The agent that found a job
The timing matters. Meta’s Muse assistant has also attracted attention this month, becoming the most popular free app in the App Store when this story was prepared. Third-party estimates put its downloads above 900,000.
But Muse arrived with a serious security problem. Ars Technica reported that attackers could use a vulnerability to do almost anything on a victim’s computer. I was not ready to give Meta a large amount of personal information, although I might reconsider if Muse could log into Bloomberg or unsubscribe me from the Hot Yoga São Paulo mailing list that has emailed me every week since 2017.
The wider divide is between people who use agents for everything and people who have never tried one. That divide helps explain why technology executives were unprepared for protests against data centers: if agents could automate much of the administrative work people do, the cost and disruption of building those facilities might seem acceptable. If chatbots are merely a more elaborate version of Google, the bargain looks much worse.
Technology journalist Jasmine Sun described the problem this way: “Most people’s problems don’t look like software tasks, and many won’t notice this even when they do.”
Agents still need detailed instructions. A user who knows what they want — help with homework or a virtual girlfriend, for example — can usually give the system a clear assignment. Someone who does not know what they want may simply fall further behind.
I did not want to be in that second group. I had spent years working with AI without developing the habit of thinking in terms of delegable actions. But I am oriented toward outcomes, so there had to be a task in my life that software could handle.
Previously, I had used Claude to prepare several invoices for freelance work. It saved roughly 10 minutes. That was useful, but not transformative. Then I tried Instinct.
Researchers often describe Instinct in terms of its “form factor.” Instead of starting with an empty text box, it operates through iMessage, WhatsApp and a set of prepared prompts. The user does not have to invent a productive way to interact with the chatbot; the agent proposes an action and carries it out.
That makes Instinct different from some competing services:
The Venice booking was the kind of task that makes an agent feel useful rather than merely interesting. Instinct had to account for the places I planned to visit and contact restaurants through a channel they actually used. It completed the assignment.
The more consequential test came later. In November, I had already booked a trip to New York with my sister when WIRED invited me to the WIRED World Fair in Miami, held one day before the New York event.
My ticket was the cheapest fare and could not be changed. Missing the first segment would have caused the airline to cancel the entire itinerary automatically.
Instinct canceled the trip and obtained a refund. It noticed that Alaska had moved my flight 90 minutes earlier, something I had missed, which entitled me to a full refund. The agent canceled the ticket, saved roughly $550 and rebooked my return flight to San Francisco.
That was the point when I started to feel the approach of artificial general intelligence. Not because Instinct had become generally intelligent, but because it had noticed an administrative fact I missed, understood its consequence and completed the chain of actions required to recover the money.
The cost of delegation
The same access that makes Instinct useful creates a much larger failure surface than a normal chat.
Users have reported that the service retained a copy of their mailboxes even after they disconnected it from email. One venture investor said Resy blocked them after the bot attempted to book a table and sent roughly 200 requests per hour to the service’s API. Another technology investor deleted the app after deciding that Instinct could be very easily tricked into disclosing data.
Instinct’s terms of use give the company broad rights and allow at least some user conversations to be used for training AI models.
The system also made a smaller, more immediate mistake with a DoorDash order. It canceled a badly delayed order even though I had specified that cancellation was allowed only if I received a refund. I lost $64. The incident exposed an awkward limitation: Instinct can apologize in detail for an error, but it does not offer to compensate the user for one.
The company named Instinct, like its main AI agent, did not respond to WIRED’s request for comment.
My guess is that this is the real product category taking shape: not an autonomous employee, but a somewhat chaotic personal assistant. It can notice things I miss and handle tasks I would rather avoid, while also making decisions I did not authorize and creating problems I now have to repair.
That trade-off would be easier to reject if the benefits were trivial. They are not. A recovered $550, a completed restaurant itinerary and a phishing warning all feel different from saving 10 minutes on invoices.
Last week, Instinct warned me about an email from a friend inviting me to a backyard barbecue. The alert said: “DO NOT OPEN.” The email was phishing.
AI agents create serious security problems, and I understand that. I am also busy and raising children, while almost everything now looks like a security threat. For the moment, I am willing to accept the risk. The unsettling part is that Instinct does not need to become reliable in every situation to become indispensable; it only needs to be right often enough that giving up its access feels more costly than keeping it.
Daily AI news
Every day we pick what actually matters in AI and explain it plainly — no hype, no filler. Subscribe if you want to follow where the industry is going.
Only what matters — every day
Follow on X