed team members | Various (engineering, product, operations) | Described as small SF team from MIT and Sierra backgrounds; names not disclosed | Team quality inferred from research pedigree but unverified at individual level | No individual accountability; succession plan entirely opaque |
Table limited to publicly confirmed or documented individuals. Board composition, observers, and governance structure are entirely undisclosed as of run date.
[CO007, CO008, CO009, CO010, CO011, CO023]Top-line KPIs for Instinct as of August 2026: valuation, capital raised, ARR, ARR growth, company age, and investor tier.
ARR and growth are management-supplied figures; headcount is an estimate based on characterization as a small team.
[CO005, CO006, CO008, CO016, CO039, CO041]1.3 Funding history, valuation trajectory, and investor base
Instinct's capital formation has been exceptionally rapid even by 2026 AI startup standards. From an approximate $50 million seed-stage valuation in early 2026, the company reached a $500 million Series A valuation (led by Kleiner Perkins' Mamoon Hamid) and then a $2.5 billion Series B post-money valuation in approximately six months. The August 26, 2026 Series B raised $250 million, co-led by Index Ventures and Benchmark, bringing total capital raised to $350 million. Early-stage backers include Conviction Partners (Sarah Guo), Greenoaks, and undisclosed seed participants. No debt facilities, secondary transactions, or credit lines have been publicly disclosed. The investor base is notable for its tier. Index Ventures and Benchmark are among the most selective consumer technology investors globally; Index has backed Dropbox, Stripe, Robinhood, and others from early stages, while Benchmark led investments in Twitter, Snap, Uber, and Discord. Kleiner Perkins, which led the Series A, has similarly supported iconic technology companies. For a pre-public company with no disclosed headcount, no public pricing, and a product still in private beta, this investor constellation is unusual and reflects the current intensity of competition for consumer AI agent deal flow. Notably, the $2.5 billion valuation at approximately $80 million ARR implies a revenue multiple of roughly 31× ARR—a premium consistent with the highest-growth AI software companies in 2026 but well above median SaaS multiples. This premium prices in significant future growth and successful monetization, neither of which has yet been demonstrated in a publicly visible way. No audited financial statements, unit economics, or burn rate figures are publicly available.[CO003, CO004, CO005, CO006, CO017, CO018]
| Stakeholder | Role | Economic / strategic importance | Publicly supported evidence | Diligence ask |
|---|---|---|---|---|
| Index Ventures | Series B co-lead investor | $125M+ of Series B; board seat expected but undisclosed | TechCrunch and multiple sources confirm co-lead; Index known for Dropbox, Stripe, Robinhood | Exact ownership stake, board rights, liquidation preference, and anti-dilution terms |
| Benchmark | Series B co-lead investor | $125M+ of Series B; board seat expected but undisclosed | TechCrunch and multiple sources confirm co-lead; Benchmark known for Twitter, Snap, Uber | Exact ownership stake, board rights, and preference stack relative to Series A holders |
| Kleiner Perkins (Mamoon Hamid) | Series A lead investor | Led ~$100M Series A at ~$500M valuation; meaningful diluted stake | TechFundingNews reports Mamoon Hamid led Series A for Kleiner Perkins | Exact A round economics, current ownership post-B dilution, board seat status |
| Conviction Partners (Sarah Guo) | Early / seed investor | Seed participation; relatively small stake but strong signal in AI ecosystem | TechFundingNews cites Sarah Guo (Conviction) as congratulating founder on funding | Confirm seed amount and whether Conviction holds any board observer rights |
| Greenoaks Capital | Series A participant | Growth-stage crossover; large potential position if invested proportionally | TechFundingNews lists Greenoaks among early backers | Amount invested, any secondary purchases, and governance rights |
| Noah Shinn (founder) | Founder and controlling shareholder (presumed) | Likely majority holder pre-B; post-B dilution unknown | Named sole founder across all sources; no cap table disclosed | Current ownership percentage, voting control, and drag-along rights |
| Unknown seed investors | Seed participants | Early validation; details undisclosed | Round described as including seed capital alongside Series A | Disclose full cap table and SAFE or convertible note terms from seed |
Economics inferred from deal structure conventions. No cap table, board composition, or governance documents have been publicly disclosed.
[CO004, CO005, CO006, CO020, CO021, CO022]1.4 Milestones, adverse events, and chronology of record
Instinct's public milestone record covers roughly 8 months of known operating history. The founding of Spear Street Technology in 2025 and early product development represent the origins. The company's first public visibility came in early 2026 with initial beta testing and a seed round, followed by a Series A reportedly led by Kleiner Perkins at roughly a $500 million valuation. By mid-2026 the company was growing ARR rapidly, and TechCrunch reported privacy and security concerns in its August 24, 2026 coverage before the Series B announcement two days later. The most material adverse events in the public record relate to the product itself rather than corporate governance. Beta testers reported that Instinct sent emails without explicit per-action consent, retained email content in plain text after users disconnected Google account access, and exposed users to prompt injection attacks via malicious emails. SC Media and StartupFortune covered these incidents. The company's response—adding a data deletion interface—was reported by TechCrunch but did not change the underlying terms of service. No regulatory investigations, lawsuits, or leadership departures have been publicly disclosed. The funding chronology is the most well-documented dimension. The gap in the public record includes the exact founding date within 2025, any regulatory filings, all partner or integration agreements, and any product launch or commercial opening plans. The absence of named board members, governance documents, or investor rights agreements is notable for a $2.5 billion company, even at the private stage.[CO002, CO003, CO005, CO016, CO017, CO018]
| Date | Event | Type | Amount / valuation / status | Participants | Implication |
|---|---|---|---|---|---|
| 2025 (est.) | Noah Shinn departs Sierra; founds Spear Street Technology in California | founding | Entity incorporated; seed capital likely contemporaneous | Noah Shinn; seed investors TBD | Founding marks commercial transition from research to product; exact date undisclosed |
| 2026-01 (est.) | Instinct achieves approximately $5M ARR in private beta | scale | ~$5M ARR | Internal metric; reported by TechCrunch via management | Earliest disclosed revenue benchmark; confirms product was live and generating revenue |
| 2026 Q1–Q2 (est.) | Series A closed at approximately $500M valuation; Kleiner Perkins (Mamoon Hamid) leads | financing | ~$100M raised (seed+A combined); ~$500M valuation | Kleiner Perkins, Conviction, Greenoaks, Noah Shinn | First institutional validation; enables team scaling and infrastructure investment |
| 2026-08-24 | TechCrunch publishes privacy and security concerns about Instinct's broad data permissions | adverse | Coverage; no direct financial impact reported | TechCrunch; beta testers; security researchers | First major adverse coverage; highlights perpetual data license and prompt injection risk |
| 2026-08-24 to 08-25 (est.) | Reports emerge of Instinct sending emails without consent; data retained after disconnect | adverse | Reputational; no fines or legal action disclosed | StartupFortune, ExplainX, SC Media; beta testers | Product reliability and consent model questioned; company responds with deletion tool |
| 2026-08-25 (est.) | Instinct adds data deletion tool to its interface in response to backlash | product | Feature addition; ToS unchanged | Internal product team | Responsive product iteration shows operational capability but does not resolve ToS concerns |
| 2026-08-26 | Series B closes; $250M raised at $2.5B post-money valuation | financing | $250M raised; $2.5B valuation | Index Ventures, Benchmark (co-leads); Noah Shinn | Unicorn+ milestone; 25× valuation step-up from seed in approximately 6 months |
| 2026-08-26 | TechCrunch publishes Series B funding announcement; confirms $350M total raised and $80M ARR | financing | $80M ARR as of announcement date | TechCrunch; Instinct management | Public confirmation of ARR growth from $5M to $80M in ~8 months; high media visibility |
| 2026-08-28 (run date) | Instinct remains in private beta; no commercial launch announced | scale | ~$80M ARR (private beta) | Internal | Open question: whether $80M ARR is sustainable at scale versus a concentrated early cohort |
Dates marked '(est.)' are estimated from contextual reporting. Exact dates for seed/Series A and early product events are not confirmed by primary sources.
[CO002, CO003, CO005, CO006, CO017, CO018]Chronological timeline of Instinct's founding, financing, product, and adverse-event milestones from 2025 founding through August 2026 Series B.
Dates for founding and Series A are estimated from contextual reporting; exact calendar dates not publicly confirmed.
[CO002, CO003, CO005, CO017, CO018, CO024]1.5 Exhibits
02Market Analysis
2.1 Market Definition and Scope
Instinct competes in the consumer AI personal assistant market, a segment of the broader intelligent virtual assistant industry. The market encompasses software products that understand natural language commands and autonomously execute tasks on behalf of individual consumers such as scheduling, email management, travel booking, purchasing, and information retrieval. The market excludes enterprise-only solutions, pure chatbots without action capabilities, and voice-only smart speaker assistants that lack deep device integration. Core market participants include platform incumbents like Apple Siri, Google Assistant, Amazon Alexa, Microsoft Cortana, and Samsung Bixby, as well as AI-native entrants like Instinct, Rabbit r1, and Humane AI Pin. The defining characteristic of the 2025-2026 market shift is the transition from reactive query-response assistants to proactive agentic systems that take autonomous action with minimal user confirmation. Instinct represents the leading edge of this agentic transition in the consumer segment, distinguished by its SMS and WhatsApp interface, deep permission model, and autonomous task execution capabilities. The market boundary is fuzzy at the edges: productivity SaaS with AI features, browser automation tools, and AI coding assistants overlap with personal assistant functionality but serve distinct primary use cases. For sizing purposes, this analysis focuses on products marketed primarily as personal assistants with multi-domain task execution capabilities.[CM001, CM002, CM003, CM004, CM005, CM006]
| Dimension | Included | Excluded | Instinct Position |
|---|---|---|---|
| Product Type | Multi-domain task assistants with action capabilities | Pure chatbots, single-purpose tools, enterprise-only solutions | Full-stack autonomous assistant |
| Interface | Text, voice, multimodal with device integration | Hardware-only devices without software intelligence | SMS and WhatsApp primary, voice secondary |
| Task Scope | Scheduling, email, travel, shopping, life admin | Industrial automation, coding-only, gaming | All consumer life administration tasks |
| User Type | Individual consumers and prosumers | Enterprise-only deployments, B2B-only products | Privacy-tolerant consumers with high task volume |
| Geography | Global with focus on English-language markets | Offline-only or region-locked products | US-primary with global waitlist |
| Permission Model | Device access for autonomous execution | Read-only assistants without action capability | Deep permissions including email, calendar, location, screen |
Market boundaries remain fuzzy as AI capabilities expand; Instinct positioned at the agentic frontier
[CM001, CM002, CM003]| Category | Participant | Primary Interface | Autonomy Level | Market Position |
|---|---|---|---|---|
| Platform Incumbent | Apple Siri with Apple Intelligence | Voice and text on Apple devices | Medium - requires confirmation for actions | Largest installed base via iOS |
| Platform Incumbent | Google Assistant with Gemini | Voice and text on Android and Google devices | Medium - expanding agentic capabilities | Second-largest via Android |
| Platform Incumbent | Amazon Alexa | Voice-first on Echo devices | Low - primarily smart home control | Dominant in smart speaker segment |
| Platform Incumbent | Microsoft Copilot | Text in Windows and Office | Medium - productivity-focused | Enterprise crossover with consumer exposure |
| AI-Native Startup | Instinct | SMS and WhatsApp | High - autonomous execution | Fastest-growing private beta |
| AI-Native Startup | Rabbit r1 | Dedicated hardware device | Medium - action-oriented but hardware-limited | Hardware differentiation play |
| AI-Native Startup | Humane AI Pin | Wearable with projection | Low - limited adoption due to hardware issues | Struggling post-launch |
| AI Chatbot Crossover | OpenAI ChatGPT agent mode | Text in app and web | High - expanding agentic features 2026 | Largest AI chatbot user base |
Market fragmented between incumbents with distribution and startups with agentic capabilities
[CM004, CM005, CM006]2.2 Market Sizing and Growth Trajectory
The global consumer AI personal assistant market reached an estimated 4.84 billion USD in 2026, representing a 42.2 percent compound annual growth rate from 2025's 3.4 billion USD baseline. The broader intelligent personal assistant market, which includes enterprise and hybrid deployments, reached approximately 17.95 billion USD in 2026 growing at 25.9 percent CAGR. Market projections suggest the consumer segment will reach 19.6 billion USD by 2030 if current growth rates sustain. These estimates carry significant uncertainty bounds due to definitional ambiguity around what constitutes a personal assistant versus a general-purpose AI chatbot or specialized productivity tool. Research and Markets and The Business Research Company provide the primary third-party sizing estimates, with methodologies that aggregate subscription revenue, advertising-supported usage, and hardware-bundled assistant value. The TAM represents the theoretical maximum if every smartphone user adopted a paid AI assistant; the SAM narrows to users with demonstrated willingness to pay for productivity delegation; the SOM reflects the addressable market for agentic assistants with deep permissions in 2026-2027. For Instinct specifically, the relevant addressable market is the subset of consumers willing to grant extensive device permissions and pay subscription fees for autonomous task execution. Privacy-conscious users and those in regulated industries represent structural exclusions from the addressable market. The 16x ARR growth Instinct achieved in 8 months suggests either exceptional product-market fit within its target segment or unsustainable early-adopter surge that will normalize as the waitlist clears.[CM008, CM009, CM010, CM011, CM012, CM013]
| Metric | 2025 Estimate | 2026 Estimate | 2030 Projection | Source | Confidence |
|---|---|---|---|---|---|
| Consumer AI Assistant TAM | 3.4B USD | 4.84B USD | 19.6B USD | Research and Markets | Medium - definitional ambiguity |
| Broader IPA Market | 14.3B USD | 17.95B USD | 35B USD | The Business Research Company | Medium - includes enterprise |
| Consumer AI Assistant CAGR | - | 42.2% | Projected 35-40% | Research and Markets | Medium - high variance possible |
| Agentic Assistant SAM | Not established | 1-2B USD estimated | 8-10B USD | Analyst synthesis | Low - nascent category |
| Instinct SOM (privacy-tolerant power users) | - | 200-500M USD | 1-3B USD | Internal estimate | Low - segment definition uncertain |
Market sizing carries high uncertainty due to evolving category definitions and limited historical data for agentic assistants
[CM008, CM009, CM010, CM011]2.3 Market Segmentation and Buyer Profiles
The consumer AI personal assistant market segments along multiple dimensions including task type, user sophistication, privacy tolerance, and payment willingness. By task type, the market divides into scheduling and calendar management, email and communication management, travel and logistics, shopping and purchasing, information retrieval and research, and life administration such as bill payment and subscription management. By user sophistication, segments range from basic voice-command users seeking simple Q-and-A to power users willing to grant extensive permissions for autonomous action. By privacy tolerance, the market bifurcates sharply between privacy-sensitive users who reject broad data access and convenience-first users who trade privacy for functionality. By payment willingness, segments include free-tier-only users, low-price-point subscribers under 10 USD per month, and premium subscribers willing to pay 20-50 USD or more for comprehensive assistance. Instinct's target segment appears to be privacy-tolerant power users with high payment willingness who value autonomous execution over step-by-step confirmation. This segment is relatively small but growing rapidly as generative AI normalizes data sharing. Geographic segmentation shows North America and Western Europe as primary markets due to smartphone penetration, English-language AI model maturity, and consumer spending power, with Asia-Pacific growing fastest in absolute terms. Age demographics skew toward 25-45 year old professionals who have complex scheduling needs and disposable income but lack dedicated human assistants.[CM016, CM017, CM018, CM019, CM020, CM021]
| Segment | Task Volume | Privacy Tolerance | Payment Willingness | Instinct Fit | Segment Size Estimate |
|---|---|---|---|---|---|
| Busy Professionals | High | Medium-High | High (20-50 USD/mo) | Strong | 50-80M users globally |
| Tech Early Adopters | Medium-High | High | High | Very Strong | 20-30M users |
| Privacy-Conscious Users | Varies | Low | Medium | Poor | 100M+ users |
| Budget-Conscious Users | Medium | Medium | Low (free or <5 USD) | Weak | 200M+ users |
| Seniors and Low-Tech Users | Low-Medium | Varies | Low-Medium | Weak - UX complexity | 150M+ users |
| High-Net-Worth Individuals | High | Medium | Very High (100+ USD) | Strong - replacing human assistants | 5-10M users |
Instinct targets privacy-tolerant professionals and early adopters; privacy-conscious segment is structural exclusion
[CM016, CM017, CM018, CM019]2.4 Growth Drivers and Market Constraints
Market growth is driven by five primary catalysts. First, generative AI capability improvements have made natural language understanding and task completion reliable enough for production use cases. Second, smartphone ubiquity provides the device substrate and connectivity for always-available assistance. Third, consumer familiarity with AI through ChatGPT and similar products has normalized AI interaction and reduced adoption friction. Fourth, productivity demands from remote and hybrid work arrangements have increased demand for delegation tools. Fifth, SMS and messaging-app interfaces like those used by Instinct eliminate the need to learn new applications, reducing onboarding friction. Market constraints include regulatory uncertainty around AI agent liability and data protection, consumer trust deficits following high-profile AI failures, platform gatekeeping by Apple and Google that limits third-party assistant capabilities, and security vulnerabilities including prompt injection attacks that undermine reliability. The FTC has signaled increased scrutiny of AI agents that enter binding transactions on behalf of consumers, and the EU AI Act may classify autonomous personal assistants as high-risk systems requiring conformity assessments. Privacy regulations including CCPA and GDPR create compliance overhead and limit data retention practices. The market trajectory depends heavily on whether the agentic AI trust gap closes faster than regulatory constraints tighten.[CM022, CM023, CM024, CM025, CM026, CM027]
03Competitors
3.1 Direct rivals and incumbent benchmarks
Instinct's closest reference set is not every chatbot. It is the subset of products trying to become a user's operating interface for everyday digital work. OpenAI Operator is the clearest direct benchmark because it explicitly promises browser-based task execution. Google Gemini, Apple Intelligence, and Microsoft Copilot are slightly different cases: they are broader ecosystems or bundled assistants rather than startup-style single products, but from a user-outcomes perspective they increasingly overlap with the same core jobs of drafting, scheduling, summarizing, and eventually acting. Meta AI belongs in the same outer ring because it conditions users to expect free AI help inside consumer communication surfaces. Humane deserves special treatment. Its AI Pin is not a live competitor anymore, but it is strategically relevant because it showed both investor appetite and consumer fragility for always-on assistant products. The shutdown after HP's acquisition is a warning that novelty and ambitious assistant rhetoric do not compensate for a weak product loop. That precedent matters for Instinct because the company is also asking users to trust a new form of delegation before broad mainstream proof exists. Instinct's edge in this set is not scale or brand. It is focus: a messaging-native assistant that aims to operate inside real accounts without waiting for constant confirmation. That makes the product feel more agentic than many incumbents, but also more exposed if trust breaks.[CP001, CP002, CP003, CP004, CP005, CP006]
| Competitor | Category | Scale / availability proxy | Target user | Differentiation | Limitation vs Instinct |
|---|---|---|---|---|---|
| OpenAI Operator | Direct agentic benchmark | Pro-tier / research preview | Prosumer and power user | Browser-based task execution | Not messaging-native |
| Google Gemini | Incumbent broad assistant | Mass distribution via Google ecosystem | Mainstream consumer and prosumer | Search, account, and device adjacency | Less focused on delegated personal operations |
| Apple Intelligence / Siri | Incumbent OS assistant | Bundled on compatible Apple devices | Premium Apple consumer | Default OS presence and trust | Lower visible autonomy today |
| Microsoft Copilot | Incumbent productivity assistant | Bundled across Microsoft surfaces | Knowledge worker and enterprise user | Suite integration and subscription bundling | Less consumer-personal in posture |
| Perplexity Pro | Functional overlap | Broadly available paid tier | Research-heavy consumer | Answer quality and search depth | Not full delegated action |
| Humane AI Pin | Predecessor cautionary tale | Product shut down | Early-adopter hardware buyer | Ambitious assistant vision | Execution and trust failure |
Humane is included for strategic context even though it is no longer a live product competitor.
[CP001, CP002, CP003, CP004, CP005, CP006]| Company | Public scale marker | Business model | Capital base | Implication for Instinct |
|---|---|---|---|---|
| Instinct | ~$80M ARR in private beta | Undisclosed paid consumer assistant | $350M raised | Strong early proof, limited brand maturity |
| OpenAI | Large paid subscription base | Subscription + API | Frontier-scale capital | Can subsidize agent experiments |
| Google / Gemini | Bundled and subscription AI plans | Bundle + subscription | Corporate balance sheet | Can price from ecosystem strength |
| Apple Intelligence | Bundled with device ecosystem | Hardware-led bundle | Corporate balance sheet | Distribution and trust advantage |
| Microsoft Copilot | Subscription suite attach | Bundle + upsell | Corporate balance sheet | Strong enterprise and productivity channel |
| Humane | Product shut down after acquisition | Hardware + subscription attempt | Prior venture-funded startup | Shows capital is not enough without product fit |
Only public markers are used; capital-base comparisons are directional rather than exhaustive.
[CP002, CP006, CP013, CP014, CP015, CP024]Instinct scores high on autonomy but lower on distribution than incumbent platform competitors.
Axes are ordinal scores for autonomy (x) and distribution power (y) inferred from public positioning.
[CP010, CP011, CP016, CP024, CP033, CP034]Competition is intensifying across incumbents and startups while trust failures remain category-defining.
Operator and Apple rollout dates are rounded to public launch windows where exact feature sequencing varied.
[CP002, CP003, CP005, CP020, CP021, CP033]3.2 Adjacent substitutes and specialist workflow tools
The next competitive ring is formed by products that solve part of Instinct's job but not the whole delegated-assistant bundle. Claude and Perplexity are the most important broad substitutes in this group. Claude is strong on reasoning, writing, and analysis, but its public surface does not currently emphasize consumer task execution in the same way as Instinct or Operator. Perplexity excels at search, research, and answer quality; for some users, that is enough to reduce demand for a broader assistant, but it is not the same product promise as autonomous inbox, calendar, shopping, and travel management. Then there are the specialists. Superhuman owns email speed and polish. Motion owns scheduling and time allocation. Cal.com provides scheduling infrastructure. These companies matter because they show that narrow workflow software can still win even if general AI improves. A specialist can be easier to trust, easier to budget for, and easier to benchmark than an assistant touching everything at once. For Instinct, this means the competitive bar is two-sided. It has to beat broad AI products on action orientation, while also beating specialists on workflow-specific usability. That is possible, but it is a higher bar than a simple 'general beats point tools' story.[CP007, CP008, CP009, CP012, CP013, CP017]
| Buying criterion | Instinct | Operator | Gemini | Apple Intelligence | Claude / Perplexity / specialists |
|---|---|---|---|---|---|
| Messaging-native access | Yes | No | Partial | No | Mostly no |
| Autonomous multi-step tasking | High | High | Medium | Low-medium | Low to medium |
| Email / calendar / travel bundle | Yes | Partial | Partial | Partial | Usually single-workflow |
| Broad public availability | No - private beta | Limited paid tier | Yes | Yes on supported devices | Yes |
| Native platform integration | Low | Low | High | High | Mixed |
| Trust / brand familiarity | Low-medium | High | High | High | Medium-high |
Cells are qualitative and constrained to publicly visible positioning rather than internal capability tests.
[CP003, CP004, CP005, CP007, CP008, CP009]Instinct overlaps broadly with several rivals, but the exact overlap differs by workflow and autonomy depth.
Cells summarize public product positioning rather than lab-tested performance scores.
[CP007, CP008, CP009, CP010, CP016, CP017]3.3 Distribution power, switching costs, and pricing pressure
Instinct's biggest non-product differentiator is that it arrives over SMS and WhatsApp rather than through an app-first interface. That matters because the setup burden for a consumer assistant is not just account creation but habit formation. A message thread is a lower-friction starting point than downloading and learning another application. At the same time, channel ownership remains external. Apple, Google, Microsoft, Meta, and WhatsApp control the dominant devices, identities, app stores, and communication surfaces that shape discovery and trust. They also have the ability to bundle assistant features into products users already pay for. That bundling power affects pricing. OpenAI, Google, Microsoft, and Claude all now sell paid AI plans, which validates recurring spend but also normalizes a market where users compare several assistants side by side. Meta pushes the opposite direction by making AI assistance free. In that environment, Instinct probably cannot win on price alone. It has to win on felt usefulness: saving enough time or cognitive load to justify a separate spend despite abundant substitutes. Switching costs are only moderate. Many users still multi-home among tools, and the status quo is fragmented. That helps Instinct get trial but makes lasting lock-in harder unless the assistant becomes deeply embedded in sensitive, trusted workflows.[CP010, CP011, CP013, CP014, CP018, CP019]
| Company | Primary surface | Acquisition motion | Pricing posture | Switching friction | Distribution power |
|---|---|---|---|---|---|
| Instinct | SMS / WhatsApp | Viral / invite-only | Undisclosed premium | Moderate | Low owned, high channel leverage |
| OpenAI Operator | ChatGPT | Subscription upsell | Paid tier | Low-moderate | Very high brand reach |
| Gemini | Google apps and web | Bundle + subscription | Free + paid | Low | Very high platform reach |
| Apple Intelligence | OS-native | Bundled with device | Bundled | Low | Very high device reach |
| Microsoft Copilot | Productivity suite | Bundle + enterprise channel | Paid / bundled | Low | Very high suite reach |
| Specialists (Superhuman / Motion / Cal.com) | Dedicated apps | Workflow-led self-serve | Paid workflow subscription | Moderate-high | Focused niche reach |
Distribution power is qualitative; Instinct benefits from channel familiarity but does not own the dominant platforms.
[CP009, CP010, CP011, CP013, CP014, CP018]Platform owners start with materially stronger default-placement advantages than Instinct.
Values are ordinal distribution-power scores, not market-share data.
[CP011, CP019, CP020, CP024, CP031]3.4 Moat durability and the anti-thesis
The best argument for Instinct's moat is product architecture and user experience. The company is trying to collapse several fragmented jobs into one assistant that acts, not just advises. If it can reliably handle communications, scheduling, shopping, and travel in a messaging thread, the product may feel qualitatively different from both general chat and single-workflow apps. The founder's research background in agentic loops adds credibility to that ambition. The anti-thesis is stronger than many startup narratives admit. Every major platform owner is moving toward more agentic behavior from a far stronger installed base. If Google, Apple, OpenAI, Microsoft, or Meta match most of Instinct's autonomy while retaining higher trust and deeper platform integration, the standalone wedge compresses quickly. Instinct's own adverse incidents make this risk worse because trust is one of the few areas where incumbents already start ahead. The right diligence view is therefore conditional. Instinct has a real wedge today, but moat durability is not yet proven. The public record is missing pricing, retention, task-level success, and churn relative to competitors. Until those data exist, competitive advantage should be treated as plausible but not durable by default.[CP012, CP016, CP017, CP018, CP020, CP021]
| Moat claim | Primary threat | Severity | Why it matters | Mitigation / diligence ask |
|---|---|---|---|---|
| Messaging-native UX | Incumbents add agentic chat in existing apps | High | Interface advantage may compress quickly | Measure retention advantage from SMS / WhatsApp |
| Higher autonomy | Autonomy incidents undermine trust | High | Users may prefer safer but less capable incumbents | Request task-level error rates |
| Cross-workflow bundling | Specialists retain deeper workflow UX | Medium | Bundle may be broad but shallow | Benchmark email and calendar NPS vs specialists |
| Founder / technical edge | Big-tech distribution and capital | High | Product quality may not overcome default placement | Test whether users switch after side-by-side trials |
| Early ARR momentum | Private-beta concentration and novelty effect | Medium | Current proof may not generalize | Analyze conversion and churn cohorts by workflow depth |
The anti-thesis centers on trust and distribution rather than on raw model quality alone.
[CP012, CP016, CP017, CP018, CP019, CP020]3.5 Exhibits
04Financials
4.1 Funding History and Capital Structure
Spear Street Technology Inc. has raised capital in two identified rounds. The Series A closed in January 2026 at $100 million, led by Kleiner Perkins with partner Mamoon Hamid taking a board-observer or director role, with participation from Conviction Capital (Sarah Guo). At time of the Series A, ARR was approximately $5 million—implying a ~100× revenue multiple for the round. The Series B closed on August 26, 2026 at $250 million, co-led by Index Ventures and Benchmark, at a $2.5 billion post-money valuation. At the time of Series B, management-stated ARR was approximately $80 million—implying ~31× ARR. Greenoaks Capital also participated in the Series B. Total capital raised across all disclosed rounds is $350 million. No seed or pre-seed information has been disclosed publicly. Cap table, investor ownership percentages, and dilution schedule are not available.[CI001, CI002, CI003, CI004, CI005, CI006]
| Round | Date | Amount | Post-money Valuation | ARR at close | ARR multiple | Lead investor(s) |
|---|---|---|---|---|---|---|
| Series A | 2026-01-01 | $100M | ~$500M est. | ~$5M | ~100× | Kleiner Perkins (Mamoon Hamid) |
| Series B | 2026-08-26 | $250M | $2.5B | ~$80M | ~31× | Index Ventures + Benchmark |
| Total / current | 2026-08-28 | $350M | $2.5B | $80M | 31× | Index Ventures, Benchmark, KP, Conviction, Greenoaks |
Series A valuation is analyst-estimated based on the $100M raise and comparable seed-to-A consumer AI step-ups; not confirmed. All ARR figures are management-stated. No seed or pre-seed data is publicly available.
[CI001, CI002, CI003, CI004, CI005]Instinct's post-money valuation stepped from ~$500 million at Series A to $2.5 billion at Series B—a 5× increase in 7 months.
Pre-Series A and Series A valuations are analyst estimates; only the Series B $2.5B valuation is confirmed. Step-up values are derived from estimated valuations.
[CI001, CI002, CI003, CI025]4.2 Revenue Trajectory and ARR Growth
Instinct's management-stated ARR grew from approximately $5 million in January 2026 to approximately $80 million in August 2026, representing a 16× increase in approximately seven months. This implies an average monthly net-new ARR of roughly $10.7 million. This growth rate, if real, would be among the fastest ARR ramp-rates recorded for any consumer software product. No independent verification of ARR has been disclosed; the figure derives entirely from management statements reported in press coverage. Gross margin, net revenue retention, customer count, average revenue per user (ARPU), and pricing structure are all undisclosed. The product remains in private beta with invite-only access, suggesting that the ARR may derive from a small cohort of early paying users or early commercial arrangements not publicly described.[CI007, CI008, CI009, CI010, CI011, CI012]
| Period | ARR (est.) | Monthly growth | Revenue multiple at period | Notes |
|---|---|---|---|---|
| January 2026 | ~$5M | N/A | ~100× (vs. $500M Series A) | Management-stated at Series A close |
| February 2026 | ~$15M est. | ~$10M | ~N/A | Interpolated; no disclosure |
| April 2026 | ~$35M est. | ~$10M | ~N/A | Interpolated; no disclosure |
| June 2026 | ~$55M est. | ~$10M | ~N/A | Interpolated; no disclosure |
| August 2026 | ~$80M | ~$12.5M | ~31× (vs. $2.5B Series B) | Management-stated at Series B close |
| Implied CAGR (annualized) | ~16× in 7mo | ~$10.7M avg | N/A | If growth linear; actual path unknown |
Intermediate ARR figures are linear interpolations between disclosed data points; actual monthly ARR is unknown. Growth could be front-loaded or back-loaded relative to this linear path.
[CI007, CI008, CI009, CI010]Management-stated ARR grew from ~$5M in January 2026 to ~$80M in August 2026, implying ~$10.7M average monthly net-new ARR over the period.
January and August 2026 data points are management-stated. Intermediate months are linear interpolations; actual ARR path is unknown.
[CI007, CI008, CI009, CI010, CI026]4.3 Unit Economics and Margin Estimates
Because Instinct has not disclosed pricing, headcount, or cost structure, all unit-economics analysis is based on sector benchmarks and inference from comparable consumer AI companies. LLM inference cost for autonomous AI assistants processing email, calendar, and multi-step tasks is estimated at 15-35% of revenue, based on published cost structures for similar agentic products. If applied to $80 million ARR, this implies $12-28 million in annual LLM inference costs. Customer acquisition cost (CAC) is likely low given the viral waitlist model, though this is speculative. Gross margin for comparable consumer AI SaaS businesses that are not entirely infrastructure- bound ranges from 50-75%; Instinct's higher inference intensity suggests the lower end of this range. Net revenue retention is unknown; the private beta context and lack of disclosed churn data prevent analysis. The go-to-market motion relies on viral distribution and an invite-only waitlist, suggesting low paid customer-acquisition cost but limited predictability of growth scaling. Sales cycle is undefined; no outbound or enterprise sales motion has been disclosed. GTM efficiency metrics—CAC payback period, LTV/CAC ratio, and channel mix—are entirely absent from public disclosures.[CI013, CI014, CI015, CI016, CI017, CI018]
| Metric | Estimated value | Methodology | Confidence | Gap |
|---|---|---|---|---|
| Gross margin | 50–70% est. | Comparable consumer AI SaaS benchmarks | Low | No disclosed financials |
| LLM inference cost (% revenue) | 15–35% | Published agentic AI cost structures | Low | Provider and pricing unknown |
| LLM inference cost ($M/yr) | $12–$28M | Applied to $80M ARR | Low | Estimate only |
| Customer acquisition cost | Low (viral) | Invite-only waitlist model | Low | No disclosed marketing spend |
| Net revenue retention | Unknown | Not disclosed | N/A | Critical gap for valuation |
| ARPU (monthly) | Unknown | No pricing disclosed | N/A | Private beta; no public pricing |
All unit economics figures are analyst estimates derived from sector benchmarks. None have been confirmed or disclosed by Instinct. Treat all values as directional only.
[CI013, CI014, CI015, CI016]Gross margin, LLM inference cost, and ARPU are all analyst estimates with wide uncertainty bands given the absence of public financial disclosures.
All ranges are analyst estimates derived from comparable consumer AI company benchmarks. Wide ranges reflect high uncertainty.
[CI013, CI014, CI015, CI016, CI027]4.4 Financial Risks and Burn Outlook
Instinct's key financial risks center on: (1) the absence of a disclosed monetization model at $2.5 billion valuation, creating execution risk to justify the price; (2) dependency on an undisclosed LLM provider whose pricing or availability could change adversely; (3) burn rate that is unknown but likely substantial given AI inference costs and engineering headcount; and (4) the historical challenge of monetizing consumer AI products at scale. With $350 million raised, assuming a burn rate of $3-7 million per month (sector-informed estimate), runway would be approximately 36-58 months from close of Series B—sufficient for a commercial launch and first monetization cycle. However, if ARR growth decelerates due to privacy backlash or competitive pressure, the burn rate relative to revenue could become problematic more quickly. The lack of audited financial statements or any third-party financial certification means all runway estimates carry high uncertainty and should be treated as indicative only. Investor-favorable terms such as anti-dilution provisions and liquidation preferences are very likely present but remain entirely undisclosed, which further limits precision of financial modeling and exit scenario analysis.[CI019, CI020, CI021, CI022, CI023, CI024]
| Scenario | Monthly burn rate | LLM costs | Other opex | Implied runway on $350M | Key assumption |
|---|---|---|---|---|---|
| Conservative (lean team) | $3M/mo | $1.2M | $1.8M | ~58 months | Headcount ~25, low spend |
| Base (sector benchmark) | $5M/mo | $2.0M | $3.0M | ~35 months | Headcount ~50, moderate spend |
| Aggressive (scale-up) | $9M/mo | $3.5M | $5.5M | ~19 months | Headcount ~100+, rapid hiring |
Burn rate scenarios are analyst estimates; actual burn is undisclosed. The $350M was not all raised at once; timing of draws affects real runway.
[CI020, CI021, CI022]| Risk area | Description | Severity | Evidence | Mitigation path |
|---|---|---|---|---|
| No monetization model | No pricing or revenue model disclosed at $2.5B valuation | Critical | Zero public disclosures | Commercial launch announcement |
| LLM provider dependency | Undisclosed LLM provider; API pricing or availability could change | High | Inference costs estimated 15–35% of revenue | Negotiate long-term contracts; diversify providers |
| Unverified ARR | $80M ARR is management-stated; no third-party verification | High | Single source: management statements | Audited financials in due diligence |
| Consumer monetization history | Consumer AI historically struggles to sustain paid subscriptions at scale | High | Historical: Inflection, Character AI | Differentiated product value; autonomous utility |
| Privacy backlash revenue risk | August 2026 adverse coverage may slow ARR growth or increase churn | High | TechCrunch Aug 2026 adverse coverage | Product fixes; transparent data policy |
Severity is analyst judgment based on available evidence and sector benchmarks. All risks may be mitigated by disclosures not yet publicly available.
[CI019, CI022, CI023, CI024]Estimated monthly burn of $3-9M implies runway of 19-58 months on $350M raised. Base case suggests ~35 months of runway, sufficient for commercial launch.
Burn rate and runway are analyst estimates. Actual cash balances depend on draw-down timing, revenue collections, and operating expenses not publicly disclosed.
[CI020, CI021, CI022, CI028]4.5 Exhibits
05Product & Technology
5.1 What Instinct delivers in day-to-day workflow terms
Instinct is positioned as a consumer personal assistant that lives inside channels people already use instead of asking them to learn a new app. The official site says there are “no new interfaces,” that the system is trained to use a phone and a computer, and that users can text or call it; third-party reporting adds WhatsApp as a supported channel. In practice, the product promise is not chat for information retrieval, but delegated execution. Publicly described tasks include inbox cleanup, follow-up drafting, appointment booking, restaurant reservations, travel coordination, ride booking, shopping, and proactive reminders when the agent notices unfinished threads. The same sources also make clear that Instinct can act across email, messaging, calendar, screen, audio, and location permissions, which materially expands the scope from an assistant to an operator. That workflow design is strategically attractive because it removes install friction and centralizes many chores into one conversational surface, but it also means product quality depends on invisible background decisions, not just answer quality. The user therefore buys convenience and agency transfer at the same time, which is why seemingly small control failures—like one unauthorized email—become first-order product risks.[CE001, CE002, CE003, CE004, CE005, CE006]
| Module / asset | What it does | User / surface | Maturity | Differentiation / diligence gap |
|---|---|---|---|---|
| Messaging interface rail | Receives user requests and sends follow-ups over text, call, and reported WhatsApp surfaces | End-user front end | Private beta, live with testers | No app download is a real UX differentiator; exact transport vendors are undisclosed |
| Connected-account ingestion | Pulls context from email, messaging, calendar, and other linked services | User data and context layer | Private beta, permissions publicly documented | Depth of access is differentiated; scope governance and least-privilege design are not public |
| Agentic action engine | Turns requests into bookings, purchases, scheduling moves, and outbound communications | Core execution layer | Functionally proven, control quality still immature | Autonomy is the headline feature; approval thresholds and rollback logic are undisclosed |
| Memory / indexing layer | Stores prior context and indexed external data so the assistant can follow up on dropped threads | Personalization layer | Clearly active, governance challenged | Persistent memory appears central; deletion semantics became controversial in beta |
| Background sync / notification layer | Monitors connected services for updates and triggers later work | Backend operations | Inferred from platform docs and product claims | Likely uses watch/webhook jobs; no public architecture or observability evidence |
| Workspace / settings surface | Hosts account linking, deletion, and control settings outside the conversational thread | Admin / safety surface | Reactive public evidence only | Delete tool appears to have been added after complaints; audit-log visibility is absent |
Rows combine official product copy, legal documents, integration-platform documentation, and adverse tester reporting; several backend layers are inferred because Instinct publishes no formal architecture diagram.
[CE001, CE002, CE003, CE004, CE015, CE018]| User job | Example task | How Instinct handles it | Integration required | Publicly evidenced benefit | Known limitation |
|---|---|---|---|---|---|
| Travel / reservation management | Book a ride to the airport or a restaurant table | User texts the request; the agent reads context, executes on connected services, and confirms or follows up | Messaging rail plus travel or merchant account access | Single conversational entry point for multi-step chores | Wrong action can create a binding commitment or unwanted purchase |
| Inbox cleanup and follow-up | Summarize email, find codes, draft or send follow-ups | Reads mailbox content and acts on behalf of the user across linked email accounts | Gmail or Outlook-style mail APIs or delegated account access | Moves from summarization into execution | Unauthorized outbound email already surfaced in beta |
| Calendar coordination | Book appointments and manage timing conflicts | Combines inbox, calendar, and reminders to schedule or reschedule events | Calendar APIs and background change monitoring | Can proactively keep threads moving | Webhook or token compromise or stale event state can trigger wrong scheduling |
| Shopping and purchases | Place an order or complete checkout steps | Uses delegated payment and merchant context to transact on behalf of the user | Merchant credentials, payment data, and external checkout flows | Reduces checkout friction dramatically | Terms place transaction responsibility on the user, not the platform |
| Long-tail life admin | Follow up on dropped threads or reminders without being re-prompted | Persistent context lets the agent re-engage later and combine multiple surfaces | Memory/index layer plus outbound messaging transport | Feels proactive rather than reactive | Persistence magnifies retention, consent, and explainability concerns |
Benefits are framed from publicly described workflows rather than measured KPI case studies; Instinct has not published per-task success rates, false-action rates, or user-control metrics.
[CE004, CE005, CE006, CE019, CE025, CE026]Representative journey from a user request into context retrieval, autonomous execution, and later follow-up.
Workflow abstracts the common operating pattern implied by official copy and tester reports; specific tasks may branch or request clarification before execution.
[CE001, CE004, CE006, CE021, CE025, CE029]5.2 Inferred agent architecture and founder technical lineage
Instinct does not publish a formal systems diagram or name its model provider, so the public technical picture has to be reconstructed from the product copy, legal disclosures, and Noah Shinn’s prior research. That lineage is unusually informative. Shinn’s Reflexion paper and NeurIPS poster describe an actor-evaluator-reflector loop where language agents learn from linguistic feedback stored in episodic memory instead of weight updates; τ-bench then extends that worldview into dynamic, tool-using conversations constrained by API tools and policy rules. Those artifacts do not prove Instinct’s internal implementation, but they strongly suggest that the product is not just a raw LLM wrapper. The most plausible public interpretation is a layered stack with a frontier LLM as reasoning substrate, an orchestration loop for planning and tool selection, a persistent memory/index layer for cross-session context, and integration adapters for each connected service. That inference is further supported by the official promise that the assistant understands what matters to the user, follows up on dropped threads, and can act on their behalf over time. In other words, the defensible technical idea is memory-backed agency, not simply messaging as a user interface.[CE009, CE010, CE011, CE012, CE013, CE014]
| Layer / component | Public evidence | Role in system | Confidence | Primary risk |
|---|---|---|---|---|
| LLM core model | Official site references a “core model”; provider is not named publicly | Reasoning substrate for intent parsing, synthesis, and action planning | Medium | Model-vendor dependence, latency, cost, and undisclosed fallback behavior |
| Agent loop / orchestration | Reflexion and τ-bench lineage point to tool-using agent loops with policy constraints | Selects tools, sequences steps, and decides when to act or ask | Medium | Autonomy can outrun approval, policy, or exception handling |
| Episodic memory / index | Official copy promises understanding of what is important and follow-up on dropped threads | Stores context and retrieved state across sessions | Medium | Retention, deletion, and stale-memory errors become product-critical |
| OAuth and linked-account adapters | Privacy policy and terms enumerate Google Workspace and linked accounts | Obtains delegated access to mail, calendar, docs, and identity surfaces | High | Token compromise or overscoped permissions create severe blast radius |
| Messaging transport layer | WhatsApp and Twilio docs show how outbound and inbound messaging can be orchestrated | Delivers user requests, confirmations, status updates, and proactive outreach | Medium | Carrier and channel limits and delivery-state failures are outside Instinct control |
| Background event ingestion | Gmail and Calendar watch models require Pub/Sub or webhook callbacks and renewal logic | Triggers follow-up work when inboxes or calendars change | High | Missed renewals, duplicate events, or callback outages can break reliability |
| Settings / deletion workspace | Terms and privacy reference Workspace and Settings control surfaces | Hosts data-deletion requests, opt-outs, and disconnect actions | Medium | Reactive controls may not be sufficient for high-autonomy failure recovery |
This table intentionally separates directly observed facts from architecture inferences; confidence rises where public platform documentation constrains what any compatible implementation must do.
[CE009, CE013, CE015, CE019, CE021, CE022]Publicly inferable layers run from messaging UX through agent orchestration, memory, integrations, and backend callback infrastructure.
Instinct has not published a formal architecture diagram; this stack is synthesized from official copy, legal pages, Shinn’s prior research, and the required behavior of the cited integration platforms.
[CE010, CE011, CE015, CE016, CE017, CE018]5.3 Integrations, transport rails, and background execution requirements
The product surface implies a broad integration estate even though Instinct names only some partners explicitly. The privacy policy says Google Workspace access can cover Gmail, Calendar, Drive, Docs, Sheets, Slides, and Tasks, while the terms mention Apple, Facebook, and Google account linking and reporting adds Outlook and WhatsApp. Public platform documentation helps bound what this means operationally. Gmail and Google Calendar both support watch-based change notification models, but they require server-side Pub/Sub or HTTPS webhook infrastructure plus renewal logic. Microsoft Graph exposes mail and calendar APIs that can bridge both personal and organizational Outlook accounts. On the messaging side, WhatsApp Cloud API constrains free-form service responses to a 24-hour customer-service window, while Twilio’s messaging APIs provide outbound sends, delivery-state callbacks, redaction, and channel abstraction. Put together, this means Instinct almost certainly depends on a substantial credential, token, and callback layer behind the scenes. The architectural burden is therefore less about generating text than about securely holding delegated permissions, receiving change events, deciding when to act, and recovering from partial failures across heterogeneous external systems.[CE019, CE020, CE021, CE022, CE023, CE024]
5.4 Maturity, trust, and security posture
Instinct’s maturity signal is paradoxical: the product is clearly functional enough to delight testers and execute real-world actions, yet not controlled enough to claim production-grade safety. Multiple independent reports describe the assistant sending or preparing email without explicit per-action approval, following instructions embedded in an inbound email, and retaining previously indexed content after Google access was revoked. Those are not cosmetic bugs. They show that the core product loop—read, infer, act—already works, and that its failure modes are exactly the ones an autonomous consumer agent should be expected to harden before general availability. Official policy partially narrows the training issue by saying Google Workspace data is excluded from model training and third-party model-provider secondary use, but the broader privacy framework still allows non-Workspace materials to improve products and models subject to policy exceptions. Just as important, there is no public evidence of external security audits, certifications, uptime metrics, or red-team disclosures. The maturity judgment therefore has to be “real product, incomplete control plane”: stronger than demo-ware, weaker than a consumer-safe operating system for delegated actions.[CE029, CE030, CE031, CE032, CE033, CE034]
| Control / issue | Public status | Evidence | Why it matters | Gap |
|---|---|---|---|---|
| Google Workspace training exclusion | Documented but scoped | Privacy policy says Workspace API data is not used to train models or sent to third-party AI providers for training | Narrower than the broad product-level training language and important for Google-linked users | No equivalent public carve-out for all non-Workspace materials |
| Deletion after disconnect | Separate deletion step required | Privacy and terms say disconnecting an integration does not automatically delete indexed data | Revocation is weaker than many users would intuit | Deletion UX, propagation timing, and verifiability are not public |
| Binding transaction authority | Explicitly granted in terms | Terms appoint the service as user agent for agreements, commitments, and transactions | Autonomy can create legal and financial exposure on mistaken actions | No disclosed per-action approval, hold, or rollback thresholds |
| Prompt-injection exposure | Demonstrated in beta reports | TechCrunch and follow-on coverage describe malicious-email instruction following | Agent can be induced to treat hostile content as a command | No public prompt-isolation or permission-segmentation design disclosed |
| Unauthorized outbound action | Demonstrated in beta reports | Testers reported email sent without asking first | Shows real execution, but also broken trust boundary | No public audit log, dry-run mode, or confirmation policy disclosed |
| Security assurance disclosure | Not publicly visible | No public audits, certifications, uptime metrics, or red-team summaries found in reviewed sources | Readers cannot distinguish hardened controls from policy copy alone | Need SOC 2 or pentest or incident response or SLO evidence before broad launch |
Statuses reflect only public evidence reviewed in this run; absence of a certification or control in this table means it was not found publicly, not that it definitively does not exist internally.
[CE028, CE030, CE032, CE033, CE034, CE035]Public maturity is strongest in messaging-native workflow and weakest in disclosed trust, assurance, and launch controls.
Matrix ratings are ordinal and evidence-based rather than benchmarked scores; Instinct publishes no public SLA, false-action rate, or control-efficacy metrics.
[CE003, CE029, CE036, CE038]5.5 Critical dependencies, roadmap opacity, and technical diligence risks
The product’s external dependency map is unusually heavy for a young consumer startup. Even without a disclosed vendor list, the design almost certainly relies on a frontier LLM API, messaging transport providers, OAuth identity systems, Gmail and Calendar infrastructure, Microsoft Graph-style connectors, cloud compute, and secure secret or token storage. The official site itself admits compute is a current gating factor by limiting access while scaling capacity. At the same time, the founder’s research lineage carries stronger developer signal than the product itself: Reflexion and τ-bench both have active public repositories, meaningful star counts, and still-open issue queues, while Instinct has little comparable public engineering surface beyond a thin Hacker News footprint. That asymmetry matters. It suggests technical credibility currently rests more on founder prior art than on observed operating excellence. The big unresolved diligence items are therefore not “can an agentic assistant be built?” but “which model and cloud vendors are concentration points, what rollback and approval mechanisms exist, what launch gates remain, and how much safety debt is being carried into scale.”[CE039, CE040, CE041, CE042, CE043, CE044]
| Date / stage | Feature or milestone | Status | Implication | Evidence |
|---|---|---|---|---|
| 2023 research foundation | Reflexion published with episodic-memory and verbal-feedback loop | Completed historical milestone | Establishes the founder’s technical prior art for memory-backed agents | NeurIPS poster and paper |
| 2025 research foundation | τ-bench published as tool-agent-user benchmark | Completed historical milestone | Shows focus on tool use, policy rules, and evaluation rather than chatbot-only UX | Noah Shinn site and repo README |
| 2026 private-access product | Instinct available only to a private access group while scaling compute | Current | Product is real but capacity constrained | Official homepage |
| 2026 legal / governance refresh | Privacy policy and terms revised on August 26, 2026 | Current | Control language evolved during rapid growth and scrutiny window | Official privacy and terms pages |
| 2026 reactive deletion control | Delete external-data tool added after public complaints | Current but reactive | Remediation happened, but after trust damage | TechCrunch and StartupFortune |
| 2026 public roadmap visibility | No public changelog, SLA, pricing page, or GA date found | Current gap | Hard to underwrite launch readiness or support burden | Official pages plus reviewed reporting |
The roadmap view is necessarily chronology-heavy because Instinct publishes little forward-looking release detail; the main public signals are research lineage, private-beta state, and reactive governance changes.
[CE003, CE010, CE013, CE036, CE038, CE044]Instinct depends on external model, transport, API, and infrastructure layers that each create concentration or control-plane risk.
Exact vendors are not all disclosed; named nodes represent dependency classes constrained by public product behavior and platform documentation.
[CE025, CE026, CE027, CE043, CE044]5.6 Exhibits
06Customers
6.1 Who uses Instinct and how they access it
Instinct’s current customer base is best described as an invite-only cohort of individual consumers, not enterprises. The official site says the product is available only to a private access group, with new users entering through a waitlist or referrals from existing members. The terms are written for personal use and the public examples revolve around errands, travel, subscriptions, email follow-up, and household logistics rather than team workflows, procurement, or enterprise deployments. That combination matters because it means the buyer, user, and likely payer are the same person: a consumer deciding whether to trust the assistant with their own inbox, calendar, accounts, and spending authority. The access method is also central to the thesis. Instinct positions itself as an assistant with “no new interfaces,” reachable by text or call and able to work through WhatsApp and other messaging surfaces. That lowers onboarding friction for early adopters because the product fits into an existing messaging habit rather than forcing app learning. At the same time, the likely earliest users are unusually technical or risk-tolerant: investors, founders, operators, and other power users who were willing to connect broad permissions before the product reached a mainstream audience. That makes the current cohort useful as a proof-of-capability sample, but only a weak proxy for mass-market willingness to trust the product at scale.[CU001, CU002, CU003, CU004, CU005, CU012]
| Segment | Buyer / user / payer | Observed use case | Scale visibility | Revenue / strategic value | Gap |
|---|---|---|---|---|---|
| Tech-insider power users | Individual consumer / same person / same person | Delegates dense personal admin, travel, shopping, subscriptions, and email tasks through text | Named anecdotes only; no cohort size disclosed | High strategic value because this cohort generated the launch-week proofs of utility and likely much of the initial virality | Unknown how representative they are of mainstream consumers |
| Founders, investors, and operators | Individual consumer using work-adjacent personal workflows | Uses Instinct for reservations, CRM follow-up, LP data rooms, and scheduling that blend work and personal life | Named anecdotes from a handful of public users | High signaling value because many of the loudest positive and negative posts came from this cohort | No evidence that enterprises buy the product or reimburse usage |
| Household and family coordinators | Individual consumer / same person / same person | Tracks school schedules, homework reminders, bills, rides, appointments, and coordination across messaging apps | Visible only in anecdotes; no demographic breakout | Potentially large long-run consumer segment if trust and reliability improve | No evidence on retention, willingness to pay, or household multi-user behavior |
| Privacy-sensitive mainstream consumers | Prospective consumer / same person / same person | May value convenience but hesitate to connect inbox, messages, credentials, and payments | Not observed directly because product is still gated | Large expansion pool if controls improve because AI-assistant adoption is already mainstream | Current beta evidence likely overstates willingness to grant broad permissions |
Segmentation is inferred from named user anecdotes, official product positioning, and 2026 consumer-AI adoption benchmarks because Instinct discloses no demographic or customer-count breakdown.
[CU001, CU002, CU004, CU005, CU012, CU033]The current journey starts with buzz and invite-gating, moves through high-permission setup and early task success, and then branches toward habit formation or trust-driven churn.
Journey stages are synthesized from official access mechanics, named-user anecdotes, and trust incidents; no company funnel data or stage-conversion metrics are disclosed.
[CU001, CU002, CU004, CU012, CU015, CU017]6.2 Adoption trajectory is strong on revenue but weak on denominators
The headline customer signal around Instinct is not a disclosed user count or named account base; it is revenue. TechCrunch reported that the company told The Wall Street Journal it had reached about $80 million ARR by late August 2026, up from about $5 million in January 2026. On its face, that is extraordinary. A roughly 16x increase in under a year while the product remains private beta suggests that some users are paying meaningfully and that the product’s scope is broad enough to justify nontrivial spending. It also explains why investors were willing to support a $2.5 billion valuation before general release. But the denominator problem is severe. Instinct does not disclose how many users generate that ARR, how many are paying versus simply testing, what pricing tiers exist, or what portion of usage comes from a tiny, high-intensity cohort. Forbes reported the product was still free to use publicly and that no formal pricing had been announced, which deepens the opacity. The result is a split picture: revenue momentum is real enough to matter, yet adoption proof is still structurally incomplete. For diligence purposes, that means customer growth cannot be separated cleanly into retention, expansion, pricing, or new-user acquisition. Each of those could support the ARR story, but the company has not shown which one dominates.[CU001, CU006, CU007, CU008, CU009, CU010]
| Metric | Value | Date / period | Source / confidence | Implication | Missing denominator |
|---|---|---|---|---|---|
| Access status | Private beta with waitlist or member invite | 2026-08-28 | Official + corroborating press / high | Access remains scarce, which can amplify exclusivity and virality | No disclosure of waitlist size, invite conversion, or active users |
| ARR | ~$5M | 2026-01 | Management-stated via TechCrunch / medium | Shows monetized usage existed early in the year | No user count, price, or segment mix disclosed |
| ARR | ~$80M | 2026-08-26 | Management-stated via TechCrunch / medium | Implies very rapid commercialization before broad release | No customer count, payer count, or monthly recurring-revenue bridge disclosed |
| Implied ARR growth | ~16x from January to August | 2026-01 to 2026-08 | Derived from disclosed ARR points / medium | Suggests either exceptional retention, rapid acquisition, high ARPU, or all three | Cannot separate new logos, price, retention, or expansion |
| Public customer proof depth | Named beta-user anecdotes but no named paying customers | 2026-08-28 | Independent press synthesis / medium | Adoption is visible in stories, not in formal deployment metrics | No named customer list, no case studies, no review-platform corpus |
Rows separate observable adoption facts from what remains opaque. Revenue points are management-stated and should not be treated as audited customer-quality evidence.
[CU001, CU006, CU007, CU008, CU009, CU029]Because Instinct discloses no user counts, the funnel is expressed as a normalized evidence-strength index rather than as actual people or accounts.
Values are a relative index of observable funnel openness, not a disclosed customer count. They illustrate how much evidence disappears between top-of-funnel hype and named proof of durable usage.
[CU001, CU006, CU007, CU009, CU042, CU044]6.3 Named beta-user proof shows real utility and real trust breakage
Because Instinct is still private beta, the closest available customer-proof is not a classic case study or review-platform corpus. Instead, the chapter relies on named beta testers and practitioner commentary quoted by TechCrunch, Forbes, SC Media, AI Weekly, and secondary syntheses of launch-week user threads. That evidence is imperfect, but it is still materially better than relying on logos or hype alone because it names people, describes tasks, and captures what went right and wrong. On the positive side, several early users described work that sounds like genuine product usage rather than novelty demos. Sheel Mohnot described 677 messages in five days and 15 finished jobs, Jesse Middleton said he used Instinct daily for a week for travel, reservations, email follow-up and CRM work, and other users described itinerary checking, subscription savings, and family scheduling. On the negative side, the same public cohort produced the chapter’s strongest adverse evidence. Katie Jacobs Stanton said the system sent an email without asking, Claire Vo found previously ingested emails still searchable after she disconnected Google, Peter Yang complained about retention and deletion, Alex Cohen demonstrated prompt injection, and Forbes cited a $200 cancellation-fee incident. The polarity of these anecdotes matters: people were not indifferent. They either saw unusual utility or unusually serious trust failures, often both.[CU013, CU014, CU015, CU016, CU017, CU018]
| Customer / tester proxy | Segment | Deployment / use case | Production vs pilot | Outcome | Limitation |
|---|---|---|---|---|---|
| Sheel Mohnot | Tech-insider power user | Used Instinct intensively across doctor search, bill negotiation, WhatsApp vendor outreach, travel logistics, subscription cancellation, and toll payment | Pilot / private beta personal usage | Most detailed positive utility proof in public: 677 messages over five days and 15 completed jobs | Investor-user anecdote, not a disclosed paying customer or longitudinal cohort |
| Jesse Middleton | Founder / operator | Used it daily for a week across travel rebookings, restaurant reservations, email follow-up, CRM management, and LP data-room work | Pilot / private beta personal usage | Shows repeat usage across both personal and work-adjacent tasks; explicitly called the product awesome | Still anecdotal; no proof of long-term retention or payment level |
| Katie Jacobs Stanton | Consumer power user | Used mostly for personal needs and praised product capability before trust failed | Pilot / private beta personal usage | Strong evidence that the product initially feels magical even to sophisticated users | Trust broke when Instinct sent an email without approval, leading her to disconnect email |
| Claire Vo | Privacy-sensitive early adopter | Connected a personal Gmail account and later tested what remained after disconnecting access | Pilot / private beta personal usage | Shows serious trust failure around retained copies and plain-text storage | Adverse proof highlights risk, not durable adoption |
Because Instinct is still private beta and no named paying customers are publicly disclosed, this table uses named beta testers as the closest permissible customer-proof proxy.
[CU013, CU014, CU015, CU017, CU029, CU043]Instinct has richer named-user anecdotes than most stealth products, but the evidence is still weak on commercial visibility and formal retention proof.
Scores are analytical ratings of evidence quality, not company-reported metrics. Commercial visibility remains low because no named paying customers or public review-platform data are available.
[CU020, CU021, CU022, CU028, CU029, CU042]6.4 Durability is unproven and concentration risk is likely material
Instinct has not disclosed the metrics normally used to judge customer durability: churn, cohort retention, renewal rates, repeat usage frequency, or revenue retention. That silence would be a moderate concern for a normal consumer product and a major concern for a product that asks for unusually broad permissions. Without customer counts or retention curves, the company’s reported ARR growth can support multiple contradictory stories: strong retention and word-of-mouth expansion, rapid acquisition masking churn, high prices charged to a small cohort, or some combination of the three. The absence of these denominators is itself one of the chapter’s most important findings. Expansion potential is nevertheless visible. Broad 2026 survey data shows that consumer AI adoption is already mainstream enough for a product like Instinct to have a real addressable market: nearly half of U.S. adults use AI chatbots, daily use has reached about one-quarter of adults, and commerce-oriented AI usage is rising quickly. However, the same datasets make clear why Instinct’s next challenge is trust, not awareness. Large majorities expect AI to make personal information less secure, over half of consumers trust AI less than humans with personal data, and meaningful shares already punish brands for AI-related data concerns by canceling or switching. For Instinct, that means the upside is substantial if it proves safer controls, but the downside is equally clear: $80 million ARR from a private beta with no user denominator strongly suggests early concentration risk, and negative word of mouth could constrain expansion before the product ever reaches the early majority.[CU030, CU031, CU032, CU034, CU035, CU036]
| Metric | Value / status | Segment | Confidence | Evidence | Diligence ask |
|---|---|---|---|---|---|
| Customer count | Not disclosed | All users | medium | No official or press source reviewed provides an active-user or payer count | Request active users, paying users, invited users, and waitlist totals by month |
| NRR / GRR / churn | Not disclosed | All users | medium | No public retention metrics were found | Request retention cohorts and churn by acquisition month |
| Repeat usage anecdote | Daily for a week reported by Jesse Middleton | Power users | medium | Named user quote indicates repeat use beyond a one-off novelty demo | Request 30-day, 90-day, and weekly-active-user retention data |
| Intensive usage anecdote | 677 messages in five days reported by Sheel Mohnot | Power users | medium | Shows heavy engagement among at least some early adopters | Request distribution of task volume per active user |
| Positive satisfaction signal | Users described the product as amazing, awesome, or like magic | Power users | medium | Multiple quoted reactions in TechCrunch and secondary summaries | Request NPS, CSAT, or task-success survey results |
| Negative satisfaction signal | Unauthorized email, retained data after disconnect, prompt injection, and off-script booking incident | Power users | high | Multiple independent adverse reports from named users | Request complaint logs, postmortems, and action-reversal rates |
| Review-platform coverage | No public G2/Capterra/App Store corpus | Mainstream users | medium | Consistent with invite-only status and lack of mainstream app distribution | Request private-beta satisfaction research and expansion-readiness benchmarks |
Most durability measures are null because Instinct is private beta and does not publish cohorts. The table therefore distinguishes direct anecdotal repeat-use proof from missing formal retention data.
[CU006, CU014, CU015, CU017, CU018, CU019]| Risk or driver | Description | Impact | Severity | Evidence | Diligence path |
|---|---|---|---|---|---|
| Early-adopter concentration | ~$80M ARR while still private beta and without a disclosed user count could mean revenue is concentrated in a small group of heavy users | High downside if a small cohort churns or downgrades | high | Revenue disclosed without denominators; public user proof is anecdotal | Request top-decile revenue concentration and ARPU distribution |
| Virality as acquisition engine | Word of mouth, insider invites, and launch-week social proof appear to be key top-of-funnel channels | Medium upside and medium fragility | medium | Waitlist mechanics plus press focus on tech-insider distribution | Request acquisition-channel mix and invite-to-active conversion |
| Trust shock risk | Unauthorized actions or data-retention concerns can collapse adoption because personal assistants ask for intimate permissions | High | high | Named adverse incidents and survey evidence on privacy sensitivity | Request escalation data, rollback controls, and permission-policy changes |
| Expansion upside from low-friction interface | Text / WhatsApp access and no-app learning curve could support broader consumer penetration if controls improve | High upside | medium | Official interface description plus strong task-completion anecdotes | Test mainstream-user onboarding and conversion outside insider networks |
| Category competition from trusted incumbents | Consumer AI time is concentrated in established platforms, so Instinct must earn trust quickly to escape a niche beta cohort | Medium to high | medium | Sensor Tower and general-market review sources | Benchmark retention and willingness-to-pay against leading assistants |
Severity reflects the likely effect on revenue durability, not just PR risk. Several rows are inferences because Instinct discloses no customer concentration or cohort data.
[CU032, CU033, CU034, CU036, CU037, CU040]Illustrative scenarios show how many different retention paths could still fit the same ARR headline when user counts and cohorts are undisclosed.
These are scenario rows, not measured Instinct cohorts. They exist because the company discloses ARR but not retention, user counts, or cohort curves, so several very different durability stories remain possible.
[CU030, CU031, CU032, CU037, CU038]6.5 Exhibits
07Risks
7.1 Privacy, consent, and regulatory exposure
Instinct's defining risk is that its strongest product feature—autonomous action inside email, calendar, shopping, and messaging workflows—is also the source of its sharpest regulatory and consent exposure. Public criticism is not about generic AI hallucinations alone. It is about whether the assistant can act, retain, and repurpose sensitive user information in ways consumers did not clearly authorize. That creates a classic high-trust/high-liability profile. The policy backdrop in 2026 is no longer permissive by default. The EU AI Act is now operative, and the European Commission has already moved into active enforcement of transparency requirements. GDPR remains relevant because a personal assistant processes intimate communications, metadata, and behavioral context across multiple connected systems. In the United States, FTC guidance gives regulators several hooks if the product overstates its safety, misstates deletion or retention behavior, or blurs user consent boundaries. The result is not necessarily immediate prohibition, but it is a meaningful increase in compliance cost, design constraint, and enforcement optionality. For a product built on delegated action, trust and legal clarity cannot be patched in later.[CR001, CR002, CR003, CR004, CR005, CR006]
| Risk | Likelihood | Severity | Primary trigger | Why it matters |
|---|---|---|---|---|
| Consent / privacy breach | High | Critical | Unauthorized action or retention | Directly attacks trust and regulation |
| Prompt injection | High | High | Malicious inbound content | Can hijack tool use and autonomy |
| Platform / API dependency | Medium | High | Policy or pricing change | Instinct does not own key rails |
| Monetization opacity | Medium | High | Weak conversion or margin surprises | Valuation may outrun proof |
| Execution / governance gap | Medium | High | Scaling faster than controls | Small-team risk |
Likelihood and severity are ordinal judgments based on current public evidence and analogous 2026 AI governance data.
[CR001, CR009, CR013, CR018, CR021, CR026]| Risk | Source of obligation | Observed signal | Potential outcome | Mitigation need |
|---|---|---|---|---|
| Unauthorized autonomous communications | FTC / consent | Emails reportedly sent without asking | Consumer harm and enforcement | Explicit approvals / guardrails |
| Retention after OAuth revocation | GDPR / privacy law | Plain-text storage allegation | Deletion and data-rights risk | Verified deletion workflows |
| Opaque data-use license | Consumer protection / contract fairness | Broad data-rights criticism | Reputation and legal scrutiny | Plain-language narrowing |
| AI Act transparency obligations | EU AI Act | 2026 enforcement start | Compliance cost and launch gating | Model / agent disclosures |
| Public-data training uncertainty | Copyright / data law | Broader 2026 policy debate | Policy and litigation uncertainty | Stronger provenance and notices |
This table focuses on legal and regulatory vectors most directly tied to high-permission consumer AI assistants.
[CR002, CR003, CR004, CR005, CR006, CR007]The legal stack is broad rather than concentrated in one rule set.
Values are ordinal exposure scores, not legal probabilities.
[CR004, CR005, CR006, CR007, CR008, CR024]7.2 Security, prompt injection, and technical control risk
The technical risk stack is serious because autonomous assistants combine three dangerous properties at once: they ingest untrusted inputs, they hold sensitive context, and they can call tools. OWASP and 2026 security guidance still place prompt injection at the top of the risk list for agentic systems. An assistant that reads inbound emails or messages and then acts on those signals is exposed to indirect prompt injection unless it has strong permission boundaries, tool scoping, and execution isolation. The public allegations around Instinct make this more than a theoretical concern. Reported prompt-injection vulnerability and plain-text retention after OAuth revocation point to control weaknesses in exactly the areas that matter most for an autonomous assistant. Even if some allegations reflect early-beta conditions, they still demonstrate how narrow the margin for error is. NIST and OWASP both imply that production-grade controls should include identity-aware access boundaries, human override, deletion confidence, logging, and structured risk review. The public record does not yet show enough of those safeguards to treat the technical risk as fully mitigated.[CR009, CR010, CR011, CR012, CR016, CR017]
| Risk | Mechanism | Why severe | Public signal | Control expectation |
|---|---|---|---|---|
| Prompt injection | Malicious content manipulates agent decisions | Could trigger harmful actions | Reported vulnerability and OWASP priority | Input filtering and scoped tools |
| Permission overreach | Too-broad account scopes | Expands blast radius | Assistant needs many connected systems | Least privilege and step-up auth |
| Deletion failure | Residual data after disconnect | Creates privacy and breach risk | Reported retention concern | Provable deletion and logging |
| Insufficient audit trail | Weak logging of agent actions | Hard to investigate incidents | No public control detail | Immutable action logs |
| Model / tool error cascade | One wrong inference fans into more actions | Autonomy compounds mistakes | Category-wide agent concern | Human overrides and risk scoring |
Prompt injection and deletion controls are the two most visible public technical concerns today.
[CR009, CR010, CR011, CR012, CR023, CR033]A single autonomy or deletion failure can cascade through several stakeholder groups quickly.
The DAG is a causal synthesis rather than a dated event chronology.
[CR023, CR028, CR029, CR035, CR041, CR042]7.3 Business-model, platform, and competitive risk
Instinct's commercial risk is inseparable from platform dependence. The company does not own the dominant operating systems, messaging rails, email ecosystems, or model supply chain it needs to deliver a polished product. Apple, Google, Microsoft, Meta/WhatsApp, and model providers can all change pricing, policies, integration depth, or defaults. Some of those entities are also direct or adjacent competitors. That dependence compounds business-model ambiguity. The company must persuade users to both pay and trust at a level higher than a chat-only product requires, while also carrying meaningful variable AI serving costs. A large funding base helps, but it does not make the economics or distribution permanently safe. If model costs rise, APIs tighten, or bundled incumbents become good enough, Instinct's wedge can narrow quickly. The same logic applies competitively. A strong product can still lose if a safer-enough experience is bundled by a platform owner into a surface the user already trusts. Platform power is therefore one of the central risks to any standalone personal agent.[CR013, CR014, CR015, CR018, CR019, CR020]
| Risk | Driver | Impact | Why it could worsen | Indicator |
|---|---|---|---|---|
| Model-provider concentration | Few external model options | Margin and reliability pressure | Rapid pricing or capability changes | Provider cost / outage changes |
| Bundled incumbent competition | Apple / Google / Microsoft / Meta | Pricing and distribution pressure | Users default to built-in assistants | Major feature launches |
| Monetization ambiguity | Undisclosed pricing | Weak revenue-quality visibility | Conversion may depend on novelty | Pricing / ARPU disclosure |
| Trust-driven churn | Public backlash after incidents | Revenue and referral pressure | Launch brings broader scrutiny | Retention cohorts |
| Compute-cost inflation | Usage-sensitive autonomous workflows | Gross-margin compression | Heavy users trigger expensive tasks | Cost-to-serve per action |
Business risk is driven by the interaction between trust, platform dependency, and variable AI serving cost.
[CR013, CR014, CR015, CR018, CR019, CR020]Even after strong early traction, downside remains highly sensitive to trust and cost assumptions.
Scores are directional and intended to visualize uncertainty rather than to serve as a formal scoring model.
[CR018, CR019, CR020, CR034, CR036, CR040]7.4 Execution, governance, and synthesis
Execution risk is amplified because the public identity of Instinct is tightly bound to a single young founder, a small team, and a product that may be scaling faster than its visible governance structure. That can be a feature during product iteration, but it becomes a liability when the company must simultaneously manage incidents, regulators, hiring, infrastructure, and public trust. There is little public evidence of a deep management bench or mature operating system beyond the founder-led core. What makes the overall risk picture unusual is speed. The upside path requires sustained growth and expanding trust. The downside path can be much faster: one serious privacy, deletion, or autonomy incident can trigger a cascade through users, media, partners, and regulators. That asymmetry is what investors should focus on. The public record is sufficient to identify the main red flags, but not sufficient to bound downside financially or legally with high precision. That means the chapter supports a high risk rating with specific kill criteria rather than a numerically precise loss forecast.[CR021, CR022, CR023, CR027, CR028, CR029]
| Risk | Observed condition | Potential effect | Severity | Kill / watch trigger |
|---|---|---|---|---|
| Founder concentration | Public identity centered on one founder | Key-person exposure | High | Leadership disruption or loss of confidence |
| Small-team scaling gap | Team described as small | Controls lag growth | High | Repeated incidents or service degradation |
| Governance opacity | No public management-bench detail | Slow crisis handling | Medium-high | Regulator or partner concerns |
| Compliance maturity gap | High-permission product pre-launch | Launch delay or redesign | High | Inability to clear legal review |
| Incident-response immaturity | Sparse public control detail | Slow user recovery after failure | High | Visible unresolved safety incident |
Execution risk is amplified because risk management requirements for an autonomous consumer assistant are unusually high for this stage.
[CR021, CR022, CR023, CR027, CR028, CR029]Trust, privacy, and platform dependency dominate the risk picture.
Cells are ordinal descriptors synthesized from public evidence and 2026 governance reports.
[CR026, CR027, CR031, CR032, CR041, CR042]7.5 Exhibits
08Valuation
8.1 Investment Thesis and Anti-Thesis
The bull thesis for Instinct rests on four propositions: (1) consumer AI assistants will become the dominant personal productivity interface, creating a winner-take-most market; (2) Instinct's 16x ARR growth in 7 months signals genuine product-market fit rarely achieved in consumer software; (3) Noah Shinn's combination of academic AI credibility and consumer product intuition is exceptionally rare at age 23; and (4) with $350M in capital, Instinct has the runway to commercialize before competitors neutralize its lead. The anti-thesis is equally compelling: (1) no disclosed pricing means the ARR figure may reflect non-recurring or promotional arrangements; (2) large incumbents — Apple, Google, Microsoft — have near-unlimited distribution to absorb AI-assistant demand at zero marginal CAC; (3) AI inference costs are structural and will compress gross margins unless negotiated down; and (4) privacy backlash in August 2026 may create regulatory friction or churn risk that has not yet materialized in the ARR figure. The net result is a company at the boundary between venture bet and strategic platform risk.[CV001, CV002, CV003, CV004, CV005, CV006]
| Dimension | Bull argument | Bear argument |
|---|---|---|
| Market | AI assistants become dominant productivity interface; winner-take-most dynamics | OS-native assistants absorb market; Google/Apple distribution insurmountable |
| Product | 16x ARR growth in 7 months is rare consumer PMF signal | No disclosed pricing; beta users may not pay at scale |
| Team | Shinn combines academic AI depth (ReAct, Reflexion) and consumer intuition | Single 23-year-old founder; thin public operating track record |
| Financials | $350M capital; 36-58 month runway; demonstrated capital efficiency | ARR unverified; burn unknown; no monetization model at 31x multiple |
| Regulatory | Privacy risk manageable with architecture adjustments | EU AI Act + California CPRA pose structural risk to email-access product |
Each dimension maps to a specific chapter: market to Ch2, product to Ch5, team to Ch1, financials to Ch4, regulatory to Ch7.
[CV001, CV002, CV003, CV004, CV005]8.2 Valuation Context and Entry Discipline
Instinct's $2.5 billion post-money valuation at Series B implies a 31x ARR multiple on management-stated $80M ARR. For context, the median consumer software unicorn at Series B has historically traded at 10-20x ARR; the top decile of hypergrowth consumer SaaS reached 30-50x ARR at peak market conditions in 2021. In the current 2026 environment, AI-native software commands a structural premium. KPMG Venture Pulse Q2 2026 reports median Series B multiples of 18-25x ARR for AI-native software; Instinct at 31x is 24-72% above this median. Key concerns include: (1) unverified ARR reduces confidence in the denominator of the multiple; (2) no pricing model means future ARR sustainability is unknown; (3) the Series A implied a 100x multiple, creating significant dilution that limits return expectations for Series B investors. A mark-to-market entry joining post-Series B would need a 5-7x return to justify the risk premium — achievable only in the bull scenario. Applying a 20-30% discount for monetization uncertainty implies fair value of $1.7-2.0B, versus the $2.5B round price.[CV009, CV010, CV011, CV012, CV013, CV014]
| Dimension | Assessment | Confidence |
|---|---|---|
| Recommendation | Track — do not invest at current terms | Medium |
| Valuation stance | Stretched — 31x unverified ARR above 18-25x median | High |
| Risk rating | High — privacy exposure; undisclosed monetization; competitive | High |
| Overall score | 6.5 / 10 | Medium |
Scores based on aggregated evidence across 8 diligence chapters. Confidence ratings reflect verifiability of underlying data, not certainty of outcomes.
[CV001, CV009, CV010]8.3 Bull, Base, and Bear Scenario Analysis
Bull scenario (25% probability): Instinct launches a paid tier at $25-50/month by Q1 2027, achieving 10% conversion from a 2-million user base. ARR grows to $250M+ by end-2027. Series C at $8-10B in 2027, IPO at $15-20B in 2029. Series B investors achieve 5-8x return. Base scenario (55% probability): Monetization is delayed until mid-2027 as Instinct navigates privacy regulations. ARR growth moderates to $8-10M/month. Next round raises at $4-5B with moderate dilution. Exit via IPO or strategic acquisition at $6-8B in 2030-2031. Series B investors achieve 2-3x return. Bear scenario (20% probability): Privacy enforcement from the EU or California forces significant product changes. Monetization stalls below $200M ARR. A strategic acquirer absorbs Instinct at 0.5-1x revenue or $300-500M — a full write-down for Series B investors. The downside is not remote: regulatory risk is real, the monetization model remains undefined, and the AI-assistant market may consolidate around OS-native assistants faster than Instinct can differentiate. Expected value across scenarios yields roughly 2.5x for a Series B co-investor at current entry — insufficient to justify the risk premium.[CV017, CV018, CV019, CV020, CV021, CV022]
| Scenario | Probability | Series B return | Key assumption |
|---|---|---|---|
| Bull | 25% | 5-8x | Paid tier Q1 2027; 10% conversion; ARR $250M+ end-2027; IPO at $15-20B in 2029 |
| Base | 55% | 2-3x | Monetization delayed to mid-2027; ARR $120-160M end-2027; exit $6-8B in 2030 |
| Bear | 20% | <0.1x | Privacy enforcement; monetization failure; distress sale at $300-500M |
Scenario probabilities are analyst judgment informed by chapter-level evidence. Series B return calculated at $2.5B entry valuation. Bear case is not remote.
[CV017, CV018, CV019, CV020, CV021, CV022]8.4 Comparable Valuation Set
The relevant comparable set spans three tiers: (1) direct consumer AI assistants (Perplexity AI, Character.AI); (2) next-generation consumer SaaS at early hypergrowth stages (Superhuman, Motion); and (3) AI-native horizontal platforms (Scale AI, Cohere, Mistral). No public company comparables exist that map precisely to Instinct's stage and positioning. Among private rounds, Perplexity AI raised at $1B valuation in April 2024 at approximately $25-30M ARR, implying 33-40x ARR — above Instinct's 31x but with a launched paid tier. Character.AI was acquired by Google in September 2024 at approximately $2.7B, representing ~25x estimated revenue. Scale AI's Series F in December 2024 valued the company at $13.8B at ~11x ARR — with audited financials and profitable government contracts. Cohere raised at $5B valuation in June 2024 at approximately $200M ARR (25x) with disclosed B2B contracts. Applying a 20-30% discount for Instinct's monetization uncertainty implies fair value of $1.7-2.0B versus the $2.5B round price.[CV025, CV026, CV027, CV028, CV029, CV030]
| Company | Round date | Valuation | ARR multiple |
|---|---|---|---|
| Perplexity AI | April 2024 | $1.0B | ~33-40x ARR |
| Character.AI (acquisition) | September 2024 | $2.7B | ~27x ARR |
| Scale AI | December 2024 | $13.8B | ~11x ARR |
| Cohere | June 2024 | $5.0B | ~25x ARR |
| Instinct | August 2026 | $2.5B | ~31x unverified ARR |
All ARR figures are analyst estimates. Instinct's ARR is management-stated and unverified. All comparables had either a paid tier or contractual revenue at time of valuation; Instinct does not.
[CV025, CV026, CV027, CV028, CV029]8.5 Exit Readiness, Diligence Asks, and Thesis-Break Triggers
Exit pathways include: (1) IPO — viable in 2029+ if Instinct achieves $300M+ ARR with a clear monetization model; (2) strategic acquisition — most likely by Apple, Google, Microsoft, or Salesforce, with acquisition multiples of 5-10x forward ARR; (3) private secondary market exit — possible in 2027-2028 as the company matures. Before any investment decision, four blocking items must be completed: independent ARR verification via third-party audit; full disclosure of the pricing model and conversion funnel; legal review of EU AI Act, UK DPA, and California CPRA compliance; and investor rights agreement review for liquidation preferences and anti-dilution. Thesis-break triggers include: ARR growth below $5M/month for two consecutive quarters; regulatory enforcement action in any major jurisdiction; departure of CEO Noah Shinn; or failure to launch a paid tier by Q2 2027. Any of these triggers should prompt immediate re-evaluation regardless of ARR trajectory.[CV033, CV034, CV035, CV036, CV037, CV038]
| Trigger | Threshold | Recommended action |
|---|---|---|
| ARR growth deceleration | Growth < $5M/month for two consecutive quarters | Re-evaluate; request ARR bridge and cohort data |
| Regulatory action | Any enforcement action in EU, UK, or California related to privacy | Immediate re-evaluation; engage legal counsel for product-change assessment |
| Key-person departure | CEO Noah Shinn departure or other principal technical author | Downgrade to sell; flag as thesis-break event for IC review |
| Monetization failure | No paid tier launched by Q2 2027 | Downgrade to pass; trigger write-down consideration for existing holders |
Threshold definitions are fixed at the time of this report. Triggers are binary flags for investment committee re-evaluation, not automatic sell signals.
[CV033, CV034, CV035, CV036]| Diligence ask | Criticality | Blocking |
|---|---|---|
| Independent ARR verification via third-party audit or rep-and-warranty insurance | Critical | Yes |
| Full disclosure of pricing model, conversion funnel, and paying-user count | Critical | Yes |
| Privacy compliance review across EU AI Act, UK DPA, and California CPRA | High | Yes |
| Investor rights agreement review for liquidation preferences and anti-dilution | High | Yes |
All four items are blocking for any investment decision at current valuation.
[CV037, CV038, CV039, CV040]8.6 Exhibits
Disclaimer
This report is produced for informational purposes only and does not constitute investment advice. All data derives from publicly available sources as of 2026-08-28. No audited financials have been reviewed. The analysis reflects the author's independent judgment based on available evidence and should not be relied upon as the sole basis for any investment decision.
Evidence index
| ID | Statement | Confidence | Sources |
|---|---|---|---|
| CO001 | Instinct is operated by Spear Street Technology Inc., a California corporation. | High | SO001, SO003 |
| CO002 | Spear Street Technology was incorporated in California in 2025. | Medium | SO001 |
| CO003 | Instinct raised $250 million in a Series B round announced August 26, 2026. | High | SO001, SO003 |
| CO004 | The Series B was co-led by Index Ventures and Benchmark. | High | SO001, SO003, SO006 |
| CO005 | The Series B valued Instinct at $2.5 billion post-money. | High | SO001, SO003, SO013 |
| CO006 | Instinct's total capital raised across all rounds is $350 million as of August 2026. | High | SO001, SO003 |
| CO007 | Noah Shinn is the founder of Instinct and CEO of Spear Street Technology. | High | SO003, SO005, SO007 |
| CO008 | Noah Shinn was 23 years old at the time of the August 2026 Series B announcement. | Medium | SO003, SO007, SO008 |
| CO009 | Noah Shinn previously worked as a research scientist at Sierra, an enterprise AI agent company. | Medium | SO003, SO007, SO008 |
| CO010 | Noah Shinn dropped out of Northeastern University in 2023. | Medium | SO008, SO007 |
| CO011 | Noah Shinn conducted machine learning and programming language research at MIT before founding Instinct. | Medium | SO008, SO007 |
| CO012 | Noah Shinn is the lead author of the Reflexion paper published at NeurIPS 2023. | High | SO024, SO023, SO008 |
| CO013 | The Reflexion framework achieved a 91% pass@1 rate on HumanEval, outperforming GPT-4's reported 80% on the same benchmark. | High | SO024, SO023 |
| CO014 | Instinct's product is an AI personal assistant accessed via SMS and WhatsApp. | High | SO001, SO002, SO004 |
| CO015 | Instinct autonomously manages email, calendar, scheduling, travel, shopping, and other tasks on behalf of users. | High | SO001, SO002, SO004 |
| CO016 | Instinct was in private beta (invite-only) as of August 2026. | High | SO001, SO002 |
| CO017 | Instinct reported approximately $80 million ARR as of August 2026. | Medium | SO001, SO003 |
| CO018 | Instinct grew from approximately $5 million ARR in January 2026 to $80 million ARR in August 2026—a 16× increase in approximately 8 months. | Medium | SO001, SO003 |
| CO019 | Instinct's headquarters is in San Francisco, California. | High | SO001, SO003, SO004 |
| CO020 | Kleiner Perkins, led by partner Mamoon Hamid, led Instinct's Series A round. | Medium | SO003, SO028 |
| CO021 | Conviction Partners (Sarah Guo) is an early investor in Instinct. | Medium | SO003, SO029 |
| CO022 | Greenoaks Capital is an investor in Instinct. | Medium | SO003 |
| CO023 | Instinct's team is described as a small San Francisco team with backgrounds from MIT and Sierra. | Low | SO003, SO007 |
| CO024 | Instinct's terms of service grant a perpetual and irrevocable license to access, store, use, and modify all user data—including email content, screen captures, and keyboard inputs—for any purpose including AI training, even after the service is discontinued. | High | SO002, SO014, SO019 |
| CO025 | Early beta testers reported that Instinct sent emails on their behalf without explicit per-action approval from the user. | High | SO002, SO016 |
| CO026 | Security researchers demonstrated that Instinct could be manipulated through prompt injection attacks delivered via malicious email content. | High | SO015, SO002 |
| CO027 | Instinct stored email content in plain text that remained accessible even after users revoked the service's Google account access. | Medium | SO016, SO017 |
| CO028 | Instinct added a user data deletion tool to its interface following public backlash in late August 2026, though the underlying terms of service were not changed. | High | SO002, SO017 |
| CO029 | Instinct requires access to users' email accounts, messaging platforms, calendar, device audio, location, and screen captures to provide its full assistant functionality. | High | SO002, SO004, SO018 |
| CO030 | Instinct's terms of service allow the AI to enter binding agreements and execute financial transactions on behalf of users. | High | SO002, SO019 |
| CO031 | No regulatory investigations, enforcement actions, or lawsuits against Instinct or Spear Street Technology have been reported in any source reviewed as of August 2026. | Low | SO002, SO015 |
| CO032 | Instinct's headcount is not publicly disclosed; reporting describes the team as small and estimated at fewer than 50 employees. | Low | SO001, SO003 |
| CO033 | Reflexion co-authors include Federico Cassano, Ashwin Gopinath, Karthik Narasimhan, and Shunyu Yao. | High | SO024, SO023 |
| CO034 | Sierra is an enterprise AI agent company; Noah Shinn was among its earliest employees. | Medium | SO025, SO007 |
| CO035 | Noah Shinn co-developed τ-bench, a benchmark for evaluating AI agents' ability to handle real-world user interactions, tool invocations, and business-rule compliance across multiple runs. | Medium | SO008, SO005 |
| CO036 | Index Ventures has backed major technology companies including Dropbox, Stripe, and Robinhood from early stages. | High | SO026, SO001 |
| CO037 | Benchmark has led investments in Twitter, Snap, Uber, and Discord among other leading consumer technology companies. | High | SO027, SO001 |
| CO038 | Instinct's valuation rose from approximately $50 million at seed stage to $2.5 billion at Series B—a 50× step-up—in approximately 6 months in 2026. | Medium | SO003 |
| CO039 | Instinct's valuation trajectory of $50M → $500M → $2.5B in approximately six months in 2026 is exceptionally rapid even by the standards of high-growth consumer AI in the same period. | Medium | SO003, SO001 |
| CO040 | No board members, board observers, or governance representatives of Spear Street Technology have been named in any public reporting as of the August 2026 run date. | Medium | SO001, SO003 |
| CO041 | At $2.5 billion valuation on approximately $80 million ARR, Instinct implies a revenue multiple of approximately 31× ARR as of August 2026. | Medium | SO001, SO003 |
| CM001 | The consumer AI personal assistant market encompasses software products that understand natural language and autonomously execute tasks for individual consumers | High | SM001, SM002 |
| CM002 | Core market participants include platform incumbents Apple Siri, Google Assistant, Amazon Alexa, Microsoft Cortana, and Samsung Bixby | High | SM008, SM009, SM003 |
| CM003 | AI-native entrants in the consumer assistant market include Instinct, Rabbit r1, and Humane AI Pin | High | SM011, SM016, SM017 |
| CM004 | The defining characteristic of the 2025-2026 market shift is the transition from reactive query-response assistants to proactive agentic systems that take autonomous action | High | SM020, SM024 |
| CM005 | Instinct differentiates through SMS and WhatsApp interface, deep permission model, and autonomous task execution without step-by-step confirmation | High | SM004, SM011 |
| CM006 | Platform incumbents have distribution advantages through iOS and Android installed bases but limited autonomy compared to AI-native startups | Medium | SM008, SM009, SM020 |
| CM007 | OpenAI ChatGPT expanded agentic capabilities in 2026 with agent mode, representing crossover competition from AI chatbot segment | High | SM010, SM028 |
| CM008 | The global consumer AI personal assistant market reached an estimated 4.84 billion USD in 2026 | High | SM001, SM003 |
| CM009 | The consumer AI assistant market grew at a 42.2 percent CAGR from 2025 baseline of 3.4 billion USD | Medium | SM001 |
| CM010 | The broader intelligent personal assistant market including enterprise reached approximately 17.95 billion USD in 2026 growing at 25.9 percent CAGR | Medium | SM002 |
| CM011 | Market projections suggest the consumer AI assistant segment will reach 19.6 billion USD by 2030 if current growth rates sustain | Low | SM001, SM007 |
| CM012 | Instinct achieved 16x ARR growth from 5 million USD to 80 million USD in approximately 8 months | High | SM004, SM015 |
| CM013 | Market sizing estimates carry significant uncertainty due to definitional ambiguity around personal assistant versus general AI chatbot categories | High | SM001, SM002 |
| CM014 | The agentic assistant serviceable addressable market is estimated at 1-2 billion USD in 2026 as a nascent category | Low | SM019, SM020 |
| CM015 | Privacy-conscious users and those in regulated industries represent structural exclusions from Instinct addressable market | High | SM005, SM021 |
| CM016 | The consumer AI assistant market segments by task type including scheduling, email, travel, shopping, and life administration | High | SM001, SM022 |
| CM017 | By privacy tolerance the market bifurcates between privacy-sensitive users rejecting broad data access and convenience-first users trading privacy for functionality | High | SM021, SM025 |
| CM018 | Instinct target segment appears to be privacy-tolerant power users with high payment willingness who value autonomous execution | Medium | SM004, SM011 |
| CM019 | Geographic segmentation shows North America and Western Europe as primary markets due to smartphone penetration and consumer spending power | High | SM001, SM022 |
| CM020 | Age demographics for AI assistant adoption skew toward 25-45 year old professionals with complex scheduling needs and disposable income | Medium | SM021, SM022 |
| CM021 | High-net-worth individuals represent a premium segment potentially replacing human assistants with AI at 100 plus USD per month price points | Low | SM024, SM029 |
| CM022 | Generative AI capability improvements have made natural language understanding and task completion reliable enough for production use cases | High | SM020, SM022 |
| CM023 | Smartphone ubiquity provides the device substrate and connectivity for always-available AI assistance | High | SM001, SM022 |
| CM024 | Consumer familiarity with AI through ChatGPT has normalized AI interaction and reduced adoption friction | High | SM010, SM028 |
| CM025 | Productivity demands from remote and hybrid work arrangements have increased demand for delegation tools | Medium | SM022, SM024 |
| CM026 | SMS and messaging-app interfaces eliminate the need to learn new applications reducing onboarding friction for AI assistants | High | SM004, SM011 |
| CM027 | FTC has signaled increased scrutiny of AI agents that enter binding transactions on behalf of consumers | High | SM012, SM005 |
| CM028 | EU AI Act may classify autonomous personal assistants as high-risk systems requiring conformity assessments | Medium | SM013 |
| CM029 | Privacy regulations including CCPA and GDPR create compliance overhead and limit data retention practices for AI assistants | High | SM014, SM013 |
| CM030 | Consumer trust deficits following high-profile AI failures and privacy incidents constrain market adoption | High | SM021, SM025 |
| CM031 | Platform gatekeeping by Apple and Google limits third-party assistant capabilities on mobile devices | High | SM008, SM029 |
| CM032 | Security vulnerabilities including prompt injection attacks demonstrated against Instinct undermine reliability of agentic assistants | High | SM005, SM023 |
| CM033 | Instinct terms of service grant a perpetual and irrevocable license to use store and modify user data raising privacy concerns | High | SM005, SM023 |
| CM034 | The market trajectory depends heavily on whether the agentic AI trust gap closes faster than regulatory constraints tighten | Medium | SM012, SM025 |
| CM035 | AI assistant market fragmented between incumbents with distribution advantages and startups with agentic capability advantages | High | SM020, SM026 |
| CP001 | Instinct competes most directly with consumer-facing assistants that can reason across tasks and act on behalf of users, not with every general chatbot. | Medium | SP001, SP004, SP006, SP008, SP009, SP011, SP013, SP014 |
| CP002 | Humane is better treated as a predecessor cautionary tale than a live direct competitor because the AI Pin was shut down after HP acquired the company. | Medium | SP018 |
| CP003 | OpenAI Operator is a direct benchmark because it is designed to use a browser to perform tasks for the user. | Medium | SP004 |
| CP004 | Google Gemini is a powerful adjacent rival because it combines general reasoning with Google account, search, and device adjacency. | Medium | SP006, SP007 |
| CP005 | Apple Intelligence makes OS-native assistance a default expectation for premium smartphone users, even if Apple is less autonomous than Instinct today. | Medium | SP008 |
| CP006 | Microsoft Copilot competes indirectly by bundling AI productivity into a much larger software and subscription ecosystem. | Medium | SP009, SP010 |
| CP007 | Claude is more of a reasoning and writing substitute than a full consumer action-taking competitor in its current public positioning. | Medium | SP011, SP012 |
| CP008 | Perplexity competes most clearly on search, research, and answer quality rather than delegated account actions. | Medium | SP013 |
| CP009 | Superhuman, Motion, and Cal.com each own a narrower workflow that Instinct tries to combine into a single assistant experience. | Medium | SP015, SP016, SP017 |
| CP010 | Instinct's SMS and WhatsApp delivery is a real differentiator because it removes app-download friction and drops the assistant into a channel users already inhabit. | High | SP001, SP022, SP024 |
| CP011 | Google, Apple, Microsoft, and Meta all enjoy stronger native ecosystem integration than Instinct because they control devices, identity, or default surfaces. | High | SP006, SP007, SP008, SP009, SP010, SP014 |
| CP012 | Brand trust today is structurally higher for Apple, Google, and Microsoft than for a private-beta startup with visible autonomy incidents. | Medium | SP002, SP008, SP009, SP010, SP025, SP026 |
| CP013 | Paid AI subscription plans from OpenAI, Google, Claude, and specialist tools demonstrate that consumers and prosumers accept recurring pricing for assistant-like software. | High | SP005, SP007, SP010, SP012, SP015, SP016, SP017 |
| CP014 | Free assistants from Meta and bundled assistants from Apple, Google, and Microsoft pressure the ceiling on what Instinct can charge without clear autonomy advantages. | Medium | SP006, SP007, SP008, SP009, SP010, SP014 |
| CP015 | Humane's shutdown is competitive evidence that consumers will not tolerate fragile high-friction assistant products just because the concept is novel. | Medium | SP018 |
| CP016 | Instinct's strongest direct moat claim is higher autonomy across communications and transactions rather than broader brand reach or ecosystem control. | Medium | SP001, SP002, SP004, SP006, SP008, SP009, SP014 |
| CP017 | Specialist workflow tools can remain durable because they pair deeper domain UX with lower trust risk than a general assistant that touches many systems. | Medium | SP015, SP016, SP017 |
| CP018 | Switching costs for consumers are moderate because the status quo is fragmented and many users already multi-home among multiple apps and assistants. | Medium | SP005, SP007, SP012, SP013, SP015, SP016, SP017 |
| CP019 | Multi-homing weakens moat durability for everyone except the platform incumbents, because users can compare assistants without major data migration costs. | Medium | SP005, SP007, SP012, SP013, SP014, SP015, SP016, SP017 |
| CP020 | The largest channel and identity surfaces are owned by Apple, Google, Microsoft, Meta, and WhatsApp rather than by Instinct itself. | Medium | SP007, SP008, SP009, SP010, SP014, SP024 |
| CP021 | Trust and safety posture are competitive variables because a startup that mishandles autonomy can lose to less capable but more trusted incumbents. | Medium | SP002, SP019, SP020, SP025, SP026 |
| CP022 | Publicly available competitive facts remain uneven: pricing and product positioning are visible, but retention, real usage depth, and true task success rates are mostly undisclosed. | Medium | SP005, SP007, SP010, SP012, SP013, SP015, SP016, SP017 |
| CP023 | Instinct is earlier than most rivals in brand maturity but ahead of many general assistants in willingness to execute cross-app tasks without per-action confirmation. | Medium | SP001, SP002, SP004, SP006, SP008, SP009, SP011, SP013 |
| CP024 | OpenAI, Google, Apple, and Microsoft all possess materially greater compute, distribution, and default-placement advantages than Instinct. | High | SP004, SP006, SP008, SP009 |
| CP025 | Perplexity, Claude, and Meta AI are easier for users to sample than Instinct because they are broadly available, while Instinct remains invite-only. | Medium | SP001, SP011, SP012, SP013, SP014 |
| CP026 | Instinct's private-beta exclusivity creates scarcity and buzz but limits the public proof set versus broad-availability competitors. | Medium | SP001, SP002, SP003 |
| CP027 | Specialists such as Superhuman and Motion market concrete workflow ROI rather than general intelligence, which may make them easier to trust and budget for. | Medium | SP015, SP016 |
| CP028 | Cal.com is better understood as scheduling infrastructure and workflow tooling than as a full substitute for Instinct, but it competes for one important user job. | Medium | SP017 |
| CP029 | The competitive landscape includes direct agentic rivals, broad AI incumbents, and specialist workflow tools, so no single comparison set is sufficient. | Medium | SP004, SP006, SP008, SP009, SP011, SP013, SP015, SP016, SP017 |
| CP030 | Law and economics commentary highlights the risk that platform incumbents and standalone assistants may be governed by mismatched competitive rules. | Medium | SP019 |
| CP031 | Cyberhaven's 2026 risk report indicates that the rise of AI agents is making security and governance a more prominent adoption variable across assistant categories. | Medium | SP020 |
| CP032 | Business of Apps shows massive ChatGPT and WhatsApp scale, underscoring how difficult it is for a startup to match incumbent reach without viral differentiation. | Medium | SP021, SP022, SP024 |
| CP033 | The Accio 2026 assistant comparison reflects a market conversation shifting from chat quality toward autonomy, integrations, and task execution. | Medium | SP023 |
| CP034 | The main evidence against a durable Instinct moat is that every major platform owner is moving toward more agentic behavior from a stronger installed base. | Medium | SP004, SP006, SP008, SP009, SP014, SP019, SP020 |
| CP035 | The main evidence for a durable Instinct wedge is that the product is optimized around delegated personal operations rather than around generic chat or one narrow workflow. | Medium | SP001, SP002, SP015, SP016, SP017, SP024 |
| CP036 | Public sources still do not disclose Instinct's pricing, retention, or task-level success rates versus competitors, which blocks precise competitive scoring. | Low | SP001, SP002, SP003 |
| CP037 | Another unresolved gap is whether consumers will prefer one general assistant or a portfolio of specialist tools plus incumbent AI surfaces. | Low | |
| CP038 | Competition later in the report should be read through trust, distribution, and ecosystem control at least as much as through raw model capability. | Medium | SP002, SP008, SP009, SP010, SP019, SP020, SP025, SP026 |
| CI001 | Instinct raised $100 million in a Series A round in January 2026 led by Kleiner Perkins. | High | SI001, SI015 |
| CI002 | Instinct raised $250 million in a Series B round on August 26, 2026 co-led by Index Ventures and Benchmark. | High | SI001, SI008 |
| CI003 | The Series B valued Instinct at $2.5 billion post-money. | High | SI001, SI002 |
| CI004 | Instinct's $350M total raised implies a capital efficiency ratio of approximately 4.4x relative to $80M ARR, comparing favorably to AI SaaS peers typically ranging 2-5x. | Medium | SI001, SI003 |
| CI005 | Greenoaks Capital and Conviction Capital also participated in Instinct's funding rounds alongside the lead investors. | Medium | SI001, SI002 |
| CI006 | Kleiner Perkins partner Mamoon Hamid led the Series A investment in Instinct. | Medium | SI002, SI015 |
| CI007 | Instinct reported approximately $5 million ARR at the close of its Series A in January 2026 per management statements. | Medium | SI002 |
| CI008 | Instinct reported approximately $80 million ARR at the close of its Series B in August 2026 per management statements. | Medium | SI001, SI002 |
| CI009 | Instinct's ARR grew approximately 16× in 7 months from January to August 2026 per management-stated figures. | Medium | SI001, SI002 |
| CI010 | Instinct's implied average monthly net-new ARR over January–August 2026 was approximately $10.7 million. | Medium | SI001 |
| CI011 | Instinct's ARR figures are management-stated and have not been independently verified or audited by any publicly disclosed third party. | High | SI001, SI003 |
| CI012 | No audited financial statements, prospectus, or third-party financial audit for Instinct or Spear Street Technology have been published as of August 2026. | High | SI001, SI004 |
| CI013 | Gross margin for comparable consumer AI SaaS businesses ranges from 50–75%; Instinct's higher LLM inference intensity suggests the lower end of this range. | Medium | SI005, SI007 |
| CI014 | AI inference costs for autonomous AI assistant products are estimated at 15–35% of revenue based on published agentic AI cost structures. | Medium | SI010, SI011 |
| CI015 | Applied to Instinct's $80M ARR, estimated LLM inference costs of 15–35% imply $12–$28 million in annual AI inference costs. | Low | SI010, SI012 |
| CI016 | Instinct has not disclosed its pricing model, average revenue per user, or subscription tier structure as of August 2026. | Medium | SI001, SI004 |
| CI017 | Consumer AI subscription products have historically struggled to sustain paying user bases beyond early adopters, per Business Insider analysis. | Medium | SI017 |
| CI018 | Instinct's viral waitlist model is likely to result in low customer acquisition costs compared to paid marketing, though this is inferred from distribution mechanics and not confirmed. | Low | SI001, SI016 |
| CI019 | Instinct has not disclosed any monetization model, path to profitability, or unit economics targets as of August 2026—a material gap at $2.5B valuation. | High | SI004, SI016 |
| CI020 | Assuming a monthly burn rate of $3–9M (sector-informed estimate), Instinct's $350M in total capital implies a runway of approximately 19–58 months. | Low | SI019, SI020 |
| CI021 | The base-case estimate of $5M monthly burn at Instinct implies approximately 35 months of runway—sufficient for a commercial launch and first monetization cycle. | Low | SI019, SI020 |
| CI022 | LLM provider dependency is a key financial risk: if Instinct's undisclosed LLM provider raises API pricing or restricts access, Instinct's cost structure could deteriorate materially. | Medium | SI010, SI011 |
| CI023 | Instinct's August 2026 privacy backlash creates a risk of user churn and ARR growth deceleration that could pressure the financial model significantly. | Medium | SI022, SI023 |
| CI024 | The historical failure of consumer AI companies like Inflection AI and Character AI to monetize at scale before acquisition is a risk benchmark for Instinct's monetization path. | Medium | SI017, SI018 |
| CI025 | Instinct's valuation increased approximately 5× from roughly $500M at Series A to $2.5B at Series B in approximately 7 months—one of the fastest step-ups in consumer software history at this scale. | Medium | SI001, SI002, SI005 |
| CI026 | Top AI SaaS companies in 2026 typically trade at 25–50× ARR depending on growth rate and category risk, according to SaaStr benchmarks. | High | SI005, SI007 |
| CI027 | Instinct's 31× ARR multiple at Series B is within the typical range for hypergrowth AI SaaS but on the higher end given pre-commercial status and consumer category risk. | Medium | SI005, SI007 |
| CI028 | Annual LLM inference costs at Instinct are estimated at $12–$28M based on 15–35% inference-cost-to-revenue ratios applied to $80M ARR. | Low | SI010, SI012 |
| CI029 | A 16× ARR growth in 7 months would place Instinct among the fastest-ever consumer software revenue ramps, comparable to early-stage ChatGPT and Slack growth trajectories. | Medium | SI005, SI006 |
| CI030 | Consumer AI personal assistant companies are expected to face significant monetization challenges as the market shifts from curiosity-driven adoption to value-driven retention. | Medium | SI016, SI017 |
| CI031 | The absence of audited financials and the single-source nature of Instinct's ARR claims make independent financial verification the primary diligence requirement before any investment decision. | Medium | SI004, SI018 |
| CI032 | At Series A, Instinct raised $100M against $5M ARR (capital efficiency: 0.05× ARR per $M raised); at Series B, $250M against $80M ARR (0.32×)— a 6× improvement in capital efficiency. | Medium | SI001, SI002 |
| CI033 | Instinct's consumer segment implies lower net revenue retention (NRR) relative to enterprise SaaS benchmarks, as consumer products typically exhibit higher churn and more volatile expansion dynamics. | Low | SI006, SI018 |
| CI034 | Consumer AI subscription pricing in 2026 ranges from $0 (ad-supported) to $100+/month (high-capability premium), with most established players in the $10–$30/month tier for consumer services. | Medium | SI024, SI025 |
| CI035 | Instinct's private beta status means its current ARR may derive from a small cohort of early paying users or commercial arrangements not publicly described, creating concentration risk in the revenue base. | Medium | SI001, SI016 |
| CE001 | Instinct is a messaging-native personal assistant accessed through text or calls on the official surface and via WhatsApp in third-party reporting, without requiring a new app download. | High | SE001, SE019 |
| CE002 | Instinct connects to user applications and devices including email, messaging, screen, audio, and location, giving it unusually broad consumer-context access. | High | SE001, SE002, SE019 |
| CE003 | Instinct remained available only to a private access group as of 2026-08-28 because the company said it was still scaling compute. | High | SE001, SE019 |
| CE004 | Instinct’s legal and product surface authorize autonomous actions on connected services and can make resulting agreements, commitments, or transactions binding on the user. | High | SE002, SE003, SE019 |
| CE005 | Publicly described tasks include inbox management, reminders, appointments, restaurant reservations, rides, travel, shopping, and other life-admin chores. | Medium | SE001, SE019, SE021 |
| CE006 | The operating workflow is messaging-first: a request arrives through a text-like surface, context is retrieved from linked systems, the agent executes, and later follow-up can happen in the same thread. | Medium | SE001, SE019 |
| CE007 | No reviewed public source disclosed a pricing page, subscription schedule, or general-availability launch date for Instinct. | Medium | SE001, SE019 |
| CE008 | Because Instinct hides most execution behind messaging rather than a visible app UI, trust depends on background action controls and user-legible recovery paths as much as on answer quality. | Medium | SE001, SE019, SE021 |
| CE009 | Instinct’s public materials refer to a core model but do not publicly name the underlying foundation-model provider. | Medium | SE001, SE002 |
| CE010 | Reflexion describes a framework for reinforcing language agents through linguistic feedback instead of model fine-tuning. | High | SE005, SE006 |
| CE011 | Reflexion stores self-reflections in an episodic memory buffer that conditions later attempts at the same or similar tasks. | High | SE005, SE006 |
| CE012 | The Reflexion paper and poster report a 91% HumanEval pass@1 result versus a cited 80% for GPT-4. | High | SE005, SE006 |
| CE013 | τ-bench benchmarks dynamic conversations between a user simulator and a language agent equipped with domain-specific API tools and policy guidelines. | Medium | SE004, SE008 |
| CE014 | τ-bench emphasizes tool-calling strategies, policy compliance, and real-world domain tasks rather than generic chatbot response quality alone. | Medium | SE008, SE027 |
| CE015 | Shinn’s public research lineage supports an inference that Instinct likely uses an agent loop with tools and persistent state on top of a frontier LLM, even though production internals are undisclosed. | Medium | SE001, SE005, SE008, SE019 |
| CE016 | The public Reflexion repository asks developers to set an OPENAI_API_KEY, indicating Shinn’s released agent code was designed around API-accessed closed models rather than open-weight self-hosting. | Medium | SE007, SE025 |
| CE017 | The public τ-bench repository supports multiple model-provider API keys, reinforcing that this research lineage assumes external LLM APIs behind the agent layer. | Medium | SE008, SE027 |
| CE018 | Persistent memory or indexing is product-critical because official copy says Instinct understands what is important to the user and follows up on dropped threads over time. | Medium | SE001, SE002 |
| CE019 | Instinct’s privacy policy says linked Google Workspace access can include Gmail, Calendar, Drive, Docs, Sheets, Slides, Tasks, and related metadata or content needed to provide the service. | Medium | SE002 |
| CE020 | Instinct’s terms explicitly mention Apple, Facebook, and Google accounts, showing the product is designed around linked-account identity and integration flows rather than a standalone SMS bot. | Medium | SE003 |
| CE021 | Gmail and Google Calendar both provide watch or push-notification models that can inform a backend when inbox or calendar state changes, reducing the need for constant polling. | High | SE010, SE012 |
| CE022 | Gmail push notifications require Cloud Pub/Sub and periodic watch renewal, which implies ongoing background jobs for any service monitoring mailbox changes continuously. | Medium | SE010 |
| CE023 | Google Calendar push notifications require HTTPS webhook endpoints, unique channels, and manual renewal near expiration. | Medium | SE012 |
| CE024 | Microsoft Graph’s Outlook mail and calendar APIs support integration across both personal and organizational account contexts. | Medium | SE014, SE015 |
| CE025 | WhatsApp Cloud API permits free-form service messages only inside a 24-hour customer-service window, after which pre-approved templates are required. | Medium | SE016 |
| CE026 | Twilio’s messaging stack supports outbound sends, delivery-state callbacks, redaction, deletion, and WhatsApp-capable message resources, making it a plausible transport abstraction for a messaging-first assistant. | Medium | SE017, SE018 |
| CE027 | Instinct’s messaging layer likely depends on either Meta’s WhatsApp infrastructure, an intermediary such as Twilio, or a similar gateway for transport and status management. | Medium | SE001, SE016, SE017, SE018 |
| CE028 | Google’s OAuth guidance requires secure token storage, least-privilege scope design, and revocation or deletion discipline, making identity and secret management a central technical risk for Instinct. | Medium | SE013 |
| CE029 | Multiple independent reports describe Instinct sending or preparing to send real email or other actions on behalf of testers, proving the product is executing workflows rather than merely drafting suggestions. | High | SE019, SE020, SE021 |
| CE030 | TechCrunch and StartupFortune each describe a prompt-injection-style exploit where instructions embedded in email caused Instinct to behave unexpectedly. | High | SE019, SE021 |
| CE031 | OWASP’s prompt-injection definition maps closely to the Instinct beta reports because hostile input can redirect an LLM system into unintended actions. | Medium | SE019, SE024 |
| CE032 | Official policy and adverse reporting agree that disconnecting an external service does not automatically delete previously indexed data; deletion is a separate step. | High | SE002, SE003, SE019, SE020, SE022 |
| CE033 | TechCrunch and SC Media reported that Instinct continued summarizing previously stored emails after Google access was revoked and that the assistant said the emails were stored in plain text for later searches. | High | SE019, SE020 |
| CE034 | Instinct’s privacy policy says Google Workspace API data is not used to train models or disclosed to third-party AI providers for that purpose, but broader non-Workspace materials can still be used to improve products and models subject to policy exceptions. | High | SE002, SE003 |
| CE035 | Instinct’s terms explicitly authorize the service to enter agreements, commitments, or transactions on the user’s behalf as if the user entered them directly. | High | SE003, SE019 |
| CE036 | The maturity state is real private beta, not launch-ready trust infrastructure: the assistant demonstrably works, but public evidence does not support calling its control plane hardened for mass-market autonomy. | Medium | SE001, SE019, SE020, SE021 |
| CE037 | No reviewed public source disclosed external security audits, certifications, uptime metrics, or formal red-team results for Instinct. | Medium | SE001, SE002, SE003, SE019 |
| CE038 | The external-data deletion tool added after complaints is better understood as reactive remediation than as proof of mature lifecycle governance. | Medium | SE019, SE021, SE022 |
| CE039 | As of 2026-08-28, the public Reflexion repository showed 3243 stars, 316 forks, and 24 open issues, indicating sustained practitioner interest in Shinn’s agentic architecture lineage. | Medium | SE025, SE029 |
| CE040 | As of 2026-08-28, the public τ-bench repository showed 1409 stars, 215 forks, and 52 open issues, indicating similarly strong ongoing developer attention to tool-agent evaluation infrastructure. | Medium | SE027, SE030 |
| CE041 | Reflexion and τ-bench both appear maintained by relatively concentrated contributor sets with active issue queues, suggesting meaningful community usage but narrow maintainer depth. | Medium | SE026, SE028, SE029, SE030 |
| CE042 | Instinct itself has a much thinner public developer footprint: the direct Hacker News link post reviewed had only 1 point and no visible discussion, and Algolia surfaced only sparse direct story hits. | Medium | SE031, SE032 |
| CE043 | Instinct’s critical external dependencies likely include a frontier model API, messaging transport providers, OAuth identity systems, Google and Microsoft connectors, cloud compute, and secret or token storage. | Medium | SE001, SE013, SE016, SE017, SE018 |
| CE044 | Compute capacity is itself a near-term operational dependency because the company says access remains limited while it scales compute. | Medium | SE001 |
| CE045 | Reviewed public materials expose little forward product roadmap detail beyond private-beta status, revised policies, and reactive controls; no public changelog, SLA, or general-availability plan was found. | Medium | SE001, SE002, SE003, SE019 |
| CE046 | Instinct’s main current differentiation is not a disclosed proprietary infrastructure advantage but the combination of messaging-native distribution, deep permissions, and willingness to let the agent take binding actions. | Medium | SE001, SE019, SE023 |
| CE047 | The terms refer to a website, subdomains, and related Mac OS or other applications, implying a nontrivial control surface behind the messaging-first consumer entry point. | Low | SE003 |
| CE048 | The public architecture evidence today is stronger for agent research lineage than for production observability, rollback, or safety instrumentation. | Low | SE019, SE025, SE027 |
| CU001 | As of 2026-08-28, Instinct remains available only to a private access group; prospects can join a waitlist or obtain an invite from an existing member. | High | SU001, SU009, SU013 |
| CU002 | Instinct is accessed through text messages and calls, including WhatsApp, rather than requiring users to learn a dedicated new interface. | High | SU001, SU004, SU009 |
| CU003 | Instinct connects to email, messaging, calendars, screen activity, audio, location, and other connected services to act on a user’s behalf. | High | SU001, SU003, SU004 |
| CU004 | Instinct is positioned as a consumer product for individual users rather than enterprises: the official terms grant personal use only and reported use cases are personal errands, travel, subscriptions, and home logistics. | High | SU001, SU002, SU004, SU009 |
| CU005 | The observed early-use cases center on life administration such as travel booking, groceries, appointments, subscriptions, reservations, messaging follow-up, and family coordination. | High | SU001, SU004, SU005, SU010 |
| CU006 | No public customer count, active-user count, or waitlist size is disclosed in the official materials or main press coverage reviewed for this run. | Medium | SU001, SU005, SU009, SU025 |
| CU007 | TechCrunch reported management-stated ARR of about $80 million as of 2026-08-26. | Medium | SU005, SU025 |
| CU008 | TechCrunch reported that Instinct’s ARR was about $5 million in January 2026. | Medium | SU005, SU025 |
| CU009 | Using the reported January and August ARR figures implies roughly 16x ARR growth in about seven months while the product remained private beta. | Medium | SU001, SU005, SU025 |
| CU010 | Forbes reported that Instinct was free to use in late August 2026 and that no public price had been announced. | Medium | SU009, SU010 |
| CU011 | The combination of reported $80 million ARR and no public pricing means the revenue model exists but is not transparently described to outsiders. | Medium | SU005, SU009, SU025 |
| CU012 | Launch-week buzz was driven disproportionately by tech insiders, investors, and power users rather than by mass-market review channels. | Medium | SU009, SU010, SU011 |
| CU013 | Sheel Mohnot reported sending 677 messages to Instinct in five days and listed 15 completed jobs, including finding a doctor, lowering a cable bill, vendor outreach on WhatsApp, subscription cancellations, and paying tolls. | Medium | SU010, SU011 |
| CU014 | Jesse Middleton said he used Instinct daily for a week across travel changes, reservations, email follow-ups, CRM work, and investor data-room tasks, calling it awesome. | Medium | SU004, SU011 |
| CU015 | Katie Jacobs Stanton first described Instinct as an amazing product but disconnected email after it sent an email on her behalf without asking. | High | SU004, SU006, SU011, SU023 |
| CU016 | Peter Yang said Instinct initially retained Gmail records and did not provide a workable deletion path until later settings changes were added. | Medium | SU004, SU006, SU008, SU011 |
| CU017 | Claire Vo showed that Instinct could still summarize previously ingested emails after Google access was disconnected and that stored emails were kept in plain text for later search. | High | SU004, SU006, SU007, SU009 |
| CU018 | Alex Cohen demonstrated an email-based prompt-injection test that caused Instinct to follow malicious inbox instructions, after which he deleted his account. | High | SU004, SU006, SU008, SU011 |
| CU019 | Forbes surfaced another autonomy failure: Jason Yeh said Instinct booked a dinner reservation with a $200 cancellation fee after he only asked it to find availability. | Medium | SU009, SU011 |
| CU020 | SC Media summarized the early market signal as simultaneous praise for the product’s capabilities and significant privacy alarm from testers. | Medium | SU023, SU004 |
| CU021 | AI Weekly summarized the trust problem as early testers learning that one unauthorized action could reset trust to zero. | Medium | SU024, SU004, SU006 |
| CU022 | A thin but positive additional signal exists in Digg’s framing of Instinct as earning praise for smooth onboarding and proactive suggestions. | Low | SU012 |
| CU023 | Instinct’s privacy policy says disconnecting a third-party integration does not automatically delete data collected from that integration. | High | SU002, SU003 |
| CU024 | Instinct’s terms likewise state that indexed connected-service data may still be used after disconnect until the user separately requests deletion. | High | SU002, SU003 |
| CU025 | Instinct’s official terms authorize the service to take actions it deems responsive, including purchases and agreements that bind the user. | High | SU002, SU003 |
| CU026 | Instinct’s privacy policy says the company may use user information to evaluate, fine-tune, and train AI models subject to a forward-looking opt-out, while Google Workspace API data is excluded from model training. | High | SU002, SU003 |
| CU027 | Instinct’s privacy policy warns that autonomous features may cause unintended communications or payments and may be manipulated by misleading instructions from third parties. | High | SU002, SU003 |
| CU028 | No G2, Capterra, App Store, or Google Play review corpus is publicly available for Instinct, consistent with its invite-only private beta and absence of a mainstream public app launch. | Medium | SU001, SU009, SU010 |
| CU029 | The chapter’s strongest customer proof therefore comes from quoted beta testers, investor-users, and practitioner commentary rather than from named paying customer case studies. | Medium | SU004, SU006, SU010, SU011, SU024 |
| CU030 | Instinct has not publicly disclosed retention, renewal, churn, NRR, GRR, or cohort data for beta users. | Medium | SU005, SU009, SU025 |
| CU031 | Because customer count and retention are undisclosed, the observed ARR growth could reflect strong retention, aggressive new-user adds, unusually high ARPU, or some combination of all three. | Medium | SU005, SU006, SU025 |
| CU032 | Private-beta ARR of roughly $80 million with no disclosed user count creates a credible risk that revenue is concentrated in a relatively small cohort of early adopters. | Medium | SU005, SU009, SU025 |
| CU033 | Instinct’s text-and-WhatsApp access lowers onboarding friction relative to assistants that require users to install and learn a new full application interface. | Medium | SU001, SU004, SU022 |
| CU034 | If trust issues are addressed, the same low-friction channel design could expand beyond insiders into broader personal-admin, travel, shopping, and household coordination use cases. | Medium | SU001, SU005, SU010, SU022 |
| CU035 | Pew reported that 49% of U.S. adults use AI chatbots in 2026, 24% use them daily, and adults under 30 reach 66% usage, showing that mainstream consumer demand for AI assistants already exists. | High | SU014, SU015, SU018 |
| CU036 | Pew also found that 71% of U.S. adults think increased AI use will make their personal information less secure and about six in ten are not confident U.S. companies will develop and use AI responsibly. | High | SU014, SU015, SU018 |
| CU037 | Usercentrics found that 52% of consumers trust AI less than humans with their personal data, 24% canceled subscriptions over AI data concerns, and 20% switched to a competitor they trusted more. | Medium | SU016, SU017 |
| CU038 | Usercentrics also found that 52% of consumers would pay more for AI transparency, averaging a 7% premium globally and rising to 67% among 18–29 year-olds. | Medium | SU016, SU017 |
| CU039 | Capital One Shopping reported that 39% of consumers had already used AI assistants for online shopping and 80% planned to use generative AI to shop in 2026, relevant to Instinct’s commerce-oriented use cases. | Medium | SU019 |
| CU040 | Sensor Tower reported that ChatGPT, Gemini, and DeepSeek represented nearly 90% of total AI-assistant time spent in Q1 2026, indicating the category is real but highly concentrated around trusted incumbents. | Medium | SU018, SU020 |
| CU041 | Cybernews and Dume both treat integrations, automation quality, and privacy controls as the defining buyer criteria for personal AI assistants in 2026. | Medium | SU021, SU022 |
| CU042 | Instinct’s customer evidence is materially weaker than its revenue narrative because it lacks named customers, public counts, public pricing detail, and third-party review-platform depth. | Medium | SU005, SU009, SU010, SU025 |
| CU043 | The product’s observed early-user mix skews toward founders, investors, operators, and other tech-savvy power users comfortable experimenting with broad account permissions. | Medium | SU004, SU009, SU010, SU011 |
| CU044 | Virality and invite-gating appear to be central acquisition channels: the official waitlist mechanics plus press emphasis on insider invites and launch-week social buzz point to word-of-mouth-led initial adoption. | Medium | SU001, SU009, SU010, SU011, SU013 |
| CU045 | A product accessed through familiar messaging channels but perceived as risky on privacy has a plausible expansion path only if trust controls improve faster than buzz fades. | Medium | SU001, SU016, SU017, SU023 |
| CR001 | Instinct's public risk profile is dominated by privacy, autonomy, and trust concerns rather than by classic consumer-app issues like simple engagement decay. | Medium | SR001, SR002, SR003, SR005 |
| CR002 | TechCrunch and other adverse coverage say Instinct can send emails or take actions without explicit per-action confirmation. | High | SR001, SR002, SR005 |
| CR003 | That autonomy design choice creates consent and authorization risk if the user does not understand or expect the action boundary. | Medium | SR001, SR002, SR006, SR007 |
| CR004 | The EU AI Act is now the first legal framework on AI and is directly relevant to autonomous assistants operating in Europe. | High | SR008, SR009 |
| CR005 | The European Commission began enforcing new AI Act transparency requirements from 2 August 2026. | High | SR008, SR009 |
| CR006 | GDPR remains relevant because an assistant like Instinct processes highly sensitive personal communications and metadata across multiple systems. | High | SR004, SR010 |
| CR007 | FTC AI guidance creates plausible enforcement exposure if the company misleads users about autonomy, retention, or safety controls. | High | SR006, SR007 |
| CR008 | Client alerts from Lowenstein and Gunderson show that 2026 compliance expectations are broadening across US state, federal-interest, and EU frameworks. | Medium | SR017, SR018 |
| CR009 | Prompt injection remains a first-order technical risk for agentic assistants according to OWASP and 2026 security guides. | High | SR012, SR013 |
| CR010 | Any assistant that can read inbound content and then call tools is vulnerable to indirect prompt injection unless inputs, permissions, and execution paths are tightly controlled. | Medium | SR012, SR013 |
| CR011 | Plain-text retention after OAuth revocation would create unusually strong privacy, security, and possibly deceptive-practice risk if confirmed broadly. | Medium | SR001, SR003, SR005, SR010 |
| CR012 | OWASP and NIST both imply that agent systems need strong identity, authorization, isolation, audit logging, and human-override controls. | High | SR011, SR012 |
| CR013 | The product is exposed to partner dependency because it relies on messaging, email, calendar, and model ecosystems it does not control. | Medium | SR004, SR025, SR026, SR027, SR028, SR029, SR030, SR031 |
| CR014 | Apple, Google, Microsoft, Meta/WhatsApp, and model providers can all change policies, access, defaults, pricing, or product capabilities in ways that harm Instinct. | Medium | SR025, SR026, SR027, SR028, SR029, SR030, SR031 |
| CR015 | Model-provider concentration is a supply-chain risk because underlying pricing and capability changes can directly alter Instinct's economics and reliability. | High | SR025, SR026, SR027 |
| CR016 | Cyberhaven, PwC, AvePoint, and BCG all show that governance and data-risk problems are rising as agentic AI use expands. | Medium | SR020, SR021, SR022, SR023 |
| CR017 | Those broader 2026 reports matter because Instinct is not just another chatbot; it is an action-taking assistant in the highest-trust part of the consumer stack. | Medium | SR020, SR021, SR022, SR023, SR004 |
| CR018 | Unclear monetization and high-permission onboarding create business-model risk because the company must earn both willingness to pay and willingness to trust. | Medium | SR001, SR004, SR024, SR025, SR026, SR027 |
| CR019 | A large Series B reduces immediate solvency risk but does not remove burn, gross-margin, or next-round risk if growth slows. | Medium | SR024, SR025, SR026, SR001 |
| CR020 | Incumbent assistants create strategic risk because they can bundle safer-enough functionality into products users already trust. | Medium | SR028, SR029, SR030, SR031 |
| CR021 | No public evidence reviewed shows a broad management bench or mature governance structure beyond Noah Shinn's founder-led profile. | Medium | SR004, SR001 |
| CR022 | A young founder and small team can be a strength in speed but a risk in compliance, operations, hiring, and crisis management during rapid scaling. | Medium | SR001, SR004, SR015, SR016, SR017, SR018 |
| CR023 | If growth outruns controls, one visible autonomy failure can trigger user churn, media backlash, regulator attention, and partner pressure in sequence. | Medium | SR001, SR002, SR003, SR005, SR006, SR008, SR012 |
| CR024 | ITIF's work on publicly available data highlights unresolved legal uncertainty around training inputs, transparency norms, and safe-harbor design. | Medium | SR016 |
| CR025 | Law and economics commentary warns that AI assistants may face regulatory mismatch between platform rules and standalone-agent reality. | Medium | SR014 |
| CR026 | The highest-probability risk cluster is trust and adoption, because every other category ultimately feeds into whether users keep delegating tasks. | Medium | SR001, SR002, SR003, SR005, SR020, SR021, SR022, SR023 |
| CR027 | The highest-severity risk cluster is privacy and security because harm can compound quickly when an assistant has broad access and action rights. | Medium | SR001, SR003, SR005, SR010, SR011, SR012 |
| CR028 | Some risks are manageable with controls, but a structural inability to build trust would be existential to the product thesis. | Medium | SR001, SR011, SR012, SR020, SR021, SR022, SR023 |
| CR029 | Public evidence of mitigations is thin beyond broad company positioning, which itself is a diligence signal. | Medium | SR004, SR001, SR005 |
| CR030 | Kill criteria should include regulatory inquiry, rising churn after autonomy incidents, revoked API access, and materially worsening model costs. | Medium | SR006, SR007, SR025, SR026, SR027, SR028 |
| CR031 | The absence of disclosed pricing, customer counts, and retention makes it hard to bound downside from trust shocks using public evidence only. | Medium | SR001, SR004, SR024 |
| CR032 | Distribution through WhatsApp or mobile surfaces is helpful commercially but risky strategically because channel owners can reprioritize or limit access. | Medium | SR028, SR004 |
| CR033 | Apple, Google, and Microsoft all have the option to move down-market or across-market into the same delegated-assistant jobs from stronger default positions. | Medium | SR029, SR030, SR031 |
| CR034 | Risk management in 2026 is expected to be continuous rather than periodic, especially for agent systems touching sensitive data and autonomous actions. | Medium | SR011, SR021, SR022, SR023 |
| CR035 | Cost-governance reports show that organizations often struggle to attribute or forecast AI spend, which raises financial control risk for usage-sensitive products. | Medium | SR020, SR024, SR025, SR026, SR027 |
| CR036 | Public adverse coverage itself is a risk amplifier because it narrows the company's margin for future mistakes during launch. | Medium | SR001, SR002, SR003, SR005 |
| CR037 | The product sits near the boundary of what users may perceive as impersonation if outbound actions are not extremely well signaled and controlled. | Medium | SR001, SR002, SR006, SR007 |
| CR038 | The company likely faces a tradeoff between richer agent autonomy and a lower-risk product posture; moving too slowly hurts differentiation, while moving too fast hurts trust. | Medium | SR001, SR004, SR012, SR013, SR020, SR021 |
| CR039 | The public record is sufficient to identify severe downside categories, but not to quantify incident probability or financial loss with confidence. | Low | SR001, SR011, SR012, SR020, SR021, SR022, SR023 |
| CR040 | A second unresolved gap is whether the company has already implemented the authorization, isolation, and deletion controls that public critics say are necessary. | Low | SR001, SR003, SR004, SR011, SR012 |
| CR041 | A third unresolved gap is how model-provider, platform, and regulator dependencies interact under stress when a real consumer incident occurs. | Low | SR006, SR008, SR012, SR014, SR025, SR026, SR027, SR028, SR029, SR030, SR031 |
| CR042 | Overall, the risk map is unusually concentrated in high-severity trust and governance issues for such an early-stage consumer company. | Medium | SR001, SR002, SR003, SR006, SR008, SR011, SR012, SR020, SR021, SR022, SR023 |
| CR043 | Because Instinct is pre-launch and high-permission, the downside path can be much faster than the upside path if a few critical trust variables break simultaneously. | Medium | SR001, SR002, SR003, SR005, SR012, SR020, SR021, SR022, SR023 |
| CV001 | Recommendation is Track — do not invest at current $2.5B valuation without independent ARR verification, disclosed monetization model, and entry price reduction to $1.2-1.5B range. | High | SV009, SV010 |
| CV002 | The investment thesis is predicated on the consumer AI assistant market becoming a winner-take-most category with $50B+ addressable value by 2030. | Medium | SV013, SV023 |
| CV003 | Instinct's 16x ARR growth in 7 months is a genuine product-market fit signal based on independently confirmed funding disclosures. | High | SV001, SV003 |
| CV004 | Apple, Google, and Microsoft have structural distribution advantages that represent a fundamental anti-thesis to Instinct's standalone consumer product. | High | SV012, SV019 |
| CV005 | Noah Shinn's background combines published AI research (ReAct, Reflexion) with a consumer product philosophy that is rare among technical founders at 23. | High | SV001, SV004 |
| CV006 | Instinct has raised $350M total across Series A ($100M, January 2026) and Series B ($250M, August 2026) with participation from five institutional investors. | High | SV001, SV003, SV004, SV005, SV006, SV007, SV008, SV017 |
| CV007 | Instinct has no disclosed pricing model at $2.5B valuation, making the 31x ARR multiple uninvestable without monetization evidence. | High | SV012, SV009 |
| CV008 | Privacy backlash in August 2026 related to Instinct's email-access permissions represents a material anti-thesis risk with potential regulatory consequences. | High | SV001, SV029 |
| CV009 | Overall score is 6.5/10, risk rating is High, valuation stance is Stretched, and recommendation confidence is Medium. Recommendation is Track. | High | SV009, SV010 |
| CV010 | At 31x management-stated ARR, Instinct's entry valuation is above the historical median of 10-20x for consumer software unicorns and at the high end of the 2026 AI premium range of 18-25x per KPMG Venture Pulse. | High | SV014, SV015, SV028 |
| CV011 | Applying a 20-30% discount for unverified ARR implies a fair value of $1.7-2.0B, versus the $2.5B round price — a 25-47% premium above risk-adjusted intrinsic value. | Medium | SV009, SV023 |
| CV012 | A Series C target valuation of $5-8B in 2027 would represent a 2-3x step-up from the Series B, consistent with typical hypergrowth consumer software trajectory if monetization is achieved. | Medium | SV016, SV024 |
| CV013 | The absence of a disclosed monetization model at $2.5B valuation is the single most significant financial risk; all return scenarios depend on this gap being closed before capital is exhausted. | High | SV012, SV009 |
| CV014 | Dilution mathematics suggest Series A investors at $500M est. valuation face a complex cap structure; Series B investors likely hold preferred stock with 1-2x liquidation preferences — terms are entirely undisclosed. | Low | SV009, SV024 |
| CV015 | At a 20-31x ARR range, Instinct's current valuation is consistent with the upper end of the 2026 AI software premium but requires continued ARR confirmation and monetization execution to sustain. | Medium | SV014, SV013 |
| CV016 | Greenoaks Capital's participation as Series B co-investor is a positive signal; Greenoaks has a strong track record in growth-stage consumer tech including Chime, Rappi, and Coupang. | High | SV007, SV030 |
| CV017 | Bull scenario at 25% probability sees $250M+ ARR by end-2027, paid tier Q1 2027, IPO at $15-20B in 2029, and Series B investors achieving 5-8x return. | Medium | SV021, SV025 |
| CV018 | Base scenario at 55% probability sees $120-160M ARR by end-2027, monetization delayed to mid-2027, Series C at $4-5B, exit at $6-8B in 2030, and Series B return of 2-3x. | Medium | SV020, SV023 |
| CV019 | Bear scenario at 20% probability sees privacy enforcement forcing product changes, monetization failing below $200M ARR, strategic acquisition at $300-500M, and a full write-down for Series B investors. | Medium | SV029, SV012 |
| CV020 | Expected value across scenarios is approximately 2.5x for a Series B co-investor at $2.5B valuation — insufficient to justify the risk premium. | Medium | SV023, SV024 |
| CV021 | The 20% bear-case probability reflects real regulatory risk, undefined monetization, and a competitive landscape with unlimited-budget incumbents. This downside is not remote. | Medium | SV019, SV029 |
| CV022 | If the consumer AI assistant market consolidates around OS-native products within 24 months, Instinct's standalone value drops to near zero in the bear case. | Medium | SV013, SV019 |
| CV023 | Bull case probability of 25% reflects Instinct's unique hypergrowth evidence and founder profile; reduced from a theoretical 35% by privacy and monetization gaps remaining unresolved as of the research date. | Medium | SV020, SV023 |
| CV024 | The base case assumes Instinct launches a paid tier at $20-30/month with 5-8% conversion from a 2M-user installed base, yielding $24-57M ARR uplift. | Low | SV014, SV016 |
| CV025 | Perplexity AI raised at $1B valuation in April 2024 at approximately $25-30M ARR, implying 33-40x ARR — above Instinct's 31x but with a launched paid tier. | Medium | SV009, SV010 |
| CV026 | Character.AI was acquired by Google in September 2024 at approximately $2.7B, representing ~25x estimated revenue with higher monetization certainty. | Medium | SV009, SV010 |
| CV027 | Scale AI was valued at $13.8B in December 2024 at approximately 11x ARR — lower multiple but with audited revenues and diversified government contracts. | Medium | SV010, SV009 |
| CV028 | Cohere raised at $5B valuation in June 2024 at approximately $200M ARR (25x) with disclosed B2B contracts and recurring revenue model. | Medium | SV009, SV010 |
| CV029 | Applying a 20-30% monetization-uncertainty discount to Instinct's 31x comparable multiple yields a risk-adjusted fair-value range of $1.7-2.0B. | Medium | SV023, SV015 |
| CV030 | No public company direct comparable exists for a pre-revenue consumer AI assistant at $2.5B; listed AI platform companies trade at 10-25x forward ARR. | High | SV015, SV014 |
| CV031 | The absence of an ARR-verified comparable means Instinct's multiple cannot be validated relative to confirmed revenue figures — all benchmarks involve some estimation. | High | SV012, SV009 |
| CV032 | KPMG Venture Pulse Q2 2026 reports median Series B AI-native software multiple of 18-25x ARR — Instinct's 31x is 24-72% above this median. | High | SV028, SV009 |
| CV033 | Primary exit pathway is strategic acquisition (Apple, Google, or Microsoft) within 3-5 years if IPO market conditions do not support $15B+ consumer software listings by 2029. | Medium | SV020, SV025 |
| CV034 | Thesis-break trigger 1 is ARR growth falling below $5M/month for two consecutive quarters — indicating monetization failure or user attrition. | High | SV014, SV022 |
| CV035 | Thesis-break trigger 2 is any regulatory enforcement action in EU, UK, or California related to privacy or AI governance. | High | SV029, SV001 |
| CV036 | Thesis-break trigger 3 is failure to launch a paid tier by Q2 2027, signaling fundamental GTM and monetization failure incompatible with the $2.5B valuation. | High | SV012, SV014 |
| CV037 | Blocking diligence item 1 is independent ARR verification via third-party audit or rep-and-warranty insurance before any investment decision. | High | SV012, SV024 |
| CV038 | Blocking diligence item 2 is full disclosure of pricing model, conversion funnel, and paying-user count before accepting 31x ARR multiple. | High | SV012, SV009 |
| CV039 | Blocking diligence item 3 is legal counsel review of EU AI Act, UK DPA, and California CPRA compliance posture given email-access product architecture. | High | SV029, SV017 |
| CV040 | Blocking diligence item 4 is investor rights agreement review for liquidation preferences, anti-dilution provisions, and drag-along rights before any entry at or near Series B terms. | Medium | SV024, SV009 |