Instinct's Trust Problem Is Every AI Agent's Problem
August 24, 2026

Instinct's Trust Problem Is Every AI Agent's Problem

Instinct's demo is great. That's exactly the problem.

TechCrunch reported this week that Instinct, a new AI assistant, is winning over early testers with what it can do -- and simultaneously drawing scrutiny for how it does it. The concerns are specific: sweeping access to a user's accounts and data, broad terms of service, and the ability to take action on someone's behalf without a human confirming every step. None of that is hypothetical risk. It's the actual design of the product, and it's the same design every serious 'agentic' assistant is racing toward, because it's also what makes them useful.

Here's my read: the more impressive an AI assistant is, the scarier its permissions model gets, and there's no way around that trade-off -- only ways to manage it. An assistant that can only suggest things is safe and mostly useless. One that can actually book, buy, message, and move money on your behalf is genuinely valuable and genuinely dangerous if the guardrails are thin. Instinct sitting at that intersection isn't a scandal, it's the whole category maturing in public. The mistake would be treating early enthusiasm as proof the trade-offs have been solved, when what testers are actually describing is a product that works well and has broad terms of service they may not have fully absorbed.

For a business owner, this is the exact calculation you make every time you connect any AI tool to your CRM, your inbox, or your billing system: what can it see, what can it do without asking, and what happens when it's wrong. It's worth reading a vendor's actual security posture and trust documentation before you grant that access, not after something goes sideways -- and worth asking specifically how incidents get handled if an agent does act outside the lines, which is exactly what an incident response page should spell out. Consumer assistants like Instinct will keep getting flashier. The businesses that come out ahead will be the ones that treated 'it can act on your behalf' as a security question first and a productivity feature second.

Amjad Masad's stage time is a signal, not just an appearance

The other headline today is smaller but worth noting: Replit co-founder and CEO Amjad Masad is joining the Disrupt Stage at TechCrunch Disrupt 2026 to talk about the future of programming and where Replit fits into it. On its own, a conference booking isn't news. But it's a useful marker of where the industry's attention is heading -- toward the people building tools that let anyone, coder or not, turn an idea into working software.

Masad has been one of the more vocal advocates for AI collapsing the distance between 'I have an idea' and 'I have an app,' and that's a conversation ViibeStack has a direct stake in. Whatever Masad says on stage, the underlying question -- who gets to build software, and how much technical skill that requires -- is the same one worth asking about any no-code app builder or AI app builder you're evaluating today. The tools are converging on the same promise. The differences show up in what happens after the demo: how the app scales, who owns the data, and how much you're locked in once you've built on someone's platform.

Which of these worries you more: an AI assistant with too much access to your accounts, or the idea that building software may soon require no traditional coding skill at all?

Sources

← Back to News