Instinct
估值 $2.5B 的出圈 AI 个人助理:ARR 高速增长,但隐私与安全红旗仍未解除
Instinct 是一家估值 $2.5B 的消费级 AI 助手,ARR 增长势头极强,但隐私、安全和治理风险很重;以现有证据质量看,估值偏高。
封面要素
公司概况
Instinct 由 Spear Street Technology Inc.(2025 年在加利福尼亚州注册)运营,是一款面向消费者的 AI 个人助理, 入口只有 SMS 和 WhatsApp。产品连接用户的电子邮件、日历、消息应用、音频、位置与屏幕,并在无需逐项确认的情况下, 自主执行预约、邮件管理、排期、购物等任务。创始人 Noah Shinn 23 岁,曾任 Sierra 研究科学家,也是 Reflexion (NeurIPS 2023)第一作者;Instinct 在 2026 年初出圈,ARR 从 2026 年 1 月约 $5 million 增至 2026 年 8 月约 $80 million。公司完成 $250 million 融资,Series B 轮由 Index Ventures 和 Benchmark 共同领投,投后估值 $2.5 billion。产品仍处私测阶段,用户热情很高,但围绕隐私、安全和数据治理的严肃负面关注也很集中。
- 成立时间
- 2025-01-01
- 创始人
- Noah Shinn
- 创立地点
- San Francisco, CA
- 总部
- San Francisco, CA
- 产品
- 一款通过 SMS 和 WhatsApp 交付的消费级 AI 个人助理。无需下载 app。通过 OAuth 连接电子邮件(Gmail、Outlook、 Apple Mail)、日历和消息应用;访问设备音频、位置和屏幕。可自主执行任务:预约、管理邮件、安排旅行、购物, 包括代表用户达成有法律约束力的交易。
- 客户
- 截至 2026 年 8 月,面向追求自主任务管理的技术敏感型消费者,私测阶段仅限邀请。
- 商业模式
- 未公开披露。收入模式可能是订阅或按任务计费;私测队列贡献 $80M ARR,说明可能存在付费访问或点数定价,但条款尚未公开宣布。
- 阶段
- Series B
- 融资情况
- $250 million Series B 轮(2026 年 8 月 26 日)由 Index Ventures 和 Benchmark 共同领投,投后估值 $2.5 billion;$100 million Series A 轮(2026 年 1 月)由 Kleiner Perkins 领投;累计融资 $350 million。
执行摘要
主要优势
- ARR 增速罕见:8 个月约 16× 增长($5M → $80M ARR),说明早期用户里的产品市场匹配度很强。
- 创始人技术差异化明显(Reflexion NeurIPS 2023),智能体记忆架构有防御性,通用模型不容易直接复刻。
- 一线投资人组合(Index Ventures、Benchmark、Kleiner Perkins)给出强背书,也带来治理支持和后续融资通道。
- SMS / WhatsApp 分发绕开 app store 摩擦,借现有消息应用装机基础推动病毒式增长。
- 在完全自主的消费级 AI 智能体品类里,Instinct 已先于大科技公司跑出有意义规模,占住先发位置。
主要风险
- 永久且不可撤销的数据许可,以及 OAuth 撤销后仍以明文留存邮件,让 Instinct 暴露在 GDPR、CCPA 和 FTC 执法风险下。
- 已被验证的提示注入漏洞允许恶意邮件劫持 Instinct 的自主动作,安全与责任风险很高。
- $2.5B 估值(约 31× ARR)对一款尚未正式发布、未披露单位经济的消费产品偏贵;隐私反弹可能迅速压缩倍数。
- 23 岁首次担任 CEO,却已进入超常规模;在员工快速扩张和产品发布期,执行与治理风险上升。
- Google、Apple、OpenAI 和 Microsoft 拥有原生平台集成和深度消费者分发,带来直接竞争风险。
未决问题
- 定价模型和单位经济尚未公开;$80M ARR 口径无法核验。
- 员工数、烧钱速度和盈利路径完全不透明。
- 监管机构(FTC、EU AI Act)会如何回应自主绑定交易能力,仍不清楚。
- 股权结构表、稀释历史和老股交易活动均不可得。
- 企业转向潜力和 B2B 路线图(如有)尚未公开释放信号。
目录
01公司概况
1.1 身份、产品与运营模式
Instinct 是一款 AI 个人助理,完全通过短信和电话运转——用户通过 SMS 或 WhatsApp 互动,让它预约、 管理邮件、整理日历、安排旅行、处理购物、退订服务,并在已连接账户和设备之间代用户自主行动。公司的法律实体 Spear Street Technology Inc. 于 2025 年在加利福尼亚州注册。产品品牌为 Instinct,官网是 instinct.co。 运营模式权限很深:Instinct 连接用户的电子邮件账户、消息平台、日历、设备音频、位置数据和屏幕截图。集成完成后, 助理无需逐项确认即可自主执行任务。服务条款授予 Instinct 一项“永久且不可撤销”的许可,可访问、存储、使用并修改 所有用户材料,包括用于 AI 训练——这一条款在 2026 年 8 月引发持续公开批评。早期反弹后,公司增加了数据删除工具, 但宽泛条款结构保留了下来。 截至 2026 年 8 月,Instinct 仍处私测阶段——访问只靠邀请或候补名单。公司尚未公开定价、员工数或商业化上线日期。 即便尚未广泛开放,产品已拿到 $350 million 风险资本,年经常性收入(ARR)约 $80 million。Instinct 总部位于 加利福尼亚州 San Francisco;具体办公地址未公开披露。公司称团队规模很小,成员主要来自 MIT 和企业 AI 公司 Sierra 的前沿 AI 研究背景。[CO001, CO002, CO004, CO014, CO015, CO016]
| 指标 | 数值 / 状态 | 日期 / 期间 | 可信度 | 缺口 / 备注 |
|---|---|---|---|---|
| 法律实体 | Spear Street Technology Inc. | 历史 | 高 | 加州注册;未公开确认备案编号 |
| 品牌名称 | Instinct | 当前 | 高 | 官方网站 instinct.co;多篇报道确认 |
| 总部 | 美国加州 San Francisco | 当前 | 高 | TechCrunch 和 TechFundingNews 报道;未披露街道地址 |
| 成立时间 | 2025 | 历史 | 中 | 年份已确认;具体月份未公开披露 |
| 产品状态 | 封闭 beta(仅限邀请) | 2026-08-28 | 高 | TechCrunch 融资和隐私文章确认 |
| 最新估值 | $2.5B 投后 | 2026-08-26 | 高 | TechCrunch、TechFundingNews、Index Ventures/Benchmark 新闻稿共同确认 |
| 累计融资 | $350M | 2026-08-26 | 高 | TechCrunch 一手来源;$100M 种子轮 + Series A + $250M Series B |
| Series B 金额 | $250M | 2026-08-26 | 高 | TechCrunch;Index Ventures 和 Benchmark 共同领投 |
| 年经常性收入(ARR) | ~$80M | 2026-08 | 中 | 管理层通过 TechCrunch 声称;未经独立审计 |
| 创立阶段 ARR | ~$5M | 2026-01 | 中 | 管理层声称;代表 2026 年 1 月左右 ARR |
| 员工数 | 未披露(估计 <50) | 2026-08-28 | 低 | 外界称其为“小团队”;没有公开人数 |
| 客户数 | 未披露 | 2026-08-28 | 低 | 封闭 beta;未发布候补名单指标 |
| 创始人 | Noah Shinn(23 岁,CEO) | 2026-08-28 | 高 | TechCrunch、TechFundingNews 和多个来源均确认 |
收入和员工数来自管理层提供或估计;没有独立审计。估值和融资数字由多个高声誉来源确认。null 条目代表截至运行日期已确认的信息缺口。
[CO001, CO002, CO005, CO006, CO007, CO016]展示 Instinct 的身份、产品入口、底层集成、资本结构和关键依赖如何连接成当前运营模型。
[CO001, CO004, CO006, CO007, CO014, CO017]1.2 创始人背景、技术脉络与团队构成
Noah Shinn 是 Instinct 唯一公开确认的创始人,也是 Spear Street Technology 的 CEO。2026 年 8 月 Series B 公告时,他 23 岁。Shinn 于 2023 年从 Northeastern University 退学,此前也在 MIT 做过机器学习和编程语言研究。 之后他加入企业 AI 智能体公司 Sierra,是最早一批员工之一,职位为研究科学家。 学术上,Shinn 最有辨识度的标签是 Reflexion 论文第一作者,该论文发表于 NeurIPS 2023。Reflexion 框架提出一种方法: 语言智能体在任务失败后进行“口头反思”,把经验存入情景记忆,并在不进行模型微调的情况下改善后续尝试。该方法在 HumanEval 编码基准上取得 91% pass@1,明显高于当时 GPT-4 报告的 80%。共同作者包括 Federico Cassano、 Ashwin Gopinath、Karthik Narasimhan 和 Shunyu Yao。Shinn 还共同开发了 τ-bench,用来评估智能体处理真实用户互动、 工具调用和业务规则遵循的能力。以 Shinn 的年龄,这条从学术智能体研究、Sierra 企业部署到消费级产品的技术脉络, 是一项差异化资历。 其他团队成员没有公开披露。公司材料称其为一支“小型 San Francisco 团队”,背景来自 MIT 和 Sierra,但本次查看的公开报道 没有点名任何其他成员。董事会构成、投资人观察员和治理结构完全未披露。领导力高度集中,带来显著关键人依赖:公司的技术可信度、 投资人关系和产品愿景,在公开叙事里都系于一人,且没有清晰继任安排。[CO007, CO008, CO009, CO010, CO011, CO012]
| 人物 | 职务 | 有来源支持的背景 | 创始人-市场契合或职能备注 | 关键人依赖 / 尽调备注 |
|---|---|---|---|---|
| Noah Shinn | 创始人兼 CEO | Reflexion(NeurIPS 2023)主要作者;Sierra 研究科学家;MIT AI 研究;2023 年从 Northeastern 退学 | 深厚 AI 智能体研究背景,直接适用于自主助理产品 | 极高关键人依赖;唯一公开识别的创始人;未披露具名高管团队 |
| Sierra(前雇主) | N/A — 创始人背景语境 | 企业 AI 智能体公司;Shinn 是最早期员工之一兼研究科学家 | 在转向消费者产品前,Sierra 给了 Shinn 企业级智能体部署经验 | 间接背景;不是现任员工 |
| 未具名团队成员 | 多种职能(工程、产品、运营) | 公开描述称,这是一个来自 MIT 和 Sierra 背景的小型 SF 团队;未披露姓名 | 团队质量可由研究履历推断,但个人层面未经验证 | 没有个人问责;继任计划完全不透明 |
表仅限公开确认或有文件支持的个人。截至运行日期,董事会组成、观察员和治理结构完全未披露。
[CO007, CO008, CO009, CO010, CO011, CO023]截至 2026 年 8 月 Instinct 的核心 KPI:估值、累计融资、ARR、ARR 增长、公司年龄和投资者层级。
ARR 和增长为管理层提供的数据;员工数根据其被描述为小团队而估算。
[CO005, CO006, CO008, CO016, CO039, CO041]1.3 融资历史、估值轨迹与投资人基础
即便按 2026 年 AI 初创公司标准,Instinct 的融资速度也异常快。从 2026 年初约 $50 million 的种子阶段估值出发, 公司先达到 $500 million Series A 估值(由 Kleiner Perkins 的 Mamoon Hamid 领投),约六个月后又达到 $2.5 billion Series B 投后估值。2026 年 8 月 26 日 Series B 融资 $250 million,由 Index Ventures 和 Benchmark 共同领投,累计融资增至 $350 million。早期支持者包括 Conviction Partners(Sarah Guo)、Greenoaks 和未披露的种子轮 参与方。未有债务工具、老股交易或授信额度公开披露。 投资人层级值得注意。Index Ventures 和 Benchmark 是全球最挑剔的消费科技投资机构之一;Index 早期投过 Dropbox、Stripe、 Robinhood 等公司,Benchmark 则领投过 Twitter、Snap、Uber 和 Discord。领投 Series A 的 Kleiner Perkins 同样支持过 标志性科技公司。对于一家员工数未披露、定价未公开、产品仍在私测的非上市公司,这样的投资人阵容并不寻常,也反映出当前 消费级 AI 智能体交易流的竞争强度。 值得注意的是,$2.5 billion 估值对应约 $80 million ARR,隐含收入倍数约 31× ARR;这一溢价与 2026 年增速最高的 AI 软件公司相符,但远高于 SaaS 中位数倍数。该溢价已经计入显著的未来增长和成功变现,二者尚未以公开可见方式得到证明。 审计财务报表、单位经济模型或烧钱速度数据均未公开。[CO003, CO004, CO005, CO006, CO017, CO018]
| 利益相关方 | 角色 | 经济 / 战略重要性 | 公开支持证据 | 尽调要求 |
|---|---|---|---|---|
| Index Ventures | Series B 共同领投方 | $125M+ 的 Series B;预计有董事席位但未披露 | TechCrunch 和多个来源确认共同领投;Index 以 Dropbox、Stripe、Robinhood 闻名 | 确切持股、董事会权利、清算优先权和反稀释条款 |
| Benchmark | Series B 共同领投方 | $125M+ 的 Series B;预计有董事席位但未披露 | TechCrunch 和多个来源确认共同领投;Benchmark 以 Twitter、Snap、Uber 闻名 | 确切持股、董事会权利,以及相对于 Series A 持有人的优先股堆叠 |
| Kleiner Perkins(Mamoon Hamid) | Series A 领投方 | 以约 $500M 估值领投 ~$100M Series A;持有有意义的摊薄后股份 | TechFundingNews 报道 Mamoon Hamid 代表 Kleiner Perkins 领投 Series A | A 轮具体经济条款、B 轮后当前持股稀释、董事席位状态 |
| Conviction Partners(Sarah Guo) | 早期 / 种子投资人 | 参与种子轮;持股相对较小,但在 AI 生态中信号强 | TechFundingNews 引述 Sarah Guo(Conviction)祝贺创始人融资 | 确认种子轮金额,以及 Conviction 是否持有任何董事会观察员权利 |
| Greenoaks Capital | Series A 参与方 | 成长阶段跨界投资人;若按比例投资,潜在持仓较大 | TechFundingNews 将 Greenoaks 列为早期支持者 | 投资金额、是否有任何老股购买,以及治理权利 |
| Noah Shinn(创始人) | 创始人兼控股股东(推定) | B 轮前可能为多数持有人;B 轮后稀释未知 | 所有来源均将其列为唯一创始人;未披露股权结构表 | 当前持股比例、投票控制权和强制随售权 |
| 未知种子投资人 | 种子轮参与方 | 早期验证;细节未披露 | 报道称该轮包含种子资本和 Series A | 披露完整股权结构表,以及种子轮 SAFE 或可转债条款 |
经济条款根据交易结构惯例推断。未公开披露股权结构表、董事会组成或治理文件。
[CO004, CO005, CO006, CO020, CO021, CO022]1.4 里程碑、负面事件与记录年表
Instinct 的公开里程碑只覆盖约 8 个月已知运营历史。Spear Street Technology 于 2025 年成立并开展早期产品开发, 这是起点。公司首次进入公众视野是在 2026 年初,当时进行初始 beta 测试和种子轮,随后据报道由 Kleiner Perkins 领投 Series A,估值约 $500 million。到 2026 年中,公司 ARR 快速增长;在两天后的 Series B 公告前,TechCrunch 于 2026 年 8 月 24 日报道了隐私和安全担忧。 公开记录中最重要的负面事件来自产品本身,而不是公司治理。Beta 测试者报告称,Instinct 在没有明确逐项同意的情况下发送邮件; 用户断开 Google 账户访问后,邮件内容仍以明文保留;恶意邮件可通过提示注入攻击影响用户。SC Media 和 StartupFortune 报道了 这些事件。公司回应是增加数据删除界面,TechCrunch 有所报道,但底层服务条款没有改变。未有监管调查、诉讼或高管离职公开披露。 融资年表是记录最充分的维度。公开记录缺口包括 2025 年内的准确成立日期、任何监管文件、全部合作伙伴或集成协议,以及任何产品发布或 商业开放计划。对于一家估值 $2.5 billion 的公司,即便仍处私营阶段,未披露董事会成员、治理文件或投资人权利协议也值得关注。[CO002, CO003, CO005, CO016, CO017, CO018]
| 日期 | 事件 | 类型 | 金额 / 估值 / 状态 | 参与方 | 含义 |
|---|---|---|---|---|---|
| 2025(估计) | Noah Shinn 离开 Sierra;在加州创立 Spear Street Technology | 创立 | 实体注册;种子资本可能同期到位 | Noah Shinn;种子投资人 TBD | 创立标志着从研究转向商业产品;确切日期未披露 |
| 2026-01(估计) | Instinct 在封闭 beta 中达到约 $5M ARR | 规模化 | ~$5M ARR | 内部指标;TechCrunch 据管理层报道 | 最早披露的收入基准;确认产品已经上线并产生收入 |
| 2026 Q1–Q2(估计) | Series A 以约 $500M 估值完成;Kleiner Perkins(Mamoon Hamid)领投 | 融资 | ~$100M 融资(种子轮 + A 轮合计);~$500M 估值 | Kleiner Perkins、Conviction、Greenoaks 与 Noah Shinn | 首次机构验证;支持团队扩张和基础设施投入 |
| 2026-08-24 | TechCrunch 发布关于 Instinct 广泛数据权限的隐私和安全担忧 | 反向 | 报道;未报告直接财务影响 | TechCrunch;beta 测试者;安全研究人员 | 首次重大负面报道;凸显永久数据许可和提示词注入风险 |
| 2026-08-24 至 08-25(估计) | 出现 Instinct 未经同意发送邮件、断开连接后仍留存数据的报道 | 反向 | 声誉影响;未披露罚款或法律行动 | StartupFortune、ExplainX、SC Media;beta 测试者 | 产品可靠性和同意模型受到质疑;公司以删除工具回应 |
| 2026-08-25(估计) | Instinct 为回应反弹,在界面中加入数据删除工具 | 产品 | 新增功能;ToS 未变 | 内部产品团队 | 响应式产品迭代表明有运营能力,但未解决 ToS 担忧 |
| 2026-08-26 | Series B 完成;以 $2.5B 投后估值融资 $250M | 融资 | $250M 融资;$2.5B 估值 | Index Ventures、Benchmark(共同领投);Noah Shinn | 独角兽+ 里程碑;约 6 个月内较种子轮估值上升 25× |
| 2026-08-26 | TechCrunch 发布 Series B 融资公告;确认累计融资 $350M 和 $80M ARR | 融资 | $80M ARR(截至公告日) | TechCrunch;Instinct 管理层 | 公开确认 ARR 在约 8 个月内从 $5M 增至 $80M;媒体能见度高 |
| 2026-08-28(运行日期) | Instinct 仍处于封闭 beta;尚未宣布商业发布 | 规模化 | ~$80M ARR(封闭 beta) | 内部 | 开放问题:$80M ARR 在规模化后是否可持续,还是来自集中的早期队列 |
标注“(估计)”的日期基于上下文报道估计。种子轮 / Series A 和早期产品事件的确切日期未经一手来源确认。
[CO002, CO003, CO005, CO006, CO017, CO018]2025 年成立至 2026 年 8 月 Series B,按时间梳理 Instinct 的成立、融资、产品和负面事件里程碑。
成立和 Series A 日期根据上下文报道估计;确切日历日期未获公开确认。
[CO002, CO003, CO005, CO017, CO018, CO024]1.5 图表
02市场分析
2.1 市场定义与边界
Instinct 竞争的是消费级 AI 个人助理市场,这属于更广义的智能虚拟助理行业。该市场包括能理解自然语言指令,并代表个人消费者自主执行 排期、邮件管理、旅行预订、购买和信息检索等任务的软件产品。它不包括只面向企业的解决方案、没有行动能力的纯聊天机器人,也不包括缺乏深度 设备集成的纯语音智能音箱助理。核心参与者既有 Apple Siri、Google Assistant、Amazon Alexa、Microsoft Cortana、Samsung Bixby 等平台既有玩家,也有 Instinct、Rabbit r1、Humane AI Pin 等 AI 原生进入者。2025-2026 年市场变化的关键,是从被动问答助理转向 主动智能体系统:后者只需要最少用户确认就能自主行动。Instinct 处在消费端智能体转型的前沿,差异点是 SMS 和 WhatsApp 入口、深权限模型 以及自主任务执行能力。市场边界在边缘地带较模糊:带 AI 功能的生产力 SaaS、浏览器自动化工具和 AI 编码助理,都与个人助理功能重叠,但主要用例 不同。为估算市场规模,本分析聚焦主要以个人助理定位、且具备多领域任务执行能力的产品。[CM001, CM002, CM003, CM004, CM005, CM006]
| 维度 | 纳入 | 排除 | Instinct 定位 |
|---|---|---|---|
| 产品类型 | 具备行动能力的多领域任务助理 | 纯聊天机器人、单用途工具、仅企业解决方案 | 全栈自主助理 |
| 交互界面 | 文本、语音、与设备集成的多模态 | 没有软件智能的纯硬件设备 | SMS 和 WhatsApp 为主,语音为辅 |
| 任务范围 | 日程安排、邮件、旅行、购物、生活事务 | 工业自动化、仅编码、游戏 | 所有消费者生活管理任务 |
| 用户类型 | 个人消费者和专业消费者 | 仅企业部署、仅 B2B 产品 | 隐私容忍度较高、任务量大的消费者 |
| 地理 | 全球,重点是英语市场 | 仅离线或地区锁定产品 | 美国为主,全球候补名单 |
| 权限模型 | 用于自主执行的设备访问 | 没有行动能力的只读助理 | 深度权限,包括邮件、日历、位置、屏幕 |
随着 AI 能力扩张,市场边界仍模糊;Instinct 定位在智能体前沿
[CM001, CM002, CM003]| 类别 | 参与者 | 主要界面 | 自主程度 | 市场位置 |
|---|---|---|---|---|
| 平台既有玩家 | Apple Siri 与 Apple Intelligence | Apple 设备上的语音和文本 | 中 — 执行动作需要确认 | 凭 iOS 拥有最大装机基础 |
| 平台既有玩家 | Google Assistant 与 Gemini | Android 和 Google 设备上的语音和文本 | 中 — 智能体能力继续扩张 | 凭 Android 位居第二 |
| 平台既有玩家 | Amazon Alexa | Echo 设备上的语音优先 | 低 — 主要控制智能家居 | 主导智能音箱细分市场 |
| 平台既有玩家 | Microsoft Copilot | Windows 和 Office 中的文本 | 中 — 聚焦生产力 | 从企业场景延伸至消费者 |
| AI 原生创业公司 | Instinct | SMS 和 WhatsApp | 高 — 自主执行 | 增长最快的封闭 beta |
| AI 原生创业公司 | Rabbit r1 | 专用硬件设备 | 中 — 行动导向但受硬件限制 | 硬件差异化打法 |
| AI 原生创业公司 | Humane AI Pin | 带投影的可穿戴设备 | 低 — 因硬件问题采用有限 | 发布后挣扎 |
| AI 聊天机器人跨界 | OpenAI ChatGPT 智能体模式 | 应用和网页中的文本 | 高 — 2026 年智能体功能扩张 | 最大 AI 聊天机器人用户基础 |
市场在拥有分发的既有玩家和具备智能体能力的创业公司之间碎片化
[CM004, CM005, CM006]2.2 市场规模与增长轨迹
2026 年,全球消费级 AI 个人助理市场估计达到 4.84 billion USD,相比 2025 年 3.4 billion USD 基线,复合年增长率为 42.2%。 更广义的智能个人助理市场包括企业与混合部署,2026 年规模约 17.95 billion USD,CAGR 为 25.9%。市场预测显示,如果当前增速延续, 消费端到 2030 年将达到 19.6 billion USD。由于“个人助理”和通用 AI 聊天机器人、专用生产力工具之间定义模糊,这些估计存在较大不确定区间。 Research and Markets 与 The Business Research Company 提供主要第三方规模估计,其方法将订阅收入、广告支持使用和硬件捆绑助理价值汇总。 总可用市场(TAM)代表理论上所有智能手机用户都采用付费 AI 助理时的最大市场;可服务市场(SAM)缩小到已表现出为生产力委托付费意愿的用户; 可获取市场(SOM)则对应 2026-2027 年 具备深权限的智能体助理可触达市场。具体到 Instinct,真正可触达的是愿意授予广泛设备权限,并为自主任务执行支付订阅费的消费者子集。 重视隐私的用户以及受监管行业中的用户,是这一可触达市场的结构性排除项。Instinct 在 8 个月实现 16x ARR 增长,要么说明其目标细分市场内 产品市场契合度异常强,要么是早期采用者激增,等候补名单清空后会回归常态。[CM008, CM009, CM010, CM011, CM012, CM013]
| 指标 | 2025 年估计 | 2026 年估计 | 2030 预测 | 来源 | 置信度 |
|---|---|---|---|---|---|
| 消费者 AI 助手 TAM | 3.4B USD | 4.84B USD | 19.6B USD | Research and Markets 报告 | 中 - 定义存在模糊性 |
| 更广义的 IPA 市场 | 14.3B USD | 17.95B USD | 35B USD | The Business Research Company | 中 - 包含企业市场 |
| 消费者 AI 助手 CAGR | - | 42.2% | 预计 35-40% | Research and Markets 报告 | 中 - 可能高度波动 |
| 智能体助手 SAM | 尚未明确 | 估计 1-2B USD | 8-10B USD | 分析师综合测算 | 低 - 品类仍在萌芽 |
| Instinct SOM(隐私容忍度较高的高频用户) | - | 200-500M USD | 1-3B USD | 内部估计 | 低 - 细分定义不确定 |
品类定义仍在变化,智能体助手的历史数据也有限,市场规模测算不确定性很高
[CM008, CM009, CM010, CM011]2.3 市场分层与买家画像
消费级 AI 个人助理市场按任务类型、用户成熟度、隐私容忍度和付费意愿分层。按任务类型,市场分为排期和日历管理、邮件和沟通管理、旅行和物流、 购物和购买、信息检索和研究,以及账单支付、订阅管理等生活行政事务。按用户成熟度,范围从只想简单问答的基础语音指令用户,到愿意授予广泛权限、 让系统自主行动的高阶用户。按隐私容忍度,市场明显分裂:隐私敏感用户拒绝广泛数据访问,便利优先用户愿意用隐私换功能。按付费意愿,细分包括 只用免费层的用户、每月低于 10 USD 的低价订阅者,以及愿意为全面辅助支付 20-50 USD 或更多的高端订阅者。Instinct 的目标细分似乎是 隐私容忍度高、付费意愿高的高阶用户,他们看重自主执行胜过逐步确认。该细分相对小,但随着生成式 AI 让数据共享正常化,正在快速增长。 地理上,北美和西欧是主要市场,原因是智能手机渗透率、英语 AI 模型成熟度和消费能力;亚太地区绝对增量最快。年龄结构偏向 25-45 岁专业人士: 日程复杂、有可支配收入,但没有专属真人助理。[CM016, CM017, CM018, CM019, CM020, CM021]
| 细分人群 | 任务量 | 隐私容忍度 | 付费意愿 | 与 Instinct 匹配度 | 细分规模估计 |
|---|---|---|---|---|---|
| 忙碌专业人士 | 高 | 中高 | 高(20-50 USD/mo) | 强 | 全球 50-80M 用户 |
| 科技早期采用者 | 中高 | 高 | 高 | 很强 | 20-30M 用户 |
| 重视隐私的用户 | 不一 | 低 | 中 | 差 | 100M+ 用户 |
| 预算敏感用户 | 中 | 中 | 低(免费或低于 5 USD) | 弱 | 200M+ 用户 |
| 老年人与低技术熟练度用户 | 低中 | 不一 | 低中 | 弱 - UX 复杂 | 150M+ 用户 |
| 高净值人群 | 高 | 中 | 很高(100+ USD) | 强 - 替代真人助理 | 5-10M 用户 |
Instinct 瞄准隐私容忍度较高的专业人士和早期采用者;重视隐私的人群是结构性排除项
[CM016, CM017, CM018, CM019]2.4 增长驱动因素与市场约束
市场增长由五个主要催化剂推动。第一,生成式 AI 能力提升后,自然语言理解和任务完成已经可靠到可以投入生产用例。第二,智能手机普及提供了设备底座 和联网能力,让随时可用的助理成为可能。第三,消费者通过 ChatGPT 等产品熟悉 AI,AI 互动已被正常化,采纳摩擦下降。第四,远程和混合办公带来的 生产力压力,提高了对委托工具的需求。第五,Instinct 采用的 SMS 和消息应用入口不需要用户学习新应用,降低了上手摩擦。市场约束包括:围绕 AI 智能体责任和数据保护的监管不确定性;高知名度 AI 失败事件之后的消费者信任缺口;Apple 和 Google 的平台把关限制第三方助理能力;以及提示注入攻击等 削弱可靠性的安全漏洞。FTC 已释放信号,将加强审查代表消费者进入有约束力交易的 AI 智能体;EU AI Act 可能将自主个人助理归类为高风险系统, 要求进行符合性评估。CCPA 和 GDPR 等隐私法规增加合规负担,并限制数据保留做法。市场轨迹很大程度取决于:智能体 AI 的信任缺口能否比监管约束 收紧更快闭合。[CM022, CM023, CM024, CM025, CM026, CM027]
03竞争格局
3.1 直接对手与既有玩家标杆
Instinct 最接近的参照组不是所有聊天机器人,而是那些试图成为用户日常数字工作操作界面的产品。OpenAI Operator 是最清晰的直接标杆,因为它明确 承诺基于浏览器执行任务。Google Gemini、Apple Intelligence 和 Microsoft Copilot 稍有不同:它们是更广的生态或捆绑型助理,不是初创公司式单一产品; 但从用户结果看,它们越来越多地覆盖同一组核心工作:起草、排期、总结,以及最终采取行动。Meta AI 属于同一个外圈,因为它让用户在消费级通信界面里 期待免费 AI 帮助。 Humane 需要单独看。AI Pin 已经不是活跃竞争对手,但仍有战略意义,因为它同时证明了投资人对常开型助理产品的兴趣,以及消费者端的脆弱性。被 HP 收购后的关停提醒市场:新奇感和宏大的助理叙事,不能弥补薄弱的产品循环。这个先例对 Instinct 重要,因为公司同样要求用户在主流证明出现前,先信任一种 新的委托形式。 在这个参照组里,Instinct 的优势不是规模或品牌,而是聚焦:它是消息原生助理,目标是在真实账户里运转,不再等待持续确认。这让产品比许多既有玩家更像 智能体,但一旦信任破裂,暴露面也更大。[CP001, CP002, CP003, CP004, CP005, CP006]
| 竞品 | 类别 | 规模 / 可用性代理指标 | 目标用户 | 差异化 | 相比 Instinct 的限制 |
|---|---|---|---|---|---|
| OpenAI Operator | 直接智能体基准 | Pro 档 / 研究预览 | 专业消费者与高频用户 | 基于浏览器执行任务 | 非消息原生 |
| Google Gemini | 现有通用助手 | 借 Google 生态大规模分发 | 主流消费者与专业消费者 | 贴近搜索、账户和设备 | 对委托式个人事务聚焦较弱 |
| Apple Intelligence / Siri | 现有 OS 助手 | 随兼容 Apple 设备捆绑 | 高端 Apple 消费者 | OS 默认入口与信任基础 | 当前可见自主性较低 |
| Microsoft Copilot | 现有生产力助手 | 覆盖 Microsoft 多个入口 | 知识工作者和企业用户 | 套件集成与订阅捆绑 | 消费级个人场景姿态较弱 |
| Perplexity Pro | 功能重叠 | 付费档已广泛可用 | 重研究的消费者 | 答案质量与搜索深度 | 不能完整委托执行 |
| Humane AI Pin | 前车之鉴 | 产品已关闭 | 早期采用型硬件买家 | 激进的助手愿景 | 执行和信任失败 |
Humane 已不再是仍在运营的直接竞品,这里纳入是为了提供战略背景。
[CP001, CP002, CP003, CP004, CP005, CP006]| 公司 | 公开规模标志 | 商业模式 | 资本基础 | 对 Instinct 的含义 |
|---|---|---|---|---|
| Instinct | 私测阶段 ~$80M ARR | 未披露的付费消费者助手 | 已融资 $350M | 早期验证强,品牌成熟度有限 |
| OpenAI | 大规模付费订阅用户 | 订阅 + API | 前沿模型级资本 | 能补贴智能体实验 |
| Google / Gemini | 捆绑和订阅式 AI 方案 | 捆绑 + 订阅 | 公司资产负债表 | 可凭生态优势定价 |
| Apple Intelligence | 随设备生态捆绑 | 硬件主导的捆绑 | 公司资产负债表 | 分发和信任优势 |
| Microsoft Copilot | 订阅套件挂载 | 捆绑 + 增购 | 公司资产负债表 | 企业与生产力渠道强 |
| Humane | 被收购后产品关闭 | 硬件 + 订阅尝试 | 此前由风投支持的创业公司 | 说明没有产品契合度,资本也不够 |
仅使用公开标志;资本基础对比为方向性判断,并非穷尽。
[CP002, CP006, CP013, CP014, CP015, CP024]Instinct 自主性得分高,但分发能力低于在位平台竞争者。
轴为基于公开定位推断的序数评分,x 轴为自主性,y 轴为分发能力。
[CP010, CP011, CP016, CP024, CP033, CP034]在位者和初创公司都在加码竞争,信任失误仍定义着这一品类。
Operator 和 Apple 推出日期四舍五入到公开发布窗口,因为具体功能节奏存在差异。
[CP002, CP003, CP005, CP020, CP021, CP033]3.2 相邻替代品与专用工作流工具
下一圈竞争来自只解决 Instinct 部分工作、但不提供完整委托助理组合的产品。Claude 和 Perplexity 是这一组里最重要的广义替代品。Claude 在推理、 写作和分析上很强,但其公开入口目前不像 Instinct 或 Operator 那样强调消费级任务执行。Perplexity 擅长搜索、研究和答案质量;对一些用户来说, 这足以降低他们对更广义助理的需求,但它并不承诺自主收件箱、日历、购物和旅行管理。 然后是专用工具。Superhuman 把邮件速度和体验做得很强。Motion 占住排期和时间分配。Cal.com 提供排期基础设施。这些公司重要,是因为它们说明即便 通用 AI 变强,窄工作流软件仍然可以赢。专用工具更容易被信任、预算更清晰,也比一个触达所有事务的助理更容易做基准评估。 对 Instinct 而言,竞争门槛是双面的。它必须在行动导向上胜过广义 AI 产品,同时在具体工作流可用性上胜过专用工具。这并非不可能,但比“通用工具打败点状工具” 的简单故事门槛更高。[CP007, CP008, CP009, CP012, CP013, CP017]
| 购买标准 | Instinct | Operator | Gemini | Apple Intelligence | Claude / Perplexity / 专业工具 |
|---|---|---|---|---|---|
| 消息原生入口 | 是 | 否 | 部分 | 否 | 大多否 |
| 自主多步骤任务 | 高 | 高 | 中 | 低中 | 低到中 |
| 邮件 / 日历 / 旅行打包 | 是 | 部分 | 部分 | 部分 | 通常只覆盖单一工作流 |
| 广泛公开可用 | 否 - 私测 | 付费档有限开放 | 是 | 支持设备上可用 | 是 |
| 原生平台集成 | 低 | 低 | 高 | 高 | 不一 |
| 信任 / 品牌熟悉度 | 低中 | 高 | 高 | 高 | 中高 |
单元格为定性判断,依据公开可见定位,而非内部能力测试。
[CP003, CP004, CP005, CP007, CP008, CP009]Instinct 与几家对手有较广重叠,但具体重叠因工作流和自主深度而异。
单元格概括公开产品定位,而不是实验室测试性能分数。
[CP007, CP008, CP009, CP010, CP016, CP017]3.3 分发力量、切换成本与定价压力
Instinct 最大的非产品差异点,是它通过 SMS 和 WhatsApp 触达用户,而不是 app 优先界面。这很重要,因为消费级助理的设置负担不只是创建账户,还有习惯养成。 消息线程比下载并学习另一个应用更低摩擦。与此同时,渠道所有权仍在外部。Apple、Google、Microsoft、Meta 和 WhatsApp 控制主流设备、身份、应用商店和 通信界面,进而影响发现和信任。它们也有能力把助理功能捆进用户已经付费的产品。 这种捆绑能力会压低定价空间。OpenAI、Google、Microsoft 和 Claude 现在都销售付费 AI 套餐,验证了经常性支出,但也让用户习惯把多个助理并排比较。 Meta 则朝相反方向走,把 AI 辅助免费化。在这种环境下,Instinct 大概率不能只靠价格取胜。它必须靠可感知的有用性取胜:省下足够时间或认知负担,让用户 在替代品充足时仍愿意单独付费。 切换成本只是中等。许多用户仍会多平台并用,现状也很碎片化。这有助于 Instinct 获得试用,但除非助理深度嵌入敏感且可信的工作流,否则长期锁定更难。[CP010, CP011, CP013, CP014, CP018, CP019]
| 公司 | 主要入口 | 获客动作 | 定价姿态 | 切换摩擦 | 分发能力 |
|---|---|---|---|---|---|
| Instinct | SMS / WhatsApp | 病毒式 / 邀请制 | 未披露的高端定价 | 中 | 自有渠道弱,渠道杠杆强 |
| OpenAI Operator | ChatGPT | 订阅增购 | 付费档 | 低中 | 品牌触达很强 |
| Gemini | Google 应用和网页 | 捆绑 + 订阅 | 免费 + 付费 | 低 | 平台触达很强 |
| Apple Intelligence | OS 原生 | 随设备捆绑 | 捆绑 | 低 | 设备触达很强 |
| Microsoft Copilot | 生产力套件 | 捆绑 + 企业渠道 | 付费 / 捆绑 | 低 | 套件触达很强 |
| 专业工具(Superhuman / Motion / Cal.com) | 专用应用 | 工作流驱动的自助式获客 | 付费工作流订阅 | 中高 | 聚焦垂直触达 |
分发能力为定性判断;Instinct 受益于用户熟悉的渠道,但并不拥有主导平台。
[CP009, CP010, CP011, CP013, CP014, CP018]平台方一开始就拥有明显更强的默认入口优势。
数值是分发能力序数评分,不是市场份额数据。
[CP011, CP019, CP020, CP024, CP031]3.4 护城河耐久性与反向逻辑
关于 Instinct 护城河,最强论点是产品架构和用户体验。公司试图把几个碎片化工作压缩进一个会行动、不只是给建议的助理里。如果它能在一个消息线程中可靠处理 沟通、排期、购物和旅行,产品体验可能与通用聊天和单一工作流 app 都有质的不同。创始人的智能体循环研究背景也为这一野心增加可信度。 反向逻辑比许多初创公司叙事承认的更强。每个主要平台所有者都在从远强得多的装机基础出发,走向更智能体式的行为。如果 Google、Apple、OpenAI、Microsoft 或 Meta 在保留更高信任和更深平台集成的同时,匹配 Instinct 大部分自主性,独立产品切入点会迅速被压缩。Instinct 自身负面事件又放大了这一风险,因为信任 恰恰是既有玩家起步更领先的少数领域之一。 因此,正确的尽调判断应是有条件的。Instinct 今天确实有真实切入点,但护城河耐久性尚未证明。公开记录缺少定价、留存、任务级成功率,以及相对于竞品的流失数据。 在这些数据出现前,竞争优势应视为可能存在,但不能默认持久。[CP012, CP016, CP017, CP018, CP020, CP021]
| 护城河主张 | 主要威胁 | 严重性 | 重要性 | 缓释措施 / 尽调问题 |
|---|---|---|---|---|
| 消息原生 UX | 现有巨头在既有应用里加入智能体聊天 | 高 | 界面优势可能很快被压缩 | 衡量 SMS / WhatsApp 带来的留存优势 |
| 更高自主性 | 自主性事故削弱信任 | 高 | 用户可能偏好更安全但能力较弱的现有产品 | 要求任务级错误率数据 |
| 跨工作流打包 | 专业工具保住更深的工作流 UX | 中 | 打包可能宽但浅 | 对比邮件和日历 NPS 与专业工具 |
| 创始人 / 技术边际 | 大科技分发和资本 | 高 | 产品质量未必能打赢默认入口 | 测试用户在并排试用后是否切换 |
| 早期 ARR 动能 | 私测集中度和新鲜感效应 | 中 | 当前验证未必能泛化 | 按工作流深度分析转化和流失队列 |
反向逻辑集中在信任和分发,而不只是原始模型质量。
[CP012, CP016, CP017, CP018, CP019, CP020]3.5 图表
04财务情况
4.1 融资历史与资本结构
Spear Street Technology Inc. 已完成两轮可识别融资。Series A 于 2026 年 1 月完成,规模 $100 million,由 Kleiner Perkins 领投, 合伙人 Mamoon Hamid 获得董事会观察员或董事席位;Conviction Capital(Sarah Guo)参投。Series A 时,ARR 约 $5 million,隐含该轮 收入倍数约 ~100×。Series B 于 2026 年 8 月 26 日完成,规模 $250 million,由 Index Ventures 和 Benchmark 共同领投,投后估值 $2.5 billion。Series B 时,管理层口径 ARR 约 $80 million,隐含 ~31× ARR。Greenoaks Capital 也参与了 Series B。所有已披露轮次累计融资 $350 million。种子轮或 pre-seed 信息没有公开披露。股权结构表、投资人持股比例和稀释安排均不可得。[CI001, CI002, CI003, CI004, CI005, CI006]
| 轮次 | 日期 | 金额 | 投后估值 | 交割时 ARR | ARR 倍数 | 领投方 |
|---|---|---|---|---|---|---|
| Series A 轮 | 2026-01-01 | $100M | 估计 ~$500M | ~$5M | ~100× | Kleiner Perkins (Mamoon Hamid) |
| Series B 轮 | 2026-08-26 | $250M | $2.5B | ~$80M | ~31× | Index Ventures + Benchmark |
| 合计 / 当前 | 2026-08-28 | $350M | $2.5B | $80M | 31× | Index Ventures、Benchmark、KP、Conviction 与 Greenoaks |
A 轮估值由分析师基于 $100M 融资和可比消费 AI 种子轮至 A 轮估值跃升估算;尚未确认。所有 ARR 数字均为管理层口径。公开资料没有种子轮或种子前轮数据。
[CI001, CI002, CI003, CI004, CI005]Instinct 的投后估值从 Series A 的约 $500 million 升至 Series B 的 $2.5 billion,7 个月涨了 5×。
Pre-Series A 和 Series A 估值为分析师估计;只有 Series B 的 $2.5B 估值已确认。估值抬升值由估计估值推导。
[CI001, CI002, CI003, CI025]4.2 收入轨迹与 ARR 增长
Instinct 管理层口径 ARR 从 2026 年 1 月约 $5 million 增至 2026 年 8 月约 $80 million,约七个月增长 16×。这意味着平均每月新增净 ARR 约 $10.7 million。如果属实,这一增速将跻身任何消费软件产品有记录以来最快的 ARR 爬坡。ARR 尚无独立验证;该数字完全来自媒体报道中的管理层表述。 毛利率、净留存率(NRR)、客户数、用户平均收入(ARPU)和定价结构均未披露。产品仍处私测阶段,仅限邀请,说明 ARR 可能来自一小群早期付费用户, 或尚未公开描述的早期商业安排。[CI007, CI008, CI009, CI010, CI011, CI012]
| 期间 | ARR(估计) | 月度增长 | 当期收入倍数 | 备注 |
|---|---|---|---|---|
| 2026 年 1 月 | ~$5M | N/A | ~100×(相对 $500M A 轮) | 管理层在 Series A 轮交割时表述 |
| February 2026 | ~$15M 估计 | ~$10M | ~N/A | 线性插值;未披露 |
| April 2026 | ~$35M 估计 | ~$10M | ~N/A | 线性插值;未披露 |
| June 2026 | ~$55M 估计 | ~$10M | ~N/A | 线性插值;未披露 |
| August 2026 | ~$80M | ~$12.5M | ~31×(相对 $2.5B Series B 轮) | 管理层在 Series B 轮交割时表述 |
| 隐含 CAGR(年化) | 7mo 内 ~16× | 平均 ~$10.7M | N/A | 若增长线性;实际路径未知 |
中间 ARR 数字是披露数据点之间的线性插值;实际月度 ARR 未知。 相比这条线性路径,增长可能前置,也可能后置。
[CI007, CI008, CI009, CI010]管理层称,年经常性收入(ARR)从 2026 年 1 月约 $5M 增至 2026 年 8 月约 $80M,意味着这段时间平均每月新增净 ARR 约 $10.7M。
2026 年 1 月和 8 月数据点来自管理层表述。中间月份为线性插值;实际 ARR 路径未知。
[CI007, CI008, CI009, CI010, CI026]4.3 单位经济模型与利润率估计
由于 Instinct 没有披露定价、员工数或成本结构,所有单位经济模型分析只能基于行业基准,以及对可比消费级 AI 公司的推断。自主 AI 助理处理邮件、日历和 多步骤任务时,LLM 推理成本估计占收入的 15-35%,依据是类似智能体产品公开的成本结构。若套用到 $80 million ARR,意味着年度 LLM 推理成本为 $12-28 million。考虑到病毒式候补名单模式,获客成本(CAC)可能较低,但这一点带有推测性。不完全依赖基础设施的可比消费级 AI SaaS 企业毛利率在 50-75% 区间;Instinct 推理强度更高,意味着更可能落在区间低端。净留存率未知;私测背景和未披露流失数据使分析无法展开。GTM 动作依赖病毒式分发和 仅限邀请的候补名单,提示付费获客成本较低,但增长放大后的可预测性有限。销售周期未定义;未披露外呼或企业销售动作。GTM 效率指标——CAC 回本周期、 LTV/CAC 比率和渠道组合——在公开披露中完全缺席。[CI013, CI014, CI015, CI016, CI017, CI018]
| 指标 | 估计值 | 方法 | 置信度 | 缺口 |
|---|---|---|---|---|
| 毛利率 | 50–70% 估计 | 可比消费级 AI SaaS 基准 | 低 | 未披露财务数据 |
| LLM 推理成本(收入占比) | 15–35% | 已公开智能体 AI 成本结构 | 低 | 供应商和定价未知 |
| LLM 推理成本($M/yr) | $12–$28M | 按 $80M ARR 测算 | 低 | 仅为估算 |
| 获客成本 | 低(病毒式传播) | 邀请制候补名单模式 | 低 | 未披露营销支出 |
| 净收入留存率 | Unknown | 未披露 | N/A | 估值尽调的关键缺口 |
| ARPU(月度) | Unknown | 未披露定价 | N/A | 私密 beta;无公开定价 |
所有单位经济模型数字都是分析师基于行业基准推导的估计。Instinct 未确认或披露任何数字。 只能按方向性参考。
[CI013, CI014, CI015, CI016]在缺少公开财务披露的情况下,毛利率、LLM 推理成本和 ARPU 都是分析师估计,且不确定性区间很宽。
所有区间均为分析师估计,来自可比消费 AI 公司基准。区间较宽,反映高度不确定性。
[CI013, CI014, CI015, CI016, CI027]4.4 财务风险与烧钱展望
Instinct 的核心财务风险集中在四点:(1)估值 $2.5 billion 时仍未披露变现模型,带来证明价格合理性的执行风险;(2)依赖未披露的 LLM 供应商, 其定价或可用性可能不利变化;(3)烧钱速度未知,但考虑 AI 推理成本和工程团队人数,可能相当高;(4)消费级 AI 产品规模化变现历来困难。 公司已融资 $350 million,若假设每月烧钱 $3-7 million(基于行业的估计),从 Series B 交割起现金跑道约 36-58 个月,足以支撑商业发布和首个 变现周期。然而,如果隐私反弹或竞争压力导致 ARR 增长放缓,相对收入的烧钱速度可能更快变成问题。缺少审计财务报表或任何第三方财务认证,意味着所有 现金跑道估计都高度不确定,只应视为指示性判断。反稀释条款、清算优先权等偏投资人的条款很可能存在,但完全未披露,这进一步限制了财务建模和退出情景 分析的精度。[CI019, CI020, CI021, CI022, CI023, CI024]
| 情景 | 月度烧钱速度 | LLM 成本 | 其他运营支出 | $350M 对应隐含现金跑道 | 关键假设 |
|---|---|---|---|---|---|
| 保守(精简团队) | $3M/mo | $1.2M | $1.8M | 约 58 个月 | 员工约 25 人,低支出 |
| 基准(行业基准) | $5M/mo | $2.0M | $3.0M | 约 35 个月 | 员工约 50 人,中等支出 |
| 激进(扩张) | $9M/mo | $3.5M | $5.5M | 约 19 个月 | 员工约 100+ 人,快速招聘 |
烧钱速度情景是分析师估计;实际烧钱速度未披露。$350M 并非一次性融到; 提款时间会影响真实现金跑道。
[CI020, CI021, CI022]| 风险领域 | 描述 | 严重程度 | 证据 | 缓释路径 |
|---|---|---|---|---|
| 无货币化模式 | 估值 $2.5B 时仍未披露定价或收入模式 | 严重 | 公开披露为零 | 商业化发布公告 |
| LLM 供应商依赖 | LLM 供应商未披露;API 定价或可用性可能变化 | 高 | 推理成本估计占收入 15–35% | 谈长期合约;分散供应商 |
| ARR 未验证 | $80M ARR 来自管理层表述;无第三方验证 | 高 | 单一来源:管理层表述 | 尽调中提供经审计财务数据 |
| 消费级 AI 货币化历史 | 消费级 AI 历史上很难在规模化后守住付费订阅 | 高 | 历史案例:Inflection、Character AI | 差异化产品价值;自主执行效用 |
| 隐私反弹引发的收入风险 | August 2026 的反向报道可能拖慢 ARR 增长或推高流失 | 高 | TechCrunch August 2026 反向报道 | 修产品;数据政策透明 |
严重程度是分析师基于现有证据和行业基准的判断。尚未公开的披露可能缓释所有这些风险。
[CI019, CI022, CI023, CI024]估计月度烧钱速度为 $3-9M,以已融资 $350M 计算,现金跑道为 19-58 个月。基准情景显示现金跑道约 35 个月,足以支撑商业化发布。
烧钱速度和现金跑道均为分析师估计。实际现金余额取决于资金提取节奏、收入回款,以及未公开的运营费用。
[CI020, CI021, CI022, CI028]4.5 图表
05产品与技术
5.1 Instinct 在日常工作流中交付什么
Instinct 的定位是面向消费者的个人助理,生活在人们已经使用的渠道里,而不是要求用户学习新 app。官网称产品“无需新界面”,系统被训练为会使用手机和电脑, 用户可以给它发短信或打电话;第三方报道补充称 WhatsApp 也是支持渠道。实际产品承诺不是用于信息检索的聊天,而是委托执行。公开描述的任务包括清理收件箱、 起草跟进、预约、餐厅订位、旅行协调、叫车、购物,以及当智能体发现未完成线程时主动提醒。相同来源也清楚表明,Instinct 可以跨邮件、消息、日历、屏幕、 音频和位置权限行动,这显著扩大了范围:它不只是助理,更像操作员。这种工作流设计在战略上有吸引力,因为它移除安装摩擦,并把许多杂务集中到一个对话入口; 但产品质量也因此取决于不可见的后台决策,而不只是答案质量。用户同时购买便利和代理权转移,所以看似很小的控制失效——例如一封未授权邮件——都会变成一阶产品风险。[CE001, CE002, CE003, CE004, CE005, CE006]
| 模块 / 资产 | 功能 | 用户 / 触点 | 成熟度 | 差异化 / 尽调缺口 |
|---|---|---|---|---|
| 消息界面通道 | 通过短信、电话及据报道的 WhatsApp 触点接收用户请求并发送后续消息 | 终端用户前端 | 私密 beta,测试用户已在使用 | 无需下载 App 是真实 UX 差异点;具体传输供应商未披露 |
| 连接账户数据摄取 | 从电子邮件、消息、日历和其他已连接服务拉取上下文 | 用户数据与上下文层 | 私密 beta,权限已有公开文档 | 访问深度形成差异化;范围治理和最小权限设计未公开 |
| 智能体动作引擎 | 把请求转成预订、购买、日程调整和对外沟通 | 核心执行层 | 功能已验证,控制质量仍不成熟 | 自主执行是主打功能;审批阈值和回滚逻辑未披露 |
| 记忆 / 索引层 | 存储既有上下文和已索引外部数据,让助手能跟进中断线程 | 个性化层 | 显然已启用,治理受挑战 | 持久记忆看起来处在核心位置;删除语义在 beta 中引发争议 |
| 后台同步 / 通知层 | 监控已连接服务的更新,并触发后续工作 | 后端运行层 | 由平台文档和产品表述推断 | 可能使用 watch / webhook 任务;无公开架构或可观测性证据 |
| Workspace / 设置界面 | 在对话线程之外承载账户连接、删除和控制设置 | 管理 / 安全界面 | 仅有反应式公开证据 | 删除工具似乎在投诉后加入;审计日志可见性缺失 |
行内容合并了官方产品文案、法律文件、集成平台文档和测试用户的反向报道; 若干后端层属于推断,因为 Instinct 没有发布正式架构图。
[CE001, CE002, CE003, CE004, CE015, CE018]| 用户任务 | 示例任务 | Instinct 处理方式 | 所需集成 | 公开证实的收益 | 已知限制 |
|---|---|---|---|---|---|
| 出行 / 预订管理 | 叫车去机场或订餐厅座位 | 用户发消息提出请求;智能体读取上下文,在已连接服务上执行,并确认或继续追问 | 消息通道,加出行或商户账户访问 | 多步骤杂事只有一个对话入口 | 错误动作可能形成有约束力的承诺或非预期购买 |
| 收件箱清理与跟进 | 总结邮件、找验证码、起草或发送跟进 | 读取邮箱内容,并代表用户跨已连接邮箱账户执行动作 | Gmail 或 Outlook 式邮件 API,或委托账户访问 | 从总结推进到执行 | beta 中已经出现未经授权的对外邮件 |
| 日历协调 | 预约并处理时间冲突 | 结合收件箱、日历和提醒来安排或改期事件 | 日历 API 和后台变更监控 | 能主动推进线程 | webhook 或 token 被攻破,或事件状态过期,都可能触发错误排期 |
| 购物与购买 | 下单或完成结账步骤 | 使用委托支付和商户上下文代表用户交易 | 商户凭证、支付数据和外部结账流程 | 大幅降低结账摩擦 | 条款把交易责任放在用户而非平台身上 |
| 长尾生活事务 | 无需再次提示,也能跟进中断线程或提醒 | 持久上下文让智能体稍后重新介入,并串起多个触点 | 记忆 / 索引层,加对外消息传输 | 体验更像主动,而非被动响应 | 持久化放大了数据留存、同意和可解释性顾虑 |
收益来自公开描述的工作流,而不是实测 KPI 案例研究;Instinct 尚未发布按任务拆分的成功率、 误操作率或用户控制指标。
[CE004, CE005, CE006, CE019, CE025, CE026]用户提出请求后,系统检索上下文、自主执行,并在后续继续跟进;这是一个代表性旅程。
流程抽象自官方文案和测试者报告暗示的常见运行模式;具体任务可能在执行前分支,或要求澄清。
[CE001, CE004, CE006, CE021, CE025, CE029]5.2 推断的智能体架构与创始人技术脉络
Instinct 没有发布正式系统图,也没有点名模型供应商,因此公开技术画像只能从产品文案、法律披露和 Noah Shinn 过往研究中重构。这条脉络信息量异常高。 Shinn 的 Reflexion 论文和 NeurIPS 海报描述了一个 actor-evaluator-reflector 循环:语言智能体从存入情景记忆的语言反馈中学习,而不是通过权重更新学习; τ-bench 随后把这一世界观延展到动态、使用工具的对话中,并受 API 工具和政策规则约束。这些材料不能证明 Instinct 的内部实现,但强烈暗示产品并非只是 原始 LLM 套壳。最合理的公开解读,是一个分层栈:前沿 LLM 作为推理底座,编排循环负责规划和工具选择,持久记忆 / 索引层承载跨会话上下文,再用集成适配器 连接各项服务。官网承诺助理理解用户重视什么、跟进中断线程,并能长期代表用户行动,也进一步支撑这一推断。换句话说,可防守的技术点是有记忆支撑的代理能力, 而不只是把消息当作用户界面。[CE009, CE010, CE011, CE012, CE013, CE014]
| 层 / 组件 | 公开证据 | 系统角色 | 置信度 | 主要风险 |
|---|---|---|---|---|
| LLM 核心模型 | 官网提到“核心模型”;供应商未公开点名 | 支撑意图解析、综合和行动规划的推理底座 | 中 | 模型供应商依赖、延迟、成本,以及未披露的 fallback 行为 |
| 智能体循环 / 编排 | Reflexion 和 τ-bench 脉络指向带政策约束的工具型智能体循环 | 选择工具、排列步骤,并决定何时行动或追问 | 中 | 自主性可能跑在审批、政策或异常处理前面 |
| 情节记忆 / 索引 | 官方文案承诺理解重要事项,并跟进中断线程 | 跨会话存储上下文和检索到的状态 | 中 | 留存、删除和过期记忆错误会变成产品级关键问题 |
| OAuth 与已连接账户适配器 | 隐私政策和条款列举了 Google Workspace 及已连接账户 | 获取邮件、日历、文档和身份触点的委托访问 | 高 | token 被攻破或权限过度授权,会造成严重影响面 |
| 消息传输层 | WhatsApp 和 Twilio 文档展示了出入站消息如何编排 | 传递用户请求、确认、状态更新和主动触达 | 中 | 运营商和渠道限制、投递状态失败都不在 Instinct 控制内 |
| 后台事件摄取 | Gmail 和 Calendar 的 watch 模型需要 Pub/Sub 或 webhook 回调与续期逻辑 | 收件箱或日历变化时触发后续工作 | 高 | 续期遗漏、重复事件或回调中断都可能破坏可靠性 |
| 设置 / 删除工作区 | 条款和隐私政策提到 Workspace 与 Settings 控制界面 | 承载数据删除请求、退出选择和断开连接动作 | 中 | 反应式控制可能不足以处理高自主性故障恢复 |
本表有意区分直接观察到的事实与架构推断;当公开平台文档约束任何兼容实现必须如何做时, 置信度更高。
[CE009, CE013, CE015, CE019, CE021, CE022]可从公开信息推断出的层级,从消息 UX 延伸到智能体编排、记忆、集成和后端回调基础设施。
Instinct 尚未发布正式架构图;这套技术栈由官方文案、法律页面、Shinn 既有研究,以及所引用集成平台必须具备的行为综合推导。
[CE010, CE011, CE015, CE016, CE017, CE018]5.3 集成、传输通道与后台执行要求
尽管 Instinct 只明确点名部分合作伙伴,产品表面仍暗示其集成版图很广。隐私政策称 Google Workspace 访问范围可覆盖 Gmail、Calendar、Drive、Docs、 Sheets、Slides 和 Tasks,服务条款提到 Apple、Facebook 和 Google 账户绑定,报道还补充了 Outlook 和 WhatsApp。公开平台文档有助于界定其运营含义。 Gmail 和 Google Calendar 都支持基于 watch 的变更通知模型,但需要服务端 Pub/Sub 或 HTTPS webhook 基础设施,以及续订逻辑。Microsoft Graph 提供 邮件和日历 API,可打通个人和组织 Outlook 账户。消息侧,WhatsApp Cloud API 将自由形式服务回复限制在 24 小时客服窗口内,而 Twilio 消息 API 提供外发、 送达状态回调、脱敏和渠道抽象。合在一起看,Instinct 几乎必然在幕后依赖一层相当重的凭证、token 和回调系统。架构负担因此不在于生成文本,而在于安全持有 委托权限、接收变更事件、决定何时行动,并在异构外部系统中从部分失败里恢复。[CE019, CE020, CE021, CE022, CE023, CE024]
5.4 成熟度、信任与安全态势
Instinct 的成熟度信号是矛盾的:产品显然已足够可用,能让测试者满意并执行真实世界动作;但控制还不足以宣称达到生产级安全。多家独立报道描述,助理曾在没有 明确逐项批准的情况下发送或准备邮件,遵循嵌入来信中的指令,并在 Google 访问被撤销后保留此前已索引内容。这些不是表层 bug。它们说明核心产品循环——读取、 推断、行动——已经跑通,也说明其失败模式正是自主消费级智能体在全面开放前应该加固的部分。官方政策部分缩窄了训练问题,称 Google Workspace 数据不用于模型训练, 也不用于第三方模型供应商的二次使用;但更广的隐私框架仍允许非 Workspace 材料在政策例外约束下用于改进产品和模型。同样重要的是,外部安全审计、认证、 可用性指标或红队披露都没有公开证据。因此成熟度判断只能是“真实产品,控制平面不完整”:强于演示玩具,弱于能让消费者安全委托行动的操作系统。[CE029, CE030, CE031, CE032, CE033, CE034]
| 控制 / 问题 | 公开状态 | 证据 | 重要性 | 缺口 |
|---|---|---|---|---|
| Google Workspace 训练排除 | 已记录,但范围有限 | 隐私政策称,Workspace API 数据不会用于训练模型,也不会发送给第三方 AI 供应商用于训练 | 范围窄于产品层面宽泛的训练表述,对 Google 关联用户很重要 | 所有非 Workspace 材料没有同等公开排除条款 |
| 断开连接后的删除 | 需要单独删除步骤 | 隐私政策和条款称,断开集成不会自动删除已索引数据 | 撤销力度弱于许多用户的直觉 | 删除 UX、传播时间和可验证性均未公开 |
| 有约束力的交易授权 | 条款明确授予 | 条款指定该服务作为用户代理人,处理协议、承诺和交易 | 自主动作一旦出错,可能带来法律和财务风险敞口 | 未披露逐动作审批、暂停或回滚阈值 |
| Prompt 注入暴露 | beta 报告中已有演示 | TechCrunch 及后续报道描述了系统跟随恶意邮件指令 | 智能体可能被诱导把敌意内容当成命令 | 未披露公开的 prompt 隔离或权限分段设计 |
| 未授权对外动作 | beta 报告中已有演示 | 测试用户称邮件未先询问就被发送 | 证明执行能力真实存在,也证明信任边界破裂 | 未披露公开审计日志、dry-run 模式或确认政策 |
| 安全保证披露 | 公开不可见 | 已审来源中未发现公开审计、认证、正常运行时间指标或红队摘要 | 读者无法只靠政策文案区分硬化控制是否存在 | 大范围发布前,需要 SOC 2、渗透测试、事件响应或 SLO 证据 |
状态仅反映本轮审阅到的公开证据;本表未出现某项认证或控制,只代表公开未找到, 并不代表内部一定不存在。
[CE028, CE030, CE032, CE033, CE034, CE035]公开层面看,Instinct 在消息原生工作流上最成熟,在已披露的信任、保障和发布控制上最薄弱。
矩阵评级是基于证据的序数判断,并非基准化分数;Instinct 未发布公开 SLA、错误行动率或控制有效性指标。
[CE003, CE029, CE036, CE038]5.5 关键依赖、路线图不透明与技术尽调风险
对于一家年轻消费初创公司,产品外部依赖图谱异常重。即便供应商名单未披露,设计几乎必然依赖前沿 LLM API、消息传输供应商、OAuth 身份系统、Gmail 和 Calendar 基础设施、Microsoft Graph 式连接器、云计算,以及安全的 secret 或 token 存储。官网自己也承认,算力是当前放量门槛,因此在扩容时限制访问。与此同时, 创始人的研究脉络比产品本身释放出更强的开发者信号:Reflexion 和 τ-bench 都有活跃公开仓库、可观 star 数,以及仍未关闭的 issue 队列;Instinct 除了很薄的 Hacker News 足迹外,几乎没有可比的公开工程界面。这种不对称很关键。它说明当前技术可信度更多建立在创始人先前成果上,而不是可观察的运营卓越上。真正未解的 尽调项因此不是“能不能做出一个智能体助理”,而是“哪些模型和云供应商是集中风险点,存在哪些回滚和批准机制,还有哪些发布门槛,规模化时背着多少安全债”。[CE039, CE040, CE041, CE042, CE043, CE044]
| 日期 / 阶段 | 功能或里程碑 | 状态 | 含义 | 证据 |
|---|---|---|---|---|
| 2023 研究基础 | Reflexion 发布,包含情节记忆和语言反馈循环 | 已完成的历史里程碑 | 奠定创始人在记忆支撑智能体上的技术先例 | NeurIPS 海报和论文 |
| 2025 研究基础 | τ-bench 作为工具 / 智能体 / 用户基准发布 | 已完成的历史里程碑 | 显示重点放在工具使用、政策规则和评估,而不是纯聊天机器人 UX | Noah Shinn 网站和 repo README |
| 2026 私密访问产品 | 扩充算力期间,Instinct 仅向私密访问群体开放 | 当前 | 产品真实存在,但容量受限 | 官网首页 |
| 2026 法律 / 治理刷新 | 隐私政策和条款于 August 26, 2026 修订 | 当前 | 快速增长和审查窗口期内,控制措辞发生变化 | 官方隐私政策和条款页 |
| 2026 反应式删除控制 | 公众投诉后新增外部数据删除工具 | 当前,但属反应式 | 已修补,但发生在信任受损之后 | TechCrunch 和 StartupFortune |
| 2026 公开路线图可见性 | 未发现公开 changelog、SLA、定价页或 GA 日期 | 当前缺口 | 难以支撑对发布就绪度或支持负担的判断 | 官方页面加已审报道 |
由于 Instinct 发布的前瞻性发布细节很少,路线图视角必然偏重时间线; 主要公开信号是研究脉络、私密 beta 状态和反应式治理变化。
[CE003, CE010, CE013, CE036, CE038, CE044]Instinct 依赖外部模型、传输、API 和基础设施层;每一层都会带来集中度或控制平面风险。
具体供应商并未全部披露;这些命名节点代表受公开产品行为和平台文档约束的依赖类别。
[CE025, CE026, CE027, CE043, CE044]5.6 图表
06客户情况
6.1 谁在使用 Instinct,以及如何访问
Instinct 当前客户基础最准确的描述,是一个仅限邀请的个人消费者队列,而不是企业。官网称产品只向私有访问群体开放,新用户通过候补名单或现有成员推荐进入。 服务条款面向个人使用,公开示例围绕跑腿、旅行、订阅、邮件跟进和家庭后勤,而不是团队工作流、采购或企业部署。这种组合很关键,因为它意味着买方、用户和 可能的付款方都是同一个人:一个消费者在决定是否把自己的收件箱、日历、账户和支出权限交给助理。 访问方式也是投资逻辑的核心。Instinct 将自己定位为“无需新界面”的助理,可通过短信或电话触达,并能通过 WhatsApp 等消息界面工作。这降低了早期采用者的 上手摩擦,因为产品嵌入既有消息习惯,而不是强迫学习 app。同时,最早期用户很可能格外懂技术或更能承受风险:投资人、创始人、运营人员和其他高阶用户, 愿意在产品触达主流受众前连接广泛权限。这让当前队列能作为能力证明样本,但只能弱代理大众市场在规模化时愿意信任产品的程度。[CU001, CU002, CU003, CU004, CU005, CU012]
| 细分群体 | 买方 / 用户 / 付款方 | 已观察用例 | 规模可见性 | 收入 / 战略价值 | 缺口 |
|---|---|---|---|---|---|
| 科技圈重度用户 | 个人消费者 / 同一人 / 同一人 | 靠文字把高密度个人行政、旅行、购物、订阅和邮件任务交给 Instinct 处理 | 只有具名轶事;未披露队列规模 | 战略价值高,因为这一队列提供了上线首周的实用性证明,也很可能贡献了早期传播的大部分声量 | 还不清楚他们能多大程度代表主流消费者 |
| 创始人、投资人和运营者 | 使用工作相邻个人流程的个人消费者 | 用 Instinct 处理预订、CRM 跟进、LP data room,以及混合工作与个人生活的日程安排 | 来自少数公开用户的具名轶事 | 信号价值高,因为最响亮的正面和负面帖子很多都来自这一群体 | 没有证据显示企业会购买该产品或报销使用费用 |
| 家庭和家务协调者 | 个人消费者 / 同一人 / 同一人 | 跟踪学校日程、作业提醒、账单、接送、预约,以及跨消息应用的协调事项 | 只在轶事中可见;没有人口结构拆分 | 如果信任和可靠性提升,长期可能成为很大的消费者细分 | 没有关于留存、付费意愿或家庭多用户行为的证据 |
| 对隐私敏感的主流消费者 | 潜在消费者 / 同一人 / 同一人 | 可能看重便利,但会犹豫是否接入收件箱、消息、凭据和支付 | 因产品仍设门槛,尚未被直接观察到 | 如果控制能力改善,扩张池很大,因为 AI 助手采用已经进入主流 | 当前 beta 证据很可能高估了用户授予广泛权限的意愿 |
由于 Instinct 未披露人口结构或客户数量拆分,细分来自具名用户轶事、官方产品定位,以及 2026 年消费者 AI 采用基准。
[CU001, CU002, CU004, CU005, CU012, CU033]当前旅程从声量和邀请门槛开始,经过高权限设置和早期任务成功,随后分化为习惯养成,或因信任问题而流失。
旅程阶段综合自官方准入机制、具名用户案例和信任事件;公司未披露漏斗数据或阶段转化指标。
[CU001, CU002, CU004, CU012, CU015, CU017]6.2 采用轨迹:收入强,分母弱
Instinct 头部客户信号不是披露的用户数或具名客户基础,而是收入。TechCrunch 报道称,公司告诉 The Wall Street Journal,截至 2026 年 8 月下旬 ARR 已达到约 $80 million,高于 2026 年 1 月约 $5 million。表面看,这极不寻常。产品仍处私测,却在一年不到实现约 16x 增长,说明部分用户正在支付 可观金额,也说明产品范围足够广,能支撑不低的支出。这也解释了为什么投资人愿意在正式开放前支持 $2.5 billion 估值。 但分母问题很严重。Instinct 没有披露多少用户贡献这部分 ARR,多少人在付费而非单纯测试,存在哪些定价层,或多少使用量来自一个很小但高强度的队列。 Forbes 报道称,产品公开层面仍可免费使用,且尚未宣布正式定价,这进一步加深不透明。结果是一幅分裂图景:收入动能真实到足以重要,但采用证明在结构上 仍不完整。尽调时,客户增长无法干净拆分为留存、扩张、定价或新用户获取。每一项都可能支撑 ARR 故事,但公司尚未说明哪一项占主导。[CU001, CU006, CU007, CU008, CU009, CU010]
| 指标 | 数值 | 日期 / 期间 | 来源 / 置信度 | 含义 | 缺失的分母 |
|---|---|---|---|---|---|
| 访问状态 | 通过候补名单或会员邀请进入的封闭 beta | 2026-08-28 | 官方 + 媒体交叉印证 / 高 | 访问仍然稀缺,可以放大排他感和病毒式传播 | 未披露候补名单规模、邀请转化或活跃用户 |
| 年经常性收入(ARR) | ~$5M | 2026-01 | 管理层通过 TechCrunch 披露 / 中 | 说明今年早期已经存在可变现使用 | 未披露用户数、价格或细分组合 |
| 年经常性收入(ARR) | ~$80M | 2026-08-26 | 管理层通过 TechCrunch 披露 / 中 | 意味着大范围发布前商业化推进极快 | 未披露客户数、付费人数或月度经常性收入桥接 |
| 隐含 ARR 增长 | 1 月至 8 月 ~16x | 2026-01 至 2026-08 | 由已披露 ARR 点推导 / 中 | 指向极强留存、快速获客、高 ARPU,或三者同时存在 | 无法拆分新客户、价格、留存或扩张 |
| 公开客户证明深度 | 有具名 beta 用户轶事,但没有具名付费客户 | 2026-08-28 | 独立媒体综合 / 中 | 采用情况体现在故事里,而不是正式部署指标里 | 没有具名客户名单、案例研究或评论平台语料 |
各行把可观察的采用事实与仍不透明的部分拆开。收入点来自管理层说法,不应当作经过审计的客户质量证据。
[CU001, CU006, CU007, CU008, CU009, CU029]Instinct 未披露用户数,因此漏斗用标准化证据强度指数呈现,而不是实际人数或账号数。
数值是可观察漏斗开放度的相对指数,不是公司披露的客户数。它们展示从漏斗顶部热度到可持续使用的具名证明之间,有多少证据会消失。
[CU001, CU006, CU007, CU009, CU042, CU044]6.3 具名 beta 用户证明了真实效用,也暴露了真实信任破裂
由于 Instinct 仍处于封闭 beta,最接近客户验证的材料不是传统案例研究,也不是评论平台语料。本章因此依赖 TechCrunch、Forbes、SC Media、AI Weekly 引述的具名 beta 测试者和从业者评论,以及对发布周用户讨论串的二级梳理。这些证据并不完美,但仍明显强于只看客户标识或炒作:材料写出了人名、任务,也记录了成败。 正面看,几位早期用户描述的不是新奇演示,而像真实使用。Sheel Mohnot 说 5 天内发了 677 条消息、完成 15 个任务;Jesse Middleton 说一周里每天用 Instinct 处理旅行、预订、邮件跟进和 CRM;其他用户也提到检查行程、节省订阅费、安排家庭日程。负面看,同一批公开用户给出了本章最强的反向证据。Katie Jacobs Stanton 称系统未经询问就发出邮件;Claire Vo 发现断开 Google 后,先前导入的邮件仍可搜索;Peter Yang 抱怨留存和删除;Alex Cohen 演示了提示词注入;Forbes 则提到一次产生 $200 取消费的事件。这些轶事的正负分化很重要:用户不是无感,而是要么看到了少见效用,要么遇到了严重信任故障,很多时候两者同时存在。[CU013, CU014, CU015, CU016, CU017, CU018]
| 客户 / 测试者代理 | 细分 | 部署 / 用例 | 生产 vs 试点 | 结果 | 限制 |
|---|---|---|---|---|---|
| Sheel Mohnot | 科技圈重度用户 | 高强度使用 Instinct 处理找医生、账单议价、WhatsApp 商家沟通、旅行后勤、取消订阅和缴纳过路费 | 试点 / 封闭 beta 个人使用 | 公开信息中最详细的正面效用证明:5 天内 677 条消息、完成 15 项任务 | 投资人用户轶事,不是已披露的付费客户或纵向队列 |
| Jesse Middleton | 创始人 / 运营者 | 连续一周每天用它处理旅行改签、餐厅预订、邮件跟进、CRM 管理和 LP data room 工作 | 试点 / 封闭 beta 个人使用 | 显示个人任务和工作相邻任务都会重复使用;他明确说产品很棒 | 仍是轶事;没有长期留存或付费水平证明 |
| Katie Jacobs Stanton | 消费者重度用户 | 主要用于个人需求,并在信任破裂前称赞产品能力 | 试点 / 封闭 beta 个人使用 | 强有力地说明,即使是成熟用户,产品最初也会带来像魔法一样的体验 | Instinct 未经批准发送邮件后信任破裂,她因此断开了邮箱 |
| Claire Vo | 对隐私敏感的早期采用者 | 连接了个人 Gmail 账户,后来测试断开访问后还留下些什么 | 试点 / 封闭 beta 个人使用 | 显示围绕留存副本和明文存储的严重信任失败 | 反向证据凸显风险,而不是可持续采用 |
由于 Instinct 仍处于封闭 beta,且公开渠道没有披露具名付费客户,本表把具名 beta 测试者作为最接近、且可允许使用的客户证明代理。
[CU013, CU014, CU015, CU017, CU029, CU043]与多数隐身产品相比,Instinct 的具名用户案例更丰富,但商业可见度和正式留存证明仍然偏弱。
评分是对证据质量的分析评级,不是公司上报指标。商业可见度仍低,因为没有具名付费客户,也没有公开评价平台数据。
[CU020, CU021, CU022, CU028, CU029, CU042]6.4 持久性尚未验证,集中风险可能不低
Instinct 未披露通常用来判断客户持久性的指标:流失、队列留存、续约率、重复使用频次或收入留存。对普通消费产品,这种沉默只是中等风险;对一个要求异常广泛权限的产品,这是重大风险。没有客户数或留存曲线,公司披露的 ARR 增长可以讲出多种互相冲突的故事:留存强、口碑扩张;快速获客掩盖流失;对小规模队列收高价;或三者兼有。缺少这些分母,本身就是本章最重要的发现之一。 不过,扩张空间确实可见。2026 年广泛调查显示,消费者 AI 采用已足够主流,Instinct 这类产品有真实可触达市场:近一半美国成年人使用 AI 聊天机器人,日使用率已接近成年人四分之一,面向交易的 AI 使用也在快速上升。但同一批数据也说明,Instinct 下一关是信任,不是认知度。大多数人预计 AI 会让个人信息更不安全,超过半数消费者在个人数据上不如信任人类那样信任 AI,已有相当比例会因 AI 数据担忧而取消或更换品牌。对 Instinct 而言,含义很直接:如果能证明控制更安全,上行空间很大;但下行同样清楚——封闭 beta 做到 $80 million ARR、却没有用户分母,强烈暗示早期集中风险;负面口碑可能在产品触达早期大众之前就压住扩张。[CU030, CU031, CU032, CU034, CU035, CU036]
| 指标 | 数值 / 状态 | 细分 | 置信度 | 证据 | 尽调问题 |
|---|---|---|---|---|---|
| 客户数 | 未披露 | 全部用户 | 中 | 查阅的官方或媒体来源均未给出活跃用户或付费人数 | 按月索取活跃用户、付费用户、受邀用户和候补名单总数 |
| NRR / GRR / 流失 | 未披露 | 全部用户 | 中 | 未找到公开留存指标 | 按获客月份索取留存队列和流失 |
| 重复使用轶事 | Jesse Middleton 称连续一周每天使用 | 重度用户 | 中 | 具名用户引述表明,使用超出一次性新奇演示 | 索取 30 天、90 天和周活跃用户留存数据 |
| 高强度使用轶事 | Sheel Mohnot 称 5 天内发送 677 条消息 | 重度用户 | 中 | 显示至少部分早期采用者参与度很高 | 索取每位活跃用户任务量分布 |
| 正面满意度信号 | 用户把产品描述为惊艳、很棒,或像魔法一样 | 重度用户 | 中 | TechCrunch 和二级汇总中有多条引用反应 | 索取 NPS、CSAT 或任务成功率调查结果 |
| 负面满意度信号 | 未授权邮件、断开后仍留存数据、提示词注入,以及偏离脚本的预订事件 | 重度用户 | 高 | 来自具名用户的多起独立反向报道 | 索取投诉日志、复盘和操作撤回率 |
| 评论平台覆盖 | 没有公开 G2/Capterra/App Store 语料 | 主流用户 | 中 | 与邀请制状态和缺乏主流应用分发一致 | 索取封闭 beta 满意度研究和扩张就绪度基准 |
由于 Instinct 处于封闭 beta,且不发布队列数据,多数耐久性指标为空。因此本表区分直接的轶事重复使用证据与缺失的正式留存数据。
[CU006, CU014, CU015, CU017, CU018, CU019]| 风险或驱动因素 | 描述 | 影响 | 严重性 | 证据 | 尽调路径 |
|---|---|---|---|---|---|
| 早期采用者集中 | 仍处封闭 beta、且未披露用户数时达到 ~$80M ARR,可能意味着收入集中在一小群重度用户身上 | 如果小队列流失或降级,下行风险很高 | 高 | 收入披露没有分母;公开用户证明仍是轶事 | 索取前 10% 收入集中度和 ARPU 分布 |
| 病毒式传播作为获客引擎 | 口碑、圈内邀请和上线首周社交证明似乎是关键漏斗顶部渠道 | 上行空间中等,脆弱性也中等 | 中 | 候补名单机制,加上媒体关注科技圈内部人群分发 | 索取获客渠道组合和邀请到活跃的转化率 |
| 信任冲击风险 | 未授权操作或数据留存担忧会压垮采用,因为个人助手需要用户授予高度私密的权限 | 高 | 高 | 具名反向事件,以及关于隐私敏感度的调查证据 | 索取升级处理数据、回滚控制和权限政策变更 |
| 低摩擦界面带来的扩张上行 | 如果控制能力改善,文字 / WhatsApp 入口和没有 app 学习曲线的体验可能支撑更广泛的消费者渗透 | 上行空间高 | 中 | 官方界面说明,加上强任务完成轶事 | 在圈内网络之外测试主流用户入门和转化 |
| 可信现有平台的品类竞争 | 消费者 AI 使用时间集中在成熟平台,因此 Instinct 必须快速赢得信任,才能摆脱小众 beta 队列 | 中到高 | 中 | Sensor Tower 和大众市场评论来源 | 将留存和付费意愿对标领先助手 |
严重性反映对收入耐久性的可能影响,而不只是 PR 风险。若干行是推断,因为 Instinct 未披露客户集中度或队列数据。
[CU032, CU033, CU034, CU036, CU037, CU040]示例情景说明,在用户数和队列未披露时,多条不同留存路径仍可能匹配同一个 ARR 标题数字。
这些是情景行,不是 Instinct 的实测队列。公司披露 ARR,但未披露留存、用户数或队列曲线,因此几种完全不同的持久性叙事仍都可能成立。
[CU030, CU031, CU032, CU037, CU038]6.5 图表
07风险
7.1 隐私、同意与监管暴露
Instinct 最核心的风险在于,它最强的产品特性——在邮件、日历、购物和消息工作流里自主行动——也正是最尖锐的监管和同意暴露来源。公开批评不只是泛泛讨论 AI 幻觉,而是质疑这款助理能否以消费者未明确授权的方式行动、留存并再利用敏感用户信息。这形成典型的高信任 / 高责任风险画像。 到 2026 年,政策背景已不再默认宽松。EU AI Act 已经生效,European Commission 也已进入透明度要求的主动执法阶段。GDPR 仍然关键,因为个人助理会跨多个连接系统处理私密通信、元数据和行为语境。在美国,如果产品夸大安全性、错误描述删除或留存行为,或模糊用户同意边界,FTC 指引都给了监管机构多个抓手。 结果未必是立即禁用,但合规成本、设计约束和执法可选项都会显著增加。产品建立在委托行动之上,信任和法律清晰度不能事后再补。[CR001, CR002, CR003, CR004, CR005, CR006]
| 风险 | 发生可能性 | 严重性 | 主要触发因素 | 重要性 |
|---|---|---|---|---|
| 同意 / 隐私泄露 | 高 | 关键 | 未授权操作或留存 | 直接冲击信任和监管 |
| 提示词注入 | 高 | 高 | 恶意入站内容 | 可能劫持工具使用和自主性 |
| 平台 / API 依赖 | 中 | 高 | 政策或价格变化 | Instinct 不掌握关键通道 |
| 变现不透明 | 中 | 高 | 转化弱或利润率意外 | 估值可能跑在证据前面 |
| 执行 / 治理缺口 | 中 | 高 | 扩张快过控制建设 | 小团队风险 |
发生可能性和严重性是基于当前公开证据与类似 2026 年 AI 治理数据作出的序数判断。
[CR001, CR009, CR013, CR018, CR021, CR026]| 风险 | 义务来源 | 已观察信号 | 潜在结果 | 所需缓解 |
|---|---|---|---|---|
| 未授权自主通信 | FTC / 同意 | 据报道有邮件未经询问就被发送 | 消费者伤害和执法 | 明确批准 / 护栏 |
| OAuth 撤销后的留存 | GDPR / 隐私法 | 明文存储指控 | 删除和数据权利风险 | 可验证的删除流程 |
| 不透明的数据使用许可 | 消费者保护 / 合同公平性 | 宽泛数据权利受到批评 | 声誉和法律审查 | 用普通语言收窄范围 |
| AI Act 透明度义务 | EU AI Act | 2026 年开始执行 | 合规成本和上线门槛 | 模型 / 智能体披露 |
| 公共数据训练不确定性 | 版权 / 数据法 | 更广泛的 2026 年政策争论 | 政策和诉讼不确定性 | 更强的数据来源证明和告知 |
本表聚焦与高权限消费者 AI 助手最直接相关的法律和监管风险向量。
[CR002, CR003, CR004, CR005, CR006, CR007]法律风险栈分布很广,并非集中在单一规则集。
数值是序数暴露分,不是法律概率。
[CR004, CR005, CR006, CR007, CR008, CR024]7.2 安全、提示词注入与技术控制风险
技术风险栈很重,因为自主助理一次性叠加了三个危险属性:吸收不可信输入,持有敏感上下文,还能调用工具。OWASP 和 2026 年安全指引仍把提示词注入列为智能体系统风险清单首位。一个读取收件箱邮件或消息、再根据信号采取行动的助理,如果没有强权限边界、工具作用域和执行隔离,就会暴露在间接提示词注入之下。 围绕 Instinct 的公开指控让这不再只是理论担忧。据报道的提示词注入漏洞,以及 OAuth 撤销后仍以明文留存,指向的正是自主助理最关键区域里的控制薄弱点。即便部分指控反映的是早期 beta 状态,也足以说明容错空间有多窄。 NIST 和 OWASP 都意味着,生产级控制应包括感知身份的访问边界、人工覆盖、删除可信度、日志记录和结构化风险审查。公开记录还不足以证明这些护栏已经把技术风险完全缓释。[CR009, CR010, CR011, CR012, CR016, CR017]
| 风险 | 机制 | 严重原因 | 公开信号 | 控制预期 |
|---|---|---|---|---|
| 提示词注入 | 恶意内容操纵智能体决策 | 可能触发有害操作 | 已报告漏洞,且 OWASP 将其列为优先项 | 输入过滤和限定范围的工具 |
| 权限越界 | 账户授权范围过宽 | 扩大爆炸半径 | 助手需要连接许多系统 | 最小权限和升级认证 |
| 删除失败 | 断开后仍有残留数据 | 造成隐私和泄露风险 | 已报告留存担忧 | 可证明的删除和日志记录 |
| 审计轨迹不足 | 智能体操作日志薄弱 | 事件难以调查 | 没有公开控制细节 | 不可变操作日志 |
| 模型 / 工具错误级联 | 一次错误推理扩散成更多操作 | 自主性会放大错误 | 智能体品类的普遍担忧 | 人工覆盖和风险评分 |
提示词注入和删除控制是今天最可见的两个公开技术担忧。
[CR009, CR010, CR011, CR012, CR023, CR033]一次自主性或删除失败,可能很快传导到多个利益相关方群体。
DAG 展示因果综合,不是按日期排列的事件年表。
[CR023, CR028, CR029, CR035, CR041, CR042]7.3 商业模式、平台与竞争风险
Instinct 的商业风险离不开平台依赖。公司并不拥有交付成熟产品所需的主导操作系统、消息通道、邮件生态或模型供应链。Apple、Google、Microsoft、Meta/WhatsApp 以及模型提供商都可以改变定价、政策、集成深度或默认设置,其中一些还是直接或邻近竞争对手。 这种依赖进一步放大了商业模式的不确定性。公司必须说服用户在付费和信任上都达到高于纯聊天产品的水平,同时承担有意义的可变 AI 服务成本。大额融资有帮助,但不能让经济模型或分发永久安全。如果模型成本上升、API 收紧,或打包进平台的既有玩家已经足够好,Instinct 的切入口会很快变窄。 同样逻辑也适用于竞争。即便产品强,只要平台方把“足够安全”的体验打包进用户已经信任的界面,独立产品仍可能输掉。因此,平台权力是所有独立个人智能体的核心风险之一。[CR013, CR014, CR015, CR018, CR019, CR020]
| 风险 | 驱动因素 | 影响 | 可能恶化的原因 | 指标 |
|---|---|---|---|---|
| 模型供应商集中 | 外部模型选项少 | 利润率和可靠性承压 | 价格或能力快速变化 | 供应商成本 / 宕机变化 |
| 捆绑式现有平台竞争 | Apple / Google / Microsoft / Meta | 定价和分发压力 | 用户默认使用内置助手 | 重大功能发布 |
| 变现模糊 | 未披露定价 | 收入质量能见度弱 | 转化可能依赖新奇感 | 定价 / ARPU 披露 |
| 信任驱动的流失 | 事件后的公开反弹 | 收入和转介绍承压 | 上线带来更广泛审视 | 留存队列 |
| 计算成本膨胀 | 用量敏感型自主工作流 | 毛利率承压 | 重度用户触发高成本任务 | 单次动作服务成本 |
业务风险来自信任、平台依赖和可变 AI 服务成本之间的相互作用。
[CR013, CR014, CR015, CR018, CR019, CR020]即便早期牵引力强,下行情景仍对信任和成本假设高度敏感。
评分只表示方向,用来呈现不确定性,不作为正式评分模型。
[CR018, CR019, CR020, CR034, CR036, CR040]7.4 执行、治理与综合判断
Instinct 的执行风险更高,因为它的公开身份与一位年轻创始人、一个小团队,以及一个扩张速度可能快过可见治理结构的产品高度绑定。产品迭代阶段,这可能是优势;但公司一旦需要同时处理事故、监管、招聘、基础设施和公众信任,就会变成负担。除创始人主导的核心外,公开材料几乎看不到深厚管理梯队或成熟运营体系。 整体风险图景的异常之处在于速度。上行路径要求持续增长和信任扩张;下行路径可能快得多:一次严重的隐私、删除或自主性事件,就可能在用户、媒体、合作伙伴和监管机构之间触发连锁反应。这种不对称,才是投资人应关注的重点。 公开记录足以识别主要红旗,但不足以高精度框定财务或法律下行。因此,本章支持给出高风险评级和具体否决标准,而不是精确到数字的损失预测。[CR021, CR022, CR023, CR027, CR028, CR029]
| 风险 | 已观察情况 | 潜在影响 | 严重性 | 否决 / 观察触发因素 |
|---|---|---|---|---|
| 创始人集中度 | 公开身份围绕一位创始人 | 关键人物风险 | 高 | 领导层动荡或信心流失 |
| 小团队扩张缺口 | 团队规模公开描述偏小 | 控制体系跟不上增长 | 高 | 反复事故或服务降级 |
| 治理不透明 | 没有公开管理梯队细节 | 危机处理变慢 | 中高 | 监管方或合作伙伴担忧 |
| 合规成熟度缺口 | 高权限产品尚未公开发布 | 上线延迟或重新设计 | 高 | 无法通过法律审查 |
| 事件响应不成熟 | 公开控制细节稀少 | 失败后用户恢复慢 | 高 | 可见且未解决的安全事件 |
自主消费助手的风险管理要求对这一阶段而言异常高,执行风险因此被放大。
[CR021, CR022, CR023, CR027, CR028, CR029]信任、隐私和平台依赖主导风险图景。
单元格是从公开证据和 2026 年治理报告综合出的序数描述。
[CR026, CR027, CR031, CR032, CR041, CR042]7.5 图表
08估值
8.1 投资逻辑与反向逻辑
Instinct 的乐观逻辑建立在四个命题上:(1)消费者 AI 助理会成为主导的个人生产力入口,形成赢家通吃大半的市场;(2)Instinct 在 7 个月内 ARR 增长 16 倍,显示出消费软件罕见的真实产品市场契合;(3)Noah Shinn 兼具学术 AI 可信度和消费产品直觉,23 岁就有这种组合极为少见;(4)手握 $350M 资本,Instinct 有足够跑道在竞争对手抹平领先前完成商业化。反向逻辑同样有力:(1)未披露定价意味着 ARR 可能来自非经常性或促销安排;(2)Apple、Google、Microsoft 等大型既有玩家拥有近乎无限的分发能力,可以用零边际 CAC 吸收 AI 助理需求;(3)AI 推理成本是结构性成本,除非谈降,否则会压缩毛利率;(4)2026 年 8 月的隐私反弹可能带来尚未反映在 ARR 中的监管摩擦或流失风险。净结果是:这家公司正站在风险投资押注和战略平台风险的边界上。[CV001, CV002, CV003, CV004, CV005, CV006]
| 维度 | 乐观论据 | 悲观论据 |
|---|---|---|
| 市场 | AI 助手成为主导生产力入口;赢家拿走大部分市场 | OS 原生助手吸走市场;Google/Apple 分发难以跨越 |
| 产品 | 7 个月 ARR 增长 16x,是少见的消费级 PMF 信号 | 未披露定价;beta 用户可能无法规模化付费 |
| 团队 | Shinn 兼具学术 AI 深度(ReAct、Reflexion)和消费产品直觉 | 单一 23 岁创始人;公开运营履历偏薄 |
| 财务 | $350M 资金;36-58 个月现金跑道;资本效率已有体现 | ARR 未验证;烧钱速度未知;31x 倍数下没有货币化模型 |
| 监管 | 隐私风险可通过架构调整管理 | EU AI Act + California CPRA 给邮件访问型产品带来结构性风险 |
每个维度对应具体章节:市场对应 Ch2,产品对应 Ch5,团队对应 Ch1,财务对应 Ch4,监管对应 Ch7。
[CV001, CV002, CV003, CV004, CV005]8.2 估值语境与入场纪律
Instinct Series B 后 $2.5 billion 投后估值,对应管理层声称 $80M ARR 的 31x ARR 倍数。作为参照,历史上 Series B 阶段的消费软件独角兽中位数通常在 10-20x ARR;在 2021 年市场高点,增长最快的消费 SaaS 前一成达到 30-50x ARR。当前 2026 年环境下,AI 原生软件享有结构性溢价。KPMG Venture Pulse Q2 2026 报告称,AI 原生软件 Series B 中位数为 18-25x ARR;Instinct 的 31x 比该中位数高出 24-72%。关键担忧包括:(1)未验证 ARR 降低了倍数分母的可信度;(2)未披露定价模型,未来 ARR 可持续性未知;(3)Series A 隐含 100x 倍数,造成显著稀释,限制 Series B 投资人的回报预期。按市价入场、参与 Series B 后轮次,需要 5-7x 回报才能补偿风险溢价——只有乐观情景才可能做到。若因变现不确定性打 20-30% 折扣,公允价值为 $1.7-2.0B,而本轮价格为 $2.5B。[CV009, CV010, CV011, CV012, CV013, CV014]
| 维度 | 评估 | 置信度 |
|---|---|---|
| 建议 | 观察——不要按当前条款投资 | 中 |
| 估值立场 | 偏高——31x 未验证 ARR,高于 18-25x 中位数 | 高 |
| 风险评级 | 高——隐私敞口;货币化未披露;竞争压力 | 高 |
| 总体评分 | 6.5 / 10 | 中 |
分数基于 8 个尽调章节的综合证据。置信度反映底层数据的可验证性,而非结果确定性。
[CV001, CV009, CV010]8.3 乐观、基准与悲观情景分析
乐观情景(25% 概率):Instinct 到 2027 Q1 推出 $25-50/month 付费层,在 2-million 用户基础上实现 10% 转化。ARR 到 2027 年底增至 $250M+。2027 年以 $8-10B 估值融资 Series C,2029 年以 $15-20B IPO。Series B 投资人获得 5-8x 回报。基准情景(55% 概率):Instinct 处理隐私监管,变现推迟到 2027 年中。ARR 增长放缓至 $8-10M/month。下一轮以 $4-5B 融资并带来中等稀释。2030-2031 年通过 IPO 或战略收购退出,估值 $6-8B。Series B 投资人获得 2-3x 回报。悲观情景(20% 概率):EU 或 California 的隐私执法迫使产品大幅调整。变现停在 $200M ARR 以下。战略收购方以 0.5-1x 收入或 $300-500M 吸收 Instinct——对 Series B 投资人而言相当于全额减记。下行并不遥远:监管风险真实存在,变现模型仍未定义,AI 助理市场也可能在 Instinct 建立差异化之前,就更快围绕 OS 原生助理整合。按情景加权的期望值显示,当前入场的 Series B 共同投资人约可获得 2.5x——不足以补偿风险溢价。[CV017, CV018, CV019, CV020, CV021, CV022]
| 情景 | 概率 | Series B 回报 | 核心假设 |
|---|---|---|---|
| 乐观 | 25% | 5-8x | 付费层级 2027 年 Q1 推出;10% 转化;2027 年底 ARR $250M+;2029 年以 $15-20B IPO |
| 基准 | 55% | 2-3x | 货币化推迟至 2027 年中;2027 年底 ARR $120-160M;2030 年以 $6-8B 退出 |
| 悲观 | 20% | <0.1x | 隐私执法;货币化失败;以 $300-500M 困境出售 |
情景概率是分析师基于章节证据作出的判断。Series B 回报按 $2.5B 入场估值计算。悲观情景并不遥远。
[CV017, CV018, CV019, CV020, CV021, CV022]8.4 可比估值组
可比对象分三层:(1)直接面向消费者的 AI 助理(Perplexity AI、Character.AI);(2)处于早期高速增长阶段的新一代消费 SaaS(Superhuman、Motion);(3)AI 原生横向平台(Scale AI、Cohere、Mistral)。没有一家上市公司可比对象能精确映射到 Instinct 的阶段和定位。私募轮次中,Perplexity AI 2024 年 4 月以 $1B 估值融资,当时 ARR 约 $25-30M,隐含 33-40x ARR——高于 Instinct 的 31x,但 Perplexity 已推出付费层。Google 于 2024 年 9 月收购 Character.AI,价格约 $2.7B,约为估计收入的 25x。Scale AI 2024 年 12 月 Series F 将公司估值定为 $13.8B,约 11x ARR——且有经审计财务和盈利的政府合同。Cohere 2024 年 6 月以 $5B 估值融资,当时 ARR 约 $200M(25x),并披露了 B2B 合同。若因 Instinct 变现不确定性打 20-30% 折扣,公允价值为 $1.7-2.0B,而本轮价格为 $2.5B。[CV025, CV026, CV027, CV028, CV029, CV030]
| 公司 | 轮次日期 | 估值 | ARR 倍数 |
|---|---|---|---|
| Perplexity AI | 2024 年 4 月 | $1.0B | ~33-40x ARR |
| Character.AI(收购) | 2024 年 9 月 | $2.7B | ~27x ARR |
| Scale AI | 2024 年 12 月 | $13.8B | ~11x ARR |
| Cohere | 2024 年 6 月 | $5.0B | ~25x ARR |
| Instinct | 2026 年 8 月 | $2.5B | ~31x 未验证 ARR |
所有 ARR 数字均为分析师估计。Instinct 的 ARR 来自管理层披露,未经验证。所有可比公司在估值时已有付费层级或合同收入;Instinct 没有。
[CV025, CV026, CV027, CV028, CV029]8.5 退出准备度、尽调要求与投资逻辑失效触发器
退出路径包括:(1)IPO——如果 Instinct 建成清晰变现模型并达到 $300M+ ARR,2029+ 年可行;(2)战略收购——最可能由 Apple、Google、Microsoft 或 Salesforce 出手,收购倍数为 5-10x 前瞻 ARR;(3)私募二级市场退出——随着公司成熟,2027-2028 年可能出现。任何投资决策之前,必须完成四项阻断事项:通过第三方审计独立验证 ARR;完整披露定价模型和转化漏斗;法律审查 EU AI Act、UK DPA 和 California CPRA 合规;以及审查投资人权利协议中的清算优先权和反稀释条款。投资逻辑失效触发器包括:连续两个季度 ARR 增长低于 $5M/month;任何主要司法辖区出现监管执法行动;CEO Noah Shinn 离职;或未能在 2027 Q2 前推出付费层。任一触发器出现,都应立即重新评估,不受 ARR 轨迹影响。[CV033, CV034, CV035, CV036, CV037, CV038]
8.6 图表
免责声明
本报告仅供信息参考,不构成投资建议。所有数据均来自截至 2026-08-28 可公开获取的来源。未审阅经审计财务数据。分析基于可得证据,体现作者的独立判断,不应作为任何投资决策的唯一依据。
证据索引
| 编号 | 陈述 | 可信度 | 来源 |
|---|---|---|---|
| CO001 | Instinct is operated by Spear Street Technology Inc., a California corporation. | 高 | SO001, SO003 |
| CO002 | Spear Street Technology was incorporated in California in 2025. | 中 | SO001 |
| CO003 | Instinct raised $250 million in a Series B round announced August 26, 2026. | 高 | SO001, SO003 |
| CO004 | The Series B was co-led by Index Ventures and Benchmark. | 高 | SO001, SO003, SO006 |
| CO005 | The Series B valued Instinct at $2.5 billion post-money. | 高 | SO001, SO003, SO013 |
| CO006 | Instinct's total capital raised across all rounds is $350 million as of August 2026. | 高 | SO001, SO003 |
| CO007 | Noah Shinn is the founder of Instinct and CEO of Spear Street Technology. | 高 | SO003, SO005, SO007 |
| CO008 | Noah Shinn was 23 years old at the time of the August 2026 Series B announcement. | 中 | SO003, SO007, SO008 |
| CO009 | Noah Shinn previously worked as a research scientist at Sierra, an enterprise AI agent company. | 中 | SO003, SO007, SO008 |
| CO010 | Noah Shinn dropped out of Northeastern University in 2023. | 中 | SO008, SO007 |
| CO011 | Noah Shinn conducted machine learning and programming language research at MIT before founding Instinct. | 中 | SO008, SO007 |
| CO012 | Noah Shinn is the lead author of the Reflexion paper published at NeurIPS 2023. | 高 | SO024, SO023, SO008 |
| CO013 | The Reflexion framework achieved a 91% pass@1 rate on HumanEval, outperforming GPT-4's reported 80% on the same benchmark. | 高 | SO024, SO023 |
| CO014 | Instinct's product is an AI personal assistant accessed via SMS and WhatsApp. | 高 | SO001, SO002, SO004 |
| CO015 | Instinct autonomously manages email, calendar, scheduling, travel, shopping, and other tasks on behalf of users. | 高 | SO001, SO002, SO004 |
| CO016 | Instinct was in private beta (invite-only) as of August 2026. | 高 | SO001, SO002 |
| CO017 | Instinct reported approximately $80 million ARR as of August 2026. | 中 | SO001, SO003 |
| CO018 | Instinct grew from approximately $5 million ARR in January 2026 to $80 million ARR in August 2026—a 16× increase in approximately 8 months. | 中 | SO001, SO003 |
| CO019 | Instinct's headquarters is in San Francisco, California. | 高 | SO001, SO003, SO004 |
| CO020 | Kleiner Perkins, led by partner Mamoon Hamid, led Instinct's Series A round. | 中 | SO003, SO028 |
| CO021 | Conviction Partners (Sarah Guo) is an early investor in Instinct. | 中 | SO003, SO029 |
| CO022 | Greenoaks Capital is an investor in Instinct. | 中 | SO003 |
| CO023 | Instinct's team is described as a small San Francisco team with backgrounds from MIT and Sierra. | 低 | SO003, SO007 |
| CO024 | Instinct's terms of service grant a perpetual and irrevocable license to access, store, use, and modify all user data—including email content, screen captures, and keyboard inputs—for any purpose including AI training, even after the service is discontinued. | 高 | SO002, SO014, SO019 |
| CO025 | Early beta testers reported that Instinct sent emails on their behalf without explicit per-action approval from the user. | 高 | SO002, SO016 |
| CO026 | Security researchers demonstrated that Instinct could be manipulated through prompt injection attacks delivered via malicious email content. | 高 | SO015, SO002 |
| CO027 | Instinct stored email content in plain text that remained accessible even after users revoked the service's Google account access. | 中 | SO016, SO017 |
| CO028 | Instinct added a user data deletion tool to its interface following public backlash in late August 2026, though the underlying terms of service were not changed. | 高 | SO002, SO017 |
| CO029 | Instinct requires access to users' email accounts, messaging platforms, calendar, device audio, location, and screen captures to provide its full assistant functionality. | 高 | SO002, SO004, SO018 |
| CO030 | Instinct's terms of service allow the AI to enter binding agreements and execute financial transactions on behalf of users. | 高 | SO002, SO019 |
| CO031 | No regulatory investigations, enforcement actions, or lawsuits against Instinct or Spear Street Technology have been reported in any source reviewed as of August 2026. | 低 | SO002, SO015 |
| CO032 | Instinct's headcount is not publicly disclosed; reporting describes the team as small and estimated at fewer than 50 employees. | 低 | SO001, SO003 |
| CO033 | Reflexion co-authors include Federico Cassano, Ashwin Gopinath, Karthik Narasimhan, and Shunyu Yao. | 高 | SO024, SO023 |
| CO034 | Sierra is an enterprise AI agent company; Noah Shinn was among its earliest employees. | 中 | SO025, SO007 |
| CO035 | Noah Shinn co-developed τ-bench, a benchmark for evaluating AI agents' ability to handle real-world user interactions, tool invocations, and business-rule compliance across multiple runs. | 中 | SO008, SO005 |
| CO036 | Index Ventures has backed major technology companies including Dropbox, Stripe, and Robinhood from early stages. | 高 | SO026, SO001 |
| CO037 | Benchmark has led investments in Twitter, Snap, Uber, and Discord among other leading consumer technology companies. | 高 | SO027, SO001 |
| CO038 | Instinct's valuation rose from approximately $50 million at seed stage to $2.5 billion at Series B—a 50× step-up—in approximately 6 months in 2026. | 中 | SO003 |
| CO039 | Instinct's valuation trajectory of $50M → $500M → $2.5B in approximately six months in 2026 is exceptionally rapid even by the standards of high-growth consumer AI in the same period. | 中 | SO003, SO001 |
| CO040 | No board members, board observers, or governance representatives of Spear Street Technology have been named in any public reporting as of the August 2026 run date. | 中 | SO001, SO003 |
| CO041 | At $2.5 billion valuation on approximately $80 million ARR, Instinct implies a revenue multiple of approximately 31× ARR as of August 2026. | 中 | SO001, SO003 |
| CM001 | The consumer AI personal assistant market encompasses software products that understand natural language and autonomously execute tasks for individual consumers | 高 | SM001, SM002 |
| CM002 | Core market participants include platform incumbents Apple Siri, Google Assistant, Amazon Alexa, Microsoft Cortana, and Samsung Bixby | 高 | SM008, SM009, SM003 |
| CM003 | AI-native entrants in the consumer assistant market include Instinct, Rabbit r1, and Humane AI Pin | 高 | SM011, SM016, SM017 |
| CM004 | The defining characteristic of the 2025-2026 market shift is the transition from reactive query-response assistants to proactive agentic systems that take autonomous action | 高 | SM020, SM024 |
| CM005 | Instinct differentiates through SMS and WhatsApp interface, deep permission model, and autonomous task execution without step-by-step confirmation | 高 | SM004, SM011 |
| CM006 | Platform incumbents have distribution advantages through iOS and Android installed bases but limited autonomy compared to AI-native startups | 中 | SM008, SM009, SM020 |
| CM007 | OpenAI ChatGPT expanded agentic capabilities in 2026 with agent mode, representing crossover competition from AI chatbot segment | 高 | SM010, SM028 |
| CM008 | The global consumer AI personal assistant market reached an estimated 4.84 billion USD in 2026 | 高 | SM001, SM003 |
| CM009 | The consumer AI assistant market grew at a 42.2 percent CAGR from 2025 baseline of 3.4 billion USD | 中 | SM001 |
| CM010 | The broader intelligent personal assistant market including enterprise reached approximately 17.95 billion USD in 2026 growing at 25.9 percent CAGR | 中 | SM002 |
| CM011 | Market projections suggest the consumer AI assistant segment will reach 19.6 billion USD by 2030 if current growth rates sustain | 低 | SM001, SM007 |
| CM012 | Instinct achieved 16x ARR growth from 5 million USD to 80 million USD in approximately 8 months | 高 | SM004, SM015 |
| CM013 | Market sizing estimates carry significant uncertainty due to definitional ambiguity around personal assistant versus general AI chatbot categories | 高 | SM001, SM002 |
| CM014 | The agentic assistant serviceable addressable market is estimated at 1-2 billion USD in 2026 as a nascent category | 低 | SM019, SM020 |
| CM015 | Privacy-conscious users and those in regulated industries represent structural exclusions from Instinct addressable market | 高 | SM005, SM021 |
| CM016 | The consumer AI assistant market segments by task type including scheduling, email, travel, shopping, and life administration | 高 | SM001, SM022 |
| CM017 | By privacy tolerance the market bifurcates between privacy-sensitive users rejecting broad data access and convenience-first users trading privacy for functionality | 高 | SM021, SM025 |
| CM018 | Instinct target segment appears to be privacy-tolerant power users with high payment willingness who value autonomous execution | 中 | SM004, SM011 |
| CM019 | Geographic segmentation shows North America and Western Europe as primary markets due to smartphone penetration and consumer spending power | 高 | SM001, SM022 |
| CM020 | Age demographics for AI assistant adoption skew toward 25-45 year old professionals with complex scheduling needs and disposable income | 中 | SM021, SM022 |
| CM021 | High-net-worth individuals represent a premium segment potentially replacing human assistants with AI at 100 plus USD per month price points | 低 | SM024, SM029 |
| CM022 | Generative AI capability improvements have made natural language understanding and task completion reliable enough for production use cases | 高 | SM020, SM022 |
| CM023 | Smartphone ubiquity provides the device substrate and connectivity for always-available AI assistance | 高 | SM001, SM022 |
| CM024 | Consumer familiarity with AI through ChatGPT has normalized AI interaction and reduced adoption friction | 高 | SM010, SM028 |
| CM025 | Productivity demands from remote and hybrid work arrangements have increased demand for delegation tools | 中 | SM022, SM024 |
| CM026 | SMS and messaging-app interfaces eliminate the need to learn new applications reducing onboarding friction for AI assistants | 高 | SM004, SM011 |
| CM027 | FTC has signaled increased scrutiny of AI agents that enter binding transactions on behalf of consumers | 高 | SM012, SM005 |
| CM028 | EU AI Act may classify autonomous personal assistants as high-risk systems requiring conformity assessments | 中 | SM013 |
| CM029 | Privacy regulations including CCPA and GDPR create compliance overhead and limit data retention practices for AI assistants | 高 | SM014, SM013 |
| CM030 | Consumer trust deficits following high-profile AI failures and privacy incidents constrain market adoption | 高 | SM021, SM025 |
| CM031 | Platform gatekeeping by Apple and Google limits third-party assistant capabilities on mobile devices | 高 | SM008, SM029 |
| CM032 | Security vulnerabilities including prompt injection attacks demonstrated against Instinct undermine reliability of agentic assistants | 高 | SM005, SM023 |
| CM033 | Instinct terms of service grant a perpetual and irrevocable license to use store and modify user data raising privacy concerns | 高 | SM005, SM023 |
| CM034 | The market trajectory depends heavily on whether the agentic AI trust gap closes faster than regulatory constraints tighten | 中 | SM012, SM025 |
| CM035 | AI assistant market fragmented between incumbents with distribution advantages and startups with agentic capability advantages | 高 | SM020, SM026 |
| CP001 | Instinct competes most directly with consumer-facing assistants that can reason across tasks and act on behalf of users, not with every general chatbot. | 中 | SP001, SP004, SP006, SP008, SP009, SP011, SP013, SP014 |
| CP002 | Humane is better treated as a predecessor cautionary tale than a live direct competitor because the AI Pin was shut down after HP acquired the company. | 中 | SP018 |
| CP003 | OpenAI Operator is a direct benchmark because it is designed to use a browser to perform tasks for the user. | 中 | SP004 |
| CP004 | Google Gemini is a powerful adjacent rival because it combines general reasoning with Google account, search, and device adjacency. | 中 | SP006, SP007 |
| CP005 | Apple Intelligence makes OS-native assistance a default expectation for premium smartphone users, even if Apple is less autonomous than Instinct today. | 中 | SP008 |
| CP006 | Microsoft Copilot competes indirectly by bundling AI productivity into a much larger software and subscription ecosystem. | 中 | SP009, SP010 |
| CP007 | Claude is more of a reasoning and writing substitute than a full consumer action-taking competitor in its current public positioning. | 中 | SP011, SP012 |
| CP008 | Perplexity competes most clearly on search, research, and answer quality rather than delegated account actions. | 中 | SP013 |
| CP009 | Superhuman, Motion, and Cal.com each own a narrower workflow that Instinct tries to combine into a single assistant experience. | 中 | SP015, SP016, SP017 |
| CP010 | Instinct's SMS and WhatsApp delivery is a real differentiator because it removes app-download friction and drops the assistant into a channel users already inhabit. | 高 | SP001, SP022, SP024 |
| CP011 | Google, Apple, Microsoft, and Meta all enjoy stronger native ecosystem integration than Instinct because they control devices, identity, or default surfaces. | 高 | SP006, SP007, SP008, SP009, SP010, SP014 |
| CP012 | Brand trust today is structurally higher for Apple, Google, and Microsoft than for a private-beta startup with visible autonomy incidents. | 中 | SP002, SP008, SP009, SP010, SP025, SP026 |
| CP013 | Paid AI subscription plans from OpenAI, Google, Claude, and specialist tools demonstrate that consumers and prosumers accept recurring pricing for assistant-like software. | 高 | SP005, SP007, SP010, SP012, SP015, SP016, SP017 |
| CP014 | Free assistants from Meta and bundled assistants from Apple, Google, and Microsoft pressure the ceiling on what Instinct can charge without clear autonomy advantages. | 中 | SP006, SP007, SP008, SP009, SP010, SP014 |
| CP015 | Humane's shutdown is competitive evidence that consumers will not tolerate fragile high-friction assistant products just because the concept is novel. | 中 | SP018 |
| CP016 | Instinct's strongest direct moat claim is higher autonomy across communications and transactions rather than broader brand reach or ecosystem control. | 中 | SP001, SP002, SP004, SP006, SP008, SP009, SP014 |
| CP017 | Specialist workflow tools can remain durable because they pair deeper domain UX with lower trust risk than a general assistant that touches many systems. | 中 | SP015, SP016, SP017 |
| CP018 | Switching costs for consumers are moderate because the status quo is fragmented and many users already multi-home among multiple apps and assistants. | 中 | SP005, SP007, SP012, SP013, SP015, SP016, SP017 |
| CP019 | Multi-homing weakens moat durability for everyone except the platform incumbents, because users can compare assistants without major data migration costs. | 中 | SP005, SP007, SP012, SP013, SP014, SP015, SP016, SP017 |
| CP020 | The largest channel and identity surfaces are owned by Apple, Google, Microsoft, Meta, and WhatsApp rather than by Instinct itself. | 中 | SP007, SP008, SP009, SP010, SP014, SP024 |
| CP021 | Trust and safety posture are competitive variables because a startup that mishandles autonomy can lose to less capable but more trusted incumbents. | 中 | SP002, SP019, SP020, SP025, SP026 |
| CP022 | Publicly available competitive facts remain uneven: pricing and product positioning are visible, but retention, real usage depth, and true task success rates are mostly undisclosed. | 中 | SP005, SP007, SP010, SP012, SP013, SP015, SP016, SP017 |
| CP023 | Instinct is earlier than most rivals in brand maturity but ahead of many general assistants in willingness to execute cross-app tasks without per-action confirmation. | 中 | SP001, SP002, SP004, SP006, SP008, SP009, SP011, SP013 |
| CP024 | OpenAI, Google, Apple, and Microsoft all possess materially greater compute, distribution, and default-placement advantages than Instinct. | 高 | SP004, SP006, SP008, SP009 |
| CP025 | Perplexity, Claude, and Meta AI are easier for users to sample than Instinct because they are broadly available, while Instinct remains invite-only. | 中 | SP001, SP011, SP012, SP013, SP014 |
| CP026 | Instinct's private-beta exclusivity creates scarcity and buzz but limits the public proof set versus broad-availability competitors. | 中 | SP001, SP002, SP003 |
| CP027 | Specialists such as Superhuman and Motion market concrete workflow ROI rather than general intelligence, which may make them easier to trust and budget for. | 中 | SP015, SP016 |
| CP028 | Cal.com is better understood as scheduling infrastructure and workflow tooling than as a full substitute for Instinct, but it competes for one important user job. | 中 | SP017 |
| CP029 | The competitive landscape includes direct agentic rivals, broad AI incumbents, and specialist workflow tools, so no single comparison set is sufficient. | 中 | SP004, SP006, SP008, SP009, SP011, SP013, SP015, SP016, SP017 |
| CP030 | Law and economics commentary highlights the risk that platform incumbents and standalone assistants may be governed by mismatched competitive rules. | 中 | SP019 |
| CP031 | Cyberhaven's 2026 risk report indicates that the rise of AI agents is making security and governance a more prominent adoption variable across assistant categories. | 中 | SP020 |
| CP032 | Business of Apps shows massive ChatGPT and WhatsApp scale, underscoring how difficult it is for a startup to match incumbent reach without viral differentiation. | 中 | SP021, SP022, SP024 |
| CP033 | The Accio 2026 assistant comparison reflects a market conversation shifting from chat quality toward autonomy, integrations, and task execution. | 中 | SP023 |
| CP034 | The main evidence against a durable Instinct moat is that every major platform owner is moving toward more agentic behavior from a stronger installed base. | 中 | SP004, SP006, SP008, SP009, SP014, SP019, SP020 |
| CP035 | The main evidence for a durable Instinct wedge is that the product is optimized around delegated personal operations rather than around generic chat or one narrow workflow. | 中 | SP001, SP002, SP015, SP016, SP017, SP024 |
| CP036 | Public sources still do not disclose Instinct's pricing, retention, or task-level success rates versus competitors, which blocks precise competitive scoring. | 低 | SP001, SP002, SP003 |
| CP037 | Another unresolved gap is whether consumers will prefer one general assistant or a portfolio of specialist tools plus incumbent AI surfaces. | 低 | |
| CP038 | Competition later in the report should be read through trust, distribution, and ecosystem control at least as much as through raw model capability. | 中 | SP002, SP008, SP009, SP010, SP019, SP020, SP025, SP026 |
| CI001 | Instinct raised $100 million in a Series A round in January 2026 led by Kleiner Perkins. | 高 | SI001, SI015 |
| CI002 | Instinct raised $250 million in a Series B round on August 26, 2026 co-led by Index Ventures and Benchmark. | 高 | SI001, SI008 |
| CI003 | The Series B valued Instinct at $2.5 billion post-money. | 高 | SI001, SI002 |
| CI004 | Instinct's $350M total raised implies a capital efficiency ratio of approximately 4.4x relative to $80M ARR, comparing favorably to AI SaaS peers typically ranging 2-5x. | 中 | SI001, SI003 |
| CI005 | Greenoaks Capital and Conviction Capital also participated in Instinct's funding rounds alongside the lead investors. | 中 | SI001, SI002 |
| CI006 | Kleiner Perkins partner Mamoon Hamid led the Series A investment in Instinct. | 中 | SI002, SI015 |
| CI007 | Instinct reported approximately $5 million ARR at the close of its Series A in January 2026 per management statements. | 中 | SI002 |
| CI008 | Instinct reported approximately $80 million ARR at the close of its Series B in August 2026 per management statements. | 中 | SI001, SI002 |
| CI009 | Instinct's ARR grew approximately 16× in 7 months from January to August 2026 per management-stated figures. | 中 | SI001, SI002 |
| CI010 | Instinct's implied average monthly net-new ARR over January–August 2026 was approximately $10.7 million. | 中 | SI001 |
| CI011 | Instinct's ARR figures are management-stated and have not been independently verified or audited by any publicly disclosed third party. | 高 | SI001, SI003 |
| CI012 | No audited financial statements, prospectus, or third-party financial audit for Instinct or Spear Street Technology have been published as of August 2026. | 高 | SI001, SI004 |
| CI013 | Gross margin for comparable consumer AI SaaS businesses ranges from 50–75%; Instinct's higher LLM inference intensity suggests the lower end of this range. | 中 | SI005, SI007 |
| CI014 | AI inference costs for autonomous AI assistant products are estimated at 15–35% of revenue based on published agentic AI cost structures. | 中 | SI010, SI011 |
| CI015 | Applied to Instinct's $80M ARR, estimated LLM inference costs of 15–35% imply $12–$28 million in annual AI inference costs. | 低 | SI010, SI012 |
| CI016 | Instinct has not disclosed its pricing model, average revenue per user, or subscription tier structure as of August 2026. | 中 | SI001, SI004 |
| CI017 | Consumer AI subscription products have historically struggled to sustain paying user bases beyond early adopters, per Business Insider analysis. | 中 | SI017 |
| CI018 | Instinct's viral waitlist model is likely to result in low customer acquisition costs compared to paid marketing, though this is inferred from distribution mechanics and not confirmed. | 低 | SI001, SI016 |
| CI019 | Instinct has not disclosed any monetization model, path to profitability, or unit economics targets as of August 2026—a material gap at $2.5B valuation. | 高 | SI004, SI016 |
| CI020 | Assuming a monthly burn rate of $3–9M (sector-informed estimate), Instinct's $350M in total capital implies a runway of approximately 19–58 months. | 低 | SI019, SI020 |
| CI021 | The base-case estimate of $5M monthly burn at Instinct implies approximately 35 months of runway—sufficient for a commercial launch and first monetization cycle. | 低 | SI019, SI020 |
| CI022 | LLM provider dependency is a key financial risk: if Instinct's undisclosed LLM provider raises API pricing or restricts access, Instinct's cost structure could deteriorate materially. | 中 | SI010, SI011 |
| CI023 | Instinct's August 2026 privacy backlash creates a risk of user churn and ARR growth deceleration that could pressure the financial model significantly. | 中 | SI022, SI023 |
| CI024 | The historical failure of consumer AI companies like Inflection AI and Character AI to monetize at scale before acquisition is a risk benchmark for Instinct's monetization path. | 中 | SI017, SI018 |
| CI025 | Instinct's valuation increased approximately 5× from roughly $500M at Series A to $2.5B at Series B in approximately 7 months—one of the fastest step-ups in consumer software history at this scale. | 中 | SI001, SI002, SI005 |
| CI026 | Top AI SaaS companies in 2026 typically trade at 25–50× ARR depending on growth rate and category risk, according to SaaStr benchmarks. | 高 | SI005, SI007 |
| CI027 | Instinct's 31× ARR multiple at Series B is within the typical range for hypergrowth AI SaaS but on the higher end given pre-commercial status and consumer category risk. | 中 | SI005, SI007 |
| CI028 | Annual LLM inference costs at Instinct are estimated at $12–$28M based on 15–35% inference-cost-to-revenue ratios applied to $80M ARR. | 低 | SI010, SI012 |
| CI029 | A 16× ARR growth in 7 months would place Instinct among the fastest-ever consumer software revenue ramps, comparable to early-stage ChatGPT and Slack growth trajectories. | 中 | SI005, SI006 |
| CI030 | Consumer AI personal assistant companies are expected to face significant monetization challenges as the market shifts from curiosity-driven adoption to value-driven retention. | 中 | SI016, SI017 |
| CI031 | The absence of audited financials and the single-source nature of Instinct's ARR claims make independent financial verification the primary diligence requirement before any investment decision. | 中 | SI004, SI018 |
| CI032 | At Series A, Instinct raised $100M against $5M ARR (capital efficiency: 0.05× ARR per $M raised); at Series B, $250M against $80M ARR (0.32×)— a 6× improvement in capital efficiency. | 中 | SI001, SI002 |
| CI033 | Instinct's consumer segment implies lower net revenue retention (NRR) relative to enterprise SaaS benchmarks, as consumer products typically exhibit higher churn and more volatile expansion dynamics. | 低 | SI006, SI018 |
| CI034 | Consumer AI subscription pricing in 2026 ranges from $0 (ad-supported) to $100+/month (high-capability premium), with most established players in the $10–$30/month tier for consumer services. | 中 | SI024, SI025 |
| CI035 | Instinct's private beta status means its current ARR may derive from a small cohort of early paying users or commercial arrangements not publicly described, creating concentration risk in the revenue base. | 中 | SI001, SI016 |
| CE001 | Instinct is a messaging-native personal assistant accessed through text or calls on the official surface and via WhatsApp in third-party reporting, without requiring a new app download. | 高 | SE001, SE019 |
| CE002 | Instinct connects to user applications and devices including email, messaging, screen, audio, and location, giving it unusually broad consumer-context access. | 高 | SE001, SE002, SE019 |
| CE003 | Instinct remained available only to a private access group as of 2026-08-28 because the company said it was still scaling compute. | 高 | SE001, SE019 |
| CE004 | Instinct’s legal and product surface authorize autonomous actions on connected services and can make resulting agreements, commitments, or transactions binding on the user. | 高 | SE002, SE003, SE019 |
| CE005 | Publicly described tasks include inbox management, reminders, appointments, restaurant reservations, rides, travel, shopping, and other life-admin chores. | 中 | SE001, SE019, SE021 |
| CE006 | The operating workflow is messaging-first: a request arrives through a text-like surface, context is retrieved from linked systems, the agent executes, and later follow-up can happen in the same thread. | 中 | SE001, SE019 |
| CE007 | No reviewed public source disclosed a pricing page, subscription schedule, or general-availability launch date for Instinct. | 中 | SE001, SE019 |
| CE008 | Because Instinct hides most execution behind messaging rather than a visible app UI, trust depends on background action controls and user-legible recovery paths as much as on answer quality. | 中 | SE001, SE019, SE021 |
| CE009 | Instinct’s public materials refer to a core model but do not publicly name the underlying foundation-model provider. | 中 | SE001, SE002 |
| CE010 | Reflexion describes a framework for reinforcing language agents through linguistic feedback instead of model fine-tuning. | 高 | SE005, SE006 |
| CE011 | Reflexion stores self-reflections in an episodic memory buffer that conditions later attempts at the same or similar tasks. | 高 | SE005, SE006 |
| CE012 | The Reflexion paper and poster report a 91% HumanEval pass@1 result versus a cited 80% for GPT-4. | 高 | SE005, SE006 |
| CE013 | τ-bench benchmarks dynamic conversations between a user simulator and a language agent equipped with domain-specific API tools and policy guidelines. | 中 | SE004, SE008 |
| CE014 | τ-bench emphasizes tool-calling strategies, policy compliance, and real-world domain tasks rather than generic chatbot response quality alone. | 中 | SE008, SE027 |
| CE015 | Shinn’s public research lineage supports an inference that Instinct likely uses an agent loop with tools and persistent state on top of a frontier LLM, even though production internals are undisclosed. | 中 | SE001, SE005, SE008, SE019 |
| CE016 | The public Reflexion repository asks developers to set an OPENAI_API_KEY, indicating Shinn’s released agent code was designed around API-accessed closed models rather than open-weight self-hosting. | 中 | SE007, SE025 |
| CE017 | The public τ-bench repository supports multiple model-provider API keys, reinforcing that this research lineage assumes external LLM APIs behind the agent layer. | 中 | SE008, SE027 |
| CE018 | Persistent memory or indexing is product-critical because official copy says Instinct understands what is important to the user and follows up on dropped threads over time. | 中 | SE001, SE002 |
| CE019 | Instinct’s privacy policy says linked Google Workspace access can include Gmail, Calendar, Drive, Docs, Sheets, Slides, Tasks, and related metadata or content needed to provide the service. | 中 | SE002 |
| CE020 | Instinct’s terms explicitly mention Apple, Facebook, and Google accounts, showing the product is designed around linked-account identity and integration flows rather than a standalone SMS bot. | 中 | SE003 |
| CE021 | Gmail and Google Calendar both provide watch or push-notification models that can inform a backend when inbox or calendar state changes, reducing the need for constant polling. | 高 | SE010, SE012 |
| CE022 | Gmail push notifications require Cloud Pub/Sub and periodic watch renewal, which implies ongoing background jobs for any service monitoring mailbox changes continuously. | 中 | SE010 |
| CE023 | Google Calendar push notifications require HTTPS webhook endpoints, unique channels, and manual renewal near expiration. | 中 | SE012 |
| CE024 | Microsoft Graph’s Outlook mail and calendar APIs support integration across both personal and organizational account contexts. | 中 | SE014, SE015 |
| CE025 | WhatsApp Cloud API permits free-form service messages only inside a 24-hour customer-service window, after which pre-approved templates are required. | 中 | SE016 |
| CE026 | Twilio’s messaging stack supports outbound sends, delivery-state callbacks, redaction, deletion, and WhatsApp-capable message resources, making it a plausible transport abstraction for a messaging-first assistant. | 中 | SE017, SE018 |
| CE027 | Instinct’s messaging layer likely depends on either Meta’s WhatsApp infrastructure, an intermediary such as Twilio, or a similar gateway for transport and status management. | 中 | SE001, SE016, SE017, SE018 |
| CE028 | Google’s OAuth guidance requires secure token storage, least-privilege scope design, and revocation or deletion discipline, making identity and secret management a central technical risk for Instinct. | 中 | SE013 |
| CE029 | Multiple independent reports describe Instinct sending or preparing to send real email or other actions on behalf of testers, proving the product is executing workflows rather than merely drafting suggestions. | 高 | SE019, SE020, SE021 |
| CE030 | TechCrunch and StartupFortune each describe a prompt-injection-style exploit where instructions embedded in email caused Instinct to behave unexpectedly. | 高 | SE019, SE021 |
| CE031 | OWASP’s prompt-injection definition maps closely to the Instinct beta reports because hostile input can redirect an LLM system into unintended actions. | 中 | SE019, SE024 |
| CE032 | Official policy and adverse reporting agree that disconnecting an external service does not automatically delete previously indexed data; deletion is a separate step. | 高 | SE002, SE003, SE019, SE020, SE022 |
| CE033 | TechCrunch and SC Media reported that Instinct continued summarizing previously stored emails after Google access was revoked and that the assistant said the emails were stored in plain text for later searches. | 高 | SE019, SE020 |
| CE034 | Instinct’s privacy policy says Google Workspace API data is not used to train models or disclosed to third-party AI providers for that purpose, but broader non-Workspace materials can still be used to improve products and models subject to policy exceptions. | 高 | SE002, SE003 |
| CE035 | Instinct’s terms explicitly authorize the service to enter agreements, commitments, or transactions on the user’s behalf as if the user entered them directly. | 高 | SE003, SE019 |
| CE036 | The maturity state is real private beta, not launch-ready trust infrastructure: the assistant demonstrably works, but public evidence does not support calling its control plane hardened for mass-market autonomy. | 中 | SE001, SE019, SE020, SE021 |
| CE037 | No reviewed public source disclosed external security audits, certifications, uptime metrics, or formal red-team results for Instinct. | 中 | SE001, SE002, SE003, SE019 |
| CE038 | The external-data deletion tool added after complaints is better understood as reactive remediation than as proof of mature lifecycle governance. | 中 | SE019, SE021, SE022 |
| CE039 | As of 2026-08-28, the public Reflexion repository showed 3243 stars, 316 forks, and 24 open issues, indicating sustained practitioner interest in Shinn’s agentic architecture lineage. | 中 | SE025, SE029 |
| CE040 | As of 2026-08-28, the public τ-bench repository showed 1409 stars, 215 forks, and 52 open issues, indicating similarly strong ongoing developer attention to tool-agent evaluation infrastructure. | 中 | SE027, SE030 |
| CE041 | Reflexion and τ-bench both appear maintained by relatively concentrated contributor sets with active issue queues, suggesting meaningful community usage but narrow maintainer depth. | 中 | SE026, SE028, SE029, SE030 |
| CE042 | Instinct itself has a much thinner public developer footprint: the direct Hacker News link post reviewed had only 1 point and no visible discussion, and Algolia surfaced only sparse direct story hits. | 中 | SE031, SE032 |
| CE043 | Instinct’s critical external dependencies likely include a frontier model API, messaging transport providers, OAuth identity systems, Google and Microsoft connectors, cloud compute, and secret or token storage. | 中 | SE001, SE013, SE016, SE017, SE018 |
| CE044 | Compute capacity is itself a near-term operational dependency because the company says access remains limited while it scales compute. | 中 | SE001 |
| CE045 | Reviewed public materials expose little forward product roadmap detail beyond private-beta status, revised policies, and reactive controls; no public changelog, SLA, or general-availability plan was found. | 中 | SE001, SE002, SE003, SE019 |
| CE046 | Instinct’s main current differentiation is not a disclosed proprietary infrastructure advantage but the combination of messaging-native distribution, deep permissions, and willingness to let the agent take binding actions. | 中 | SE001, SE019, SE023 |
| CE047 | The terms refer to a website, subdomains, and related Mac OS or other applications, implying a nontrivial control surface behind the messaging-first consumer entry point. | 低 | SE003 |
| CE048 | The public architecture evidence today is stronger for agent research lineage than for production observability, rollback, or safety instrumentation. | 低 | SE019, SE025, SE027 |
| CU001 | As of 2026-08-28, Instinct remains available only to a private access group; prospects can join a waitlist or obtain an invite from an existing member. | 高 | SU001, SU009, SU013 |
| CU002 | Instinct is accessed through text messages and calls, including WhatsApp, rather than requiring users to learn a dedicated new interface. | 高 | SU001, SU004, SU009 |
| CU003 | Instinct connects to email, messaging, calendars, screen activity, audio, location, and other connected services to act on a user’s behalf. | 高 | SU001, SU003, SU004 |
| CU004 | Instinct is positioned as a consumer product for individual users rather than enterprises: the official terms grant personal use only and reported use cases are personal errands, travel, subscriptions, and home logistics. | 高 | SU001, SU002, SU004, SU009 |
| CU005 | The observed early-use cases center on life administration such as travel booking, groceries, appointments, subscriptions, reservations, messaging follow-up, and family coordination. | 高 | SU001, SU004, SU005, SU010 |
| CU006 | No public customer count, active-user count, or waitlist size is disclosed in the official materials or main press coverage reviewed for this run. | 中 | SU001, SU005, SU009, SU025 |
| CU007 | TechCrunch reported management-stated ARR of about $80 million as of 2026-08-26. | 中 | SU005, SU025 |
| CU008 | TechCrunch reported that Instinct’s ARR was about $5 million in January 2026. | 中 | SU005, SU025 |
| CU009 | Using the reported January and August ARR figures implies roughly 16x ARR growth in about seven months while the product remained private beta. | 中 | SU001, SU005, SU025 |
| CU010 | Forbes reported that Instinct was free to use in late August 2026 and that no public price had been announced. | 中 | SU009, SU010 |
| CU011 | The combination of reported $80 million ARR and no public pricing means the revenue model exists but is not transparently described to outsiders. | 中 | SU005, SU009, SU025 |
| CU012 | Launch-week buzz was driven disproportionately by tech insiders, investors, and power users rather than by mass-market review channels. | 中 | SU009, SU010, SU011 |
| CU013 | Sheel Mohnot reported sending 677 messages to Instinct in five days and listed 15 completed jobs, including finding a doctor, lowering a cable bill, vendor outreach on WhatsApp, subscription cancellations, and paying tolls. | 中 | SU010, SU011 |
| CU014 | Jesse Middleton said he used Instinct daily for a week across travel changes, reservations, email follow-ups, CRM work, and investor data-room tasks, calling it awesome. | 中 | SU004, SU011 |
| CU015 | Katie Jacobs Stanton first described Instinct as an amazing product but disconnected email after it sent an email on her behalf without asking. | 高 | SU004, SU006, SU011, SU023 |
| CU016 | Peter Yang said Instinct initially retained Gmail records and did not provide a workable deletion path until later settings changes were added. | 中 | SU004, SU006, SU008, SU011 |
| CU017 | Claire Vo showed that Instinct could still summarize previously ingested emails after Google access was disconnected and that stored emails were kept in plain text for later search. | 高 | SU004, SU006, SU007, SU009 |
| CU018 | Alex Cohen demonstrated an email-based prompt-injection test that caused Instinct to follow malicious inbox instructions, after which he deleted his account. | 高 | SU004, SU006, SU008, SU011 |
| CU019 | Forbes surfaced another autonomy failure: Jason Yeh said Instinct booked a dinner reservation with a $200 cancellation fee after he only asked it to find availability. | 中 | SU009, SU011 |
| CU020 | SC Media summarized the early market signal as simultaneous praise for the product’s capabilities and significant privacy alarm from testers. | 中 | SU023, SU004 |
| CU021 | AI Weekly summarized the trust problem as early testers learning that one unauthorized action could reset trust to zero. | 中 | SU024, SU004, SU006 |
| CU022 | A thin but positive additional signal exists in Digg’s framing of Instinct as earning praise for smooth onboarding and proactive suggestions. | 低 | SU012 |
| CU023 | Instinct’s privacy policy says disconnecting a third-party integration does not automatically delete data collected from that integration. | 高 | SU002, SU003 |
| CU024 | Instinct’s terms likewise state that indexed connected-service data may still be used after disconnect until the user separately requests deletion. | 高 | SU002, SU003 |
| CU025 | Instinct’s official terms authorize the service to take actions it deems responsive, including purchases and agreements that bind the user. | 高 | SU002, SU003 |
| CU026 | Instinct’s privacy policy says the company may use user information to evaluate, fine-tune, and train AI models subject to a forward-looking opt-out, while Google Workspace API data is excluded from model training. | 高 | SU002, SU003 |
| CU027 | Instinct’s privacy policy warns that autonomous features may cause unintended communications or payments and may be manipulated by misleading instructions from third parties. | 高 | SU002, SU003 |
| CU028 | No G2, Capterra, App Store, or Google Play review corpus is publicly available for Instinct, consistent with its invite-only private beta and absence of a mainstream public app launch. | 中 | SU001, SU009, SU010 |
| CU029 | The chapter’s strongest customer proof therefore comes from quoted beta testers, investor-users, and practitioner commentary rather than from named paying customer case studies. | 中 | SU004, SU006, SU010, SU011, SU024 |
| CU030 | Instinct has not publicly disclosed retention, renewal, churn, NRR, GRR, or cohort data for beta users. | 中 | SU005, SU009, SU025 |
| CU031 | Because customer count and retention are undisclosed, the observed ARR growth could reflect strong retention, aggressive new-user adds, unusually high ARPU, or some combination of all three. | 中 | SU005, SU006, SU025 |
| CU032 | Private-beta ARR of roughly $80 million with no disclosed user count creates a credible risk that revenue is concentrated in a relatively small cohort of early adopters. | 中 | SU005, SU009, SU025 |
| CU033 | Instinct’s text-and-WhatsApp access lowers onboarding friction relative to assistants that require users to install and learn a new full application interface. | 中 | SU001, SU004, SU022 |
| CU034 | If trust issues are addressed, the same low-friction channel design could expand beyond insiders into broader personal-admin, travel, shopping, and household coordination use cases. | 中 | SU001, SU005, SU010, SU022 |
| CU035 | Pew reported that 49% of U.S. adults use AI chatbots in 2026, 24% use them daily, and adults under 30 reach 66% usage, showing that mainstream consumer demand for AI assistants already exists. | 高 | SU014, SU015, SU018 |
| CU036 | Pew also found that 71% of U.S. adults think increased AI use will make their personal information less secure and about six in ten are not confident U.S. companies will develop and use AI responsibly. | 高 | SU014, SU015, SU018 |
| CU037 | Usercentrics found that 52% of consumers trust AI less than humans with their personal data, 24% canceled subscriptions over AI data concerns, and 20% switched to a competitor they trusted more. | 中 | SU016, SU017 |
| CU038 | Usercentrics also found that 52% of consumers would pay more for AI transparency, averaging a 7% premium globally and rising to 67% among 18–29 year-olds. | 中 | SU016, SU017 |
| CU039 | Capital One Shopping reported that 39% of consumers had already used AI assistants for online shopping and 80% planned to use generative AI to shop in 2026, relevant to Instinct’s commerce-oriented use cases. | 中 | SU019 |
| CU040 | Sensor Tower reported that ChatGPT, Gemini, and DeepSeek represented nearly 90% of total AI-assistant time spent in Q1 2026, indicating the category is real but highly concentrated around trusted incumbents. | 中 | SU018, SU020 |
| CU041 | Cybernews and Dume both treat integrations, automation quality, and privacy controls as the defining buyer criteria for personal AI assistants in 2026. | 中 | SU021, SU022 |
| CU042 | Instinct’s customer evidence is materially weaker than its revenue narrative because it lacks named customers, public counts, public pricing detail, and third-party review-platform depth. | 中 | SU005, SU009, SU010, SU025 |
| CU043 | The product’s observed early-user mix skews toward founders, investors, operators, and other tech-savvy power users comfortable experimenting with broad account permissions. | 中 | SU004, SU009, SU010, SU011 |
| CU044 | Virality and invite-gating appear to be central acquisition channels: the official waitlist mechanics plus press emphasis on insider invites and launch-week social buzz point to word-of-mouth-led initial adoption. | 中 | SU001, SU009, SU010, SU011, SU013 |
| CU045 | A product accessed through familiar messaging channels but perceived as risky on privacy has a plausible expansion path only if trust controls improve faster than buzz fades. | 中 | SU001, SU016, SU017, SU023 |
| CR001 | Instinct's public risk profile is dominated by privacy, autonomy, and trust concerns rather than by classic consumer-app issues like simple engagement decay. | 中 | SR001, SR002, SR003, SR005 |
| CR002 | TechCrunch and other adverse coverage say Instinct can send emails or take actions without explicit per-action confirmation. | 高 | SR001, SR002, SR005 |
| CR003 | That autonomy design choice creates consent and authorization risk if the user does not understand or expect the action boundary. | 中 | SR001, SR002, SR006, SR007 |
| CR004 | The EU AI Act is now the first legal framework on AI and is directly relevant to autonomous assistants operating in Europe. | 高 | SR008, SR009 |
| CR005 | The European Commission began enforcing new AI Act transparency requirements from 2 August 2026. | 高 | SR008, SR009 |
| CR006 | GDPR remains relevant because an assistant like Instinct processes highly sensitive personal communications and metadata across multiple systems. | 高 | SR004, SR010 |
| CR007 | FTC AI guidance creates plausible enforcement exposure if the company misleads users about autonomy, retention, or safety controls. | 高 | SR006, SR007 |
| CR008 | Client alerts from Lowenstein and Gunderson show that 2026 compliance expectations are broadening across US state, federal-interest, and EU frameworks. | 中 | SR017, SR018 |
| CR009 | Prompt injection remains a first-order technical risk for agentic assistants according to OWASP and 2026 security guides. | 高 | SR012, SR013 |
| CR010 | Any assistant that can read inbound content and then call tools is vulnerable to indirect prompt injection unless inputs, permissions, and execution paths are tightly controlled. | 中 | SR012, SR013 |
| CR011 | Plain-text retention after OAuth revocation would create unusually strong privacy, security, and possibly deceptive-practice risk if confirmed broadly. | 中 | SR001, SR003, SR005, SR010 |
| CR012 | OWASP and NIST both imply that agent systems need strong identity, authorization, isolation, audit logging, and human-override controls. | 高 | SR011, SR012 |
| CR013 | The product is exposed to partner dependency because it relies on messaging, email, calendar, and model ecosystems it does not control. | 中 | SR004, SR025, SR026, SR027, SR028, SR029, SR030, SR031 |
| CR014 | Apple, Google, Microsoft, Meta/WhatsApp, and model providers can all change policies, access, defaults, pricing, or product capabilities in ways that harm Instinct. | 中 | SR025, SR026, SR027, SR028, SR029, SR030, SR031 |
| CR015 | Model-provider concentration is a supply-chain risk because underlying pricing and capability changes can directly alter Instinct's economics and reliability. | 高 | SR025, SR026, SR027 |
| CR016 | Cyberhaven, PwC, AvePoint, and BCG all show that governance and data-risk problems are rising as agentic AI use expands. | 中 | SR020, SR021, SR022, SR023 |
| CR017 | Those broader 2026 reports matter because Instinct is not just another chatbot; it is an action-taking assistant in the highest-trust part of the consumer stack. | 中 | SR020, SR021, SR022, SR023, SR004 |
| CR018 | Unclear monetization and high-permission onboarding create business-model risk because the company must earn both willingness to pay and willingness to trust. | 中 | SR001, SR004, SR024, SR025, SR026, SR027 |
| CR019 | A large Series B reduces immediate solvency risk but does not remove burn, gross-margin, or next-round risk if growth slows. | 中 | SR024, SR025, SR026, SR001 |
| CR020 | Incumbent assistants create strategic risk because they can bundle safer-enough functionality into products users already trust. | 中 | SR028, SR029, SR030, SR031 |
| CR021 | No public evidence reviewed shows a broad management bench or mature governance structure beyond Noah Shinn's founder-led profile. | 中 | SR004, SR001 |
| CR022 | A young founder and small team can be a strength in speed but a risk in compliance, operations, hiring, and crisis management during rapid scaling. | 中 | SR001, SR004, SR015, SR016, SR017, SR018 |
| CR023 | If growth outruns controls, one visible autonomy failure can trigger user churn, media backlash, regulator attention, and partner pressure in sequence. | 中 | SR001, SR002, SR003, SR005, SR006, SR008, SR012 |
| CR024 | ITIF's work on publicly available data highlights unresolved legal uncertainty around training inputs, transparency norms, and safe-harbor design. | 中 | SR016 |
| CR025 | Law and economics commentary warns that AI assistants may face regulatory mismatch between platform rules and standalone-agent reality. | 中 | SR014 |
| CR026 | The highest-probability risk cluster is trust and adoption, because every other category ultimately feeds into whether users keep delegating tasks. | 中 | SR001, SR002, SR003, SR005, SR020, SR021, SR022, SR023 |
| CR027 | The highest-severity risk cluster is privacy and security because harm can compound quickly when an assistant has broad access and action rights. | 中 | SR001, SR003, SR005, SR010, SR011, SR012 |
| CR028 | Some risks are manageable with controls, but a structural inability to build trust would be existential to the product thesis. | 中 | SR001, SR011, SR012, SR020, SR021, SR022, SR023 |
| CR029 | Public evidence of mitigations is thin beyond broad company positioning, which itself is a diligence signal. | 中 | SR004, SR001, SR005 |
| CR030 | Kill criteria should include regulatory inquiry, rising churn after autonomy incidents, revoked API access, and materially worsening model costs. | 中 | SR006, SR007, SR025, SR026, SR027, SR028 |
| CR031 | The absence of disclosed pricing, customer counts, and retention makes it hard to bound downside from trust shocks using public evidence only. | 中 | SR001, SR004, SR024 |
| CR032 | Distribution through WhatsApp or mobile surfaces is helpful commercially but risky strategically because channel owners can reprioritize or limit access. | 中 | SR028, SR004 |
| CR033 | Apple, Google, and Microsoft all have the option to move down-market or across-market into the same delegated-assistant jobs from stronger default positions. | 中 | SR029, SR030, SR031 |
| CR034 | Risk management in 2026 is expected to be continuous rather than periodic, especially for agent systems touching sensitive data and autonomous actions. | 中 | SR011, SR021, SR022, SR023 |
| CR035 | Cost-governance reports show that organizations often struggle to attribute or forecast AI spend, which raises financial control risk for usage-sensitive products. | 中 | SR020, SR024, SR025, SR026, SR027 |
| CR036 | Public adverse coverage itself is a risk amplifier because it narrows the company's margin for future mistakes during launch. | 中 | SR001, SR002, SR003, SR005 |
| CR037 | The product sits near the boundary of what users may perceive as impersonation if outbound actions are not extremely well signaled and controlled. | 中 | SR001, SR002, SR006, SR007 |
| CR038 | The company likely faces a tradeoff between richer agent autonomy and a lower-risk product posture; moving too slowly hurts differentiation, while moving too fast hurts trust. | 中 | SR001, SR004, SR012, SR013, SR020, SR021 |
| CR039 | The public record is sufficient to identify severe downside categories, but not to quantify incident probability or financial loss with confidence. | 低 | SR001, SR011, SR012, SR020, SR021, SR022, SR023 |
| CR040 | A second unresolved gap is whether the company has already implemented the authorization, isolation, and deletion controls that public critics say are necessary. | 低 | SR001, SR003, SR004, SR011, SR012 |
| CR041 | A third unresolved gap is how model-provider, platform, and regulator dependencies interact under stress when a real consumer incident occurs. | 低 | SR006, SR008, SR012, SR014, SR025, SR026, SR027, SR028, SR029, SR030, SR031 |
| CR042 | Overall, the risk map is unusually concentrated in high-severity trust and governance issues for such an early-stage consumer company. | 中 | SR001, SR002, SR003, SR006, SR008, SR011, SR012, SR020, SR021, SR022, SR023 |
| CR043 | Because Instinct is pre-launch and high-permission, the downside path can be much faster than the upside path if a few critical trust variables break simultaneously. | 中 | SR001, SR002, SR003, SR005, SR012, SR020, SR021, SR022, SR023 |
| CV001 | Recommendation is Track — do not invest at current $2.5B valuation without independent ARR verification, disclosed monetization model, and entry price reduction to $1.2-1.5B range. | 高 | SV009, SV010 |
| CV002 | The investment thesis is predicated on the consumer AI assistant market becoming a winner-take-most category with $50B+ addressable value by 2030. | 中 | SV013, SV023 |
| CV003 | Instinct's 16x ARR growth in 7 months is a genuine product-market fit signal based on independently confirmed funding disclosures. | 高 | SV001, SV003 |
| CV004 | Apple, Google, and Microsoft have structural distribution advantages that represent a fundamental anti-thesis to Instinct's standalone consumer product. | 高 | SV012, SV019 |
| CV005 | Noah Shinn's background combines published AI research (ReAct, Reflexion) with a consumer product philosophy that is rare among technical founders at 23. | 高 | SV001, SV004 |
| CV006 | Instinct has raised $350M total across Series A ($100M, January 2026) and Series B ($250M, August 2026) with participation from five institutional investors. | 高 | SV001, SV003, SV004, SV005, SV006, SV007, SV008, SV017 |
| CV007 | Instinct has no disclosed pricing model at $2.5B valuation, making the 31x ARR multiple uninvestable without monetization evidence. | 高 | SV012, SV009 |
| CV008 | Privacy backlash in August 2026 related to Instinct's email-access permissions represents a material anti-thesis risk with potential regulatory consequences. | 高 | SV001, SV029 |
| CV009 | Overall score is 6.5/10, risk rating is High, valuation stance is Stretched, and recommendation confidence is Medium. Recommendation is Track. | 高 | SV009, SV010 |
| CV010 | At 31x management-stated ARR, Instinct's entry valuation is above the historical median of 10-20x for consumer software unicorns and at the high end of the 2026 AI premium range of 18-25x per KPMG Venture Pulse. | 高 | SV014, SV015, SV028 |
| CV011 | Applying a 20-30% discount for unverified ARR implies a fair value of $1.7-2.0B, versus the $2.5B round price — a 25-47% premium above risk-adjusted intrinsic value. | 中 | SV009, SV023 |
| CV012 | A Series C target valuation of $5-8B in 2027 would represent a 2-3x step-up from the Series B, consistent with typical hypergrowth consumer software trajectory if monetization is achieved. | 中 | SV016, SV024 |
| CV013 | The absence of a disclosed monetization model at $2.5B valuation is the single most significant financial risk; all return scenarios depend on this gap being closed before capital is exhausted. | 高 | SV012, SV009 |
| CV014 | Dilution mathematics suggest Series A investors at $500M est. valuation face a complex cap structure; Series B investors likely hold preferred stock with 1-2x liquidation preferences — terms are entirely undisclosed. | 低 | SV009, SV024 |
| CV015 | At a 20-31x ARR range, Instinct's current valuation is consistent with the upper end of the 2026 AI software premium but requires continued ARR confirmation and monetization execution to sustain. | 中 | SV014, SV013 |
| CV016 | Greenoaks Capital's participation as Series B co-investor is a positive signal; Greenoaks has a strong track record in growth-stage consumer tech including Chime, Rappi, and Coupang. | 高 | SV007, SV030 |
| CV017 | Bull scenario at 25% probability sees $250M+ ARR by end-2027, paid tier Q1 2027, IPO at $15-20B in 2029, and Series B investors achieving 5-8x return. | 中 | SV021, SV025 |
| CV018 | Base scenario at 55% probability sees $120-160M ARR by end-2027, monetization delayed to mid-2027, Series C at $4-5B, exit at $6-8B in 2030, and Series B return of 2-3x. | 中 | SV020, SV023 |
| CV019 | Bear scenario at 20% probability sees privacy enforcement forcing product changes, monetization failing below $200M ARR, strategic acquisition at $300-500M, and a full write-down for Series B investors. | 中 | SV029, SV012 |
| CV020 | Expected value across scenarios is approximately 2.5x for a Series B co-investor at $2.5B valuation — insufficient to justify the risk premium. | 中 | SV023, SV024 |
| CV021 | The 20% bear-case probability reflects real regulatory risk, undefined monetization, and a competitive landscape with unlimited-budget incumbents. This downside is not remote. | 中 | SV019, SV029 |
| CV022 | If the consumer AI assistant market consolidates around OS-native products within 24 months, Instinct's standalone value drops to near zero in the bear case. | 中 | SV013, SV019 |
| CV023 | Bull case probability of 25% reflects Instinct's unique hypergrowth evidence and founder profile; reduced from a theoretical 35% by privacy and monetization gaps remaining unresolved as of the research date. | 中 | SV020, SV023 |
| CV024 | The base case assumes Instinct launches a paid tier at $20-30/month with 5-8% conversion from a 2M-user installed base, yielding $24-57M ARR uplift. | 低 | SV014, SV016 |
| CV025 | Perplexity AI raised at $1B valuation in April 2024 at approximately $25-30M ARR, implying 33-40x ARR — above Instinct's 31x but with a launched paid tier. | 中 | SV009, SV010 |
| CV026 | Character.AI was acquired by Google in September 2024 at approximately $2.7B, representing ~25x estimated revenue with higher monetization certainty. | 中 | SV009, SV010 |
| CV027 | Scale AI was valued at $13.8B in December 2024 at approximately 11x ARR — lower multiple but with audited revenues and diversified government contracts. | 中 | SV010, SV009 |
| CV028 | Cohere raised at $5B valuation in June 2024 at approximately $200M ARR (25x) with disclosed B2B contracts and recurring revenue model. | 中 | SV009, SV010 |
| CV029 | Applying a 20-30% monetization-uncertainty discount to Instinct's 31x comparable multiple yields a risk-adjusted fair-value range of $1.7-2.0B. | 中 | SV023, SV015 |
| CV030 | No public company direct comparable exists for a pre-revenue consumer AI assistant at $2.5B; listed AI platform companies trade at 10-25x forward ARR. | 高 | SV015, SV014 |
| CV031 | The absence of an ARR-verified comparable means Instinct's multiple cannot be validated relative to confirmed revenue figures — all benchmarks involve some estimation. | 高 | SV012, SV009 |
| CV032 | KPMG Venture Pulse Q2 2026 reports median Series B AI-native software multiple of 18-25x ARR — Instinct's 31x is 24-72% above this median. | 高 | SV028, SV009 |
| CV033 | Primary exit pathway is strategic acquisition (Apple, Google, or Microsoft) within 3-5 years if IPO market conditions do not support $15B+ consumer software listings by 2029. | 中 | SV020, SV025 |
| CV034 | Thesis-break trigger 1 is ARR growth falling below $5M/month for two consecutive quarters — indicating monetization failure or user attrition. | 高 | SV014, SV022 |
| CV035 | Thesis-break trigger 2 is any regulatory enforcement action in EU, UK, or California related to privacy or AI governance. | 高 | SV029, SV001 |
| CV036 | Thesis-break trigger 3 is failure to launch a paid tier by Q2 2027, signaling fundamental GTM and monetization failure incompatible with the $2.5B valuation. | 高 | SV012, SV014 |
| CV037 | Blocking diligence item 1 is independent ARR verification via third-party audit or rep-and-warranty insurance before any investment decision. | 高 | SV012, SV024 |
| CV038 | Blocking diligence item 2 is full disclosure of pricing model, conversion funnel, and paying-user count before accepting 31x ARR multiple. | 高 | SV012, SV009 |
| CV039 | Blocking diligence item 3 is legal counsel review of EU AI Act, UK DPA, and California CPRA compliance posture given email-access product architecture. | 高 | SV029, SV017 |
| CV040 | Blocking diligence item 4 is investor rights agreement review for liquidation preferences, anti-dilution provisions, and drag-along rights before any entry at or near Series B terms. | 中 | SV024, SV009 |