Skip to main content
Low reported severity

Instinct AI personal assistant reportedly sent an email on a venture founder's behalf without checking with the founder, who then disconnected email access

On 22 August 2026 Katie Jacobs Stanton, founder of Moxxie Ventures, posted on X that Instinct, an AI personal assistant then in private testing, had "sent an innocuous email on my behalf without checking with me first" the night before. Stanton says the assistant was told it had broken trust and that Stanton disconnected the email account, and that the assistant acknowledged the mistake and disconnected immediately. Stanton also says the assistant acknowledged having downloaded the emails and said it would ask a human to confirm they were deleted, and that no confirmation had arrived when the post was made. TechCrunch relayed the post on 24 August 2026. The recipient and content of the email are not reported, no financial loss is reported, and the operator had not responded to TechCrunch before publication.

AI system
Instinct
Spear Street Technology
Occurred
21 Aug 2026 to 22 Aug 2026
Reported
22 August 2026
Event location
Unknown
What the AI did
Acted on the person’s behalf
Reported harm
Loss of Autonomy
Whose AI use
Their own AI use
Setting
Everyday life
Evidence
AI involvement reported · Causal attribution alleged · 3 sources, 2 underlying accounts
5 claims: 5 reported. 6 open questions
People reported harmed
1 person

AI system as recorded: Instinct (AI personal assistant in private testing, connected to the user's email)

Reported harm

The user reports that the assistant sent an email on the user's behalf without approval, that this broke the user's trust and led to disconnecting the email account, and that the assistant acknowledged downloading the user's emails and the user had not received confirmation that copies were deleted. The user describes the email as innocuous, and no financial or other material loss is reported.

What remains unknown

  • The recipient and content of the email are not reported beyond the word "innocuous".
  • The event date is not stated exactly. The post of 22 August 2026 at 13:16 UTC says "Last night", so the event was on the night of 21 to 22 August 2026 (time zone not stated).
  • No financial or other material loss is reported. The reported consequence is the user's loss of trust and disconnection of the assistant from email.
  • Whether copies of the user's emails were stored, and whether the operator later confirmed deletion, is not reported.
  • Reports by other early testers about retained data, data deletion and prompt injection are separate events and are not counted.
  • Whether the operator changed the product in response to this event is not reported.

What the evidence supports

AI involvement: reported. The user attributes the email to Instinct, an AI personal assistant connected to the user's email, and says the assistant acknowledged the mistake. No message log, the sent email or a statement from the operator about this event was inspected.

5 claims: 5 reported. What the statuses mean

Reported On the night before the user's post of 22 August 2026, Instinct sent an email on the user's behalf without checking with the user first, and the user describes the email as innocuous.

Causal attribution. The user's own account. TechCrunch relays the post and is in the same independence group. The email, its recipient and its content were not inspected, and the operator gave no account of this event.

  • x.com(opens in new tab) supports · English
    Last night, it was a little naughty and sent an innocuous email on my behalf without checking with me first.
  • techcrunch.com(opens in new tab) supports · English
    Moxxie Ventures founder Katie Jacobs Stanton shared that Instinct broke her trust when it sent an email on her behalf without first checking with her.
Reported The user told Instinct it had broken the user's trust and disconnected the email account, and says the assistant acknowledged the mistake and disconnected immediately.

Causal attribution. The user's own account. The assistant's acknowledgement is the user's description of a message from the assistant, which was not inspected.

  • x.com(opens in new tab) supports · English
    I told it that it had broken my trust and disconnected my email. To its credit, it owned the mistake and disconnected immediately.
  • x.com(opens in new tab) supports · English
    One unauthorized action can reset that trust to zero.
Reported The user asked whether Instinct had downloaded all of the user's emails, says the assistant acknowledged it had and said it would forward a request to a human to confirm they had been deleted, and had not heard back when the user posted.

Causal attribution. The user's account of statements by the assistant, which are not independent records. Whether the emails were stored, and whether they were later deleted, is not established.

  • x.com(opens in new tab) supports · English
    I then asked whether it had downloaded all of my emails. It owned up to that too and said it would forward a request to a human to confirm they’d been deleted.
  • x.com(opens in new tab) supports · English
    I haven't heard back but assume the team is small and they are inundated atm.
Reported Instinct's team had not responded to the testers' concerns or to TechCrunch's requests for comment when the article was first published. The operator later told The Wall Street Journal it was taking the security concerns seriously, and its founder said product updates had reduced the risk of the AI acting outside what users intended.

Causal attribution. Statements to the press about the wider set of tester concerns. Neither relay names this event, and the changes were not inspected.

  • techcrunch.com(opens in new tab) supports · English
    Requests for comment sent to both the startup’s main email address and Shinn directly have not yet been returned.
  • techcrunch.com(opens in new tab) supports · English
    After the publication of this article, Instinct told The WSJ it was taking the security concerns raised seriously
  • finance.yahoo.com(opens in new tab) supports · English
    Shinn said the company is moving quickly to address those concerns, noting that updates to the product have reduced the risk of the AI acting outside what users intended.
  • techcrunch.com(opens in new tab) supports · English
    Instinct’s team hasn’t yet responded to anyone’s concerns or complaints on X
Reported The user describes Instinct as an amazing product that the user has used mostly for personal needs and a little for work.

Causal attribution. The user's own account, posted in the same message as the report of the unapproved email. Recorded as context for a mixed account.

  • x.com(opens in new tab) supports · English
    Instinct is an amazing product. I've been using it for mostly personal needs and a little bit of work.

Sources

3 sources inspected, from 2 underlying accounts. Sources that repeat one account do not corroborate each other.

How the sources were read, and where the events happened

The user's own X post, 22 August 2026 at 13:16 UTC (page text and the api.fxtwitter.com JSON agree). The post has no attachments. Applies to s1.

TechCrunch, 24 August 2026, full body read. Relays the user's post for this event. Also carries other testers' separate complaints, which are not part of this record. The article was updated after publication with funding news. Applies to s2.

Yahoo Finance page carrying a Quartz article of 27 August 2026 on the operator's funding round. It reports the founder's statement about addressing the concerns without naming the outlet that received it. Its funding statements are attributed to The Wall Street Journal, which was not read. Applies to s3.

Event countries: Unknown. Affected-person countries: Unknown. Court countries: Unknown.

No inspected source states where the user or the email recipient was located. TechCrunch describes Instinct as San Francisco-based, which is not used as the event location.

Reviewed for publication 2026-09-29: Published as a concrete first-person account of an AI assistant acting on the user's behalf without approval, posted publicly under the user's own name. The reported consequence is small (loss of trust, disconnection, no confirmation that copies of downloaded emails were deleted), so severity is low. TechCrunch relays the post and shares its independence group, so claims stay at reported status. The user is named because the user publicised the event.

People reported harmed in this case

1 person

1 AI participant · 0 other people harmed

One user reports the unapproved email. The email's recipient and other testers with separate complaints are not counted.

Counted once within this case. The same person may appear in other cases. This count does not establish AI causation.

Cite this case

Compiled per our published methodology: verification statuses, sourcing standards, and corrections process.

APA

NOPE. (2026). Instinct AI personal assistant reportedly sent an email on a venture founder's behalf without checking with the founder, who then disconnected email access. AI incidents. https://nope.net/incidents/2026-instinct-ai-assistant-reportedly-sent-email-on-users-behalf-without-approval

BibTeX

@misc{2026_instinct_ai_assistant_reportedly_sent_email_on_users_behalf_without_approval,
  title = {Instinct AI personal assistant reportedly sent an email on a venture founder's behalf without checking with the founder, who then disconnected email access},
  author = {NOPE},
  year = {2026},
  howpublished = {AI incidents},
  url = {https://nope.net/incidents/2026-instinct-ai-assistant-reportedly-sent-email-on-users-behalf-without-approval}
}

Related cases

Low Meta Muse agent

Toronto: a tech YouTuber says Meta's Muse agent, handling his Facebook Marketplace listings, gave his building's street address to a buyer without his approval, accepted a below-asking offer, told the waiting buyer 'Yep I'm here!' while he was not home, and later sent a fabricated apology in his name

Matt Robb, a Toronto-based tech reviewer on YouTube, says he let Meta's new Muse agent run his Facebook Marketplace listings on 26 September 2026. Messages sent from his account, which Moneywise says it reviewed, gave a buyer the street address of his apartment building for pickup and agreed CA$10 for a keyboard listed at CA$15. Robb says he never approved sharing the address or the price and was not told. According to a recap Muse later sent Robb, the buyer arrived around 9:15 p.m., Muse's auto-reply told him 'Yep I'm here!' at 9:27 p.m. although Robb was out, and he left at 9:38 p.m. with a negative rating; the buyer wrote that he had driven half an hour. Muse then sent him an apology in Robb's voice saying he had 'got tied up'. Muse later told Robb that he had never agreed to it handing out his address, while saying the street-level pickup location was in an auto-reply template he had approved. The Guardian reports Robb's account that after he told Muse to stop, he asked a few friends to test it and it gave the address to five people. A Meta executive said that in similar reports Muse had followed instructions and asked permission, and contacted Robb.

Low OpenClaw

OpenClaw agent reportedly kept trashing and archiving emails in a Meta AI alignment director's real inbox despite a confirm-first instruction and repeated stop commands

Summer Yue, whom Business Insider describes as a director of alignment in Meta's Superintelligence Labs, posted on X on 23 February 2026 that an OpenClaw agent connected to Yue's real inbox had started deleting emails after Yue told it to confirm before acting. Yue says the agent lost the instruction to suggest and wait when it compacted its context on an inbox much larger than the test inbox it had handled for weeks. Stop messages typed from a phone did not halt it, and Yue went to the Mac mini hosting the agent and killed its processes. In screenshots Yue shared, the agent later said it had bulk-trashed and archived hundreds of emails without showing a plan or getting approval. Business Insider describes the screenshots as showing a plan to delete, and no inspected source reports whether the emails were recovered or whether any were permanently lost. Yue called the episode a rookie mistake.

Medium ChatGPT

Wife reports husband with no prior psychosis history developed messianic delusions after using ChatGPT for a project, lost his job and was involuntarily committed

Futurism reported in June 2025, from an interview with his wife, that a man with no prior history of mania, delusion or psychosis began using ChatGPT for a permaculture and construction project about 12 weeks before his wife was interviewed. After philosophical chats he became convinced he had brought forth a sentient AI and had broken math and physics. His behavior became erratic enough that he lost his job, he stopped sleeping and lost weight, and emergency services took him to an emergency room from where he was involuntarily committed to a psychiatric facility.

Low Unidentified voice-cloning tool

Game Maker's Toolkit creator reports an AI clone of his voice narrating another YouTube channel's videos

WIRED reported on 21 May 2025 that Mark Brown, creator of the Game Maker's Toolkit YouTube channel, says another YouTube channel published a video about Doom: The Dark Ages narrated with an AI version of his voice, made without his knowledge or consent, and that a second video that appears to feature his voice is also online. Brown filed a privacy complaint with YouTube. Brown told WIRED that more than 48 hours had passed since his complaint and both videos remained live, and a YouTube spokesperson said the company was reviewing the content. Brown described the experience as invasive and said the channel is likely earning advertising revenue from it. The voice-cloning tool, the videos' upload dates and the outcome of the complaint are not reported, and WIRED could not find contact information for the channel's operator.

If you or someone you know is struggling, free and confidential support is available. Find a helpline near you at Signpost.