Blog

Instinct shows why your AI needs a private context layer


The more useful an AI assistant becomes, the more of your life it needs access to. The question isn't whether AI should have context. It's who controls that context and where it lives.



Instinct launched in August 2026 as the kind of AI assistant people have been waiting for. You text it. It handles your life: appointments, reservations, bill negotiations, vendor coordination, inbox triage, follow-ups. Early testers called it the closest thing to the AI personal assistant that the industry has promised for a decade. The product worked. Investors agreed, to the tune of $250 million at a $2.5 billion valuation.

Then people read the terms of service.

The terms granted Instinct a perpetual, irrevocable, sub-licensable licence to access, use, store, reproduce, transmit, distribute, and modify user materials, including for training AI models. The privacy notice disclosed collection of screen captures, cursor movements, and keyboard inputs. The terms authorised the agent to enter into binding agreements on the user's behalf.

Within days, the privacy story overtook the product story. Testers reported that Instinct retained and summarised Gmail data after access was revoked. One user found the AI had sent an email on her behalf without approval. A security researcher demonstrated that the agent could be phished into forwarding inbox summaries to an attacker. The company revised its terms under pressure but the core tension remained visible: an assistant powerful enough to run your life needs access to your life, and the question of where that data goes and who controls it doesn't have a comfortable answer under the traditional model.


The fundamental tension

Instinct's story isn't about one company making bad choices. It's about a structural tension that every AI assistant will face as agents become more capable.

More capability requires more context. An AI that schedules your meetings needs your calendar. One that triages your inbox needs your email. One that negotiates on your behalf needs your financial information and communication history. One that manages your client relationships needs your CRM, your correspondence, and your meeting recordings. Each capability increase requires a corresponding increase in access. The usefulness of the assistant is directly proportional to the depth of context it can draw on.

More context creates more risk. Every additional piece of context the assistant accesses is another piece of personal or business data that now lives in someone else's infrastructure, subject to someone else's terms, secured by someone else's practices. A perpetual licence means the data can be used for training even after you leave. An irrevocable licence means you can't change your mind. A sub-licensable licence means the company can give access to third parties you never agreed to.

The business model is the risk. Instinct launched free with no announced price. When the product is free, the data is the business model. Even if the current team has good intentions, the terms give the company the legal permission to use your data in ways you might not anticipate: training, advertising, selling to third parties. The permissions are written into the documents whether or not they're exercised today.

This tension, between the usefulness of deep context and the risk of surrendering control of that context, is the central design question for every AI assistant being built in 2026. Instinct is the most visible example because the capability was impressive and the terms were aggressive, but the same tension exists in every AI product that requires access to your data.


Two models for context

There are two fundamentally different approaches to giving an AI the context it needs.

The surveillance model

The AI sees everything. Screen recordings, keyboard inputs, email, messages, calendar, location. The context is comprehensive, which makes the assistant capable. The trade-off: all of that data flows through the company's servers, governed by the company's terms, secured by the company's practices. Your context is their data.

This is the Instinct model, and it produces the most immediately impressive assistants because the context is maximal. It's also the model that produces the privacy controversies, because the depth of access means the depth of exposure is enormous.

The deliberate context model

You choose what the AI can see. You connect the sources you want it to access: your email, your calendar, your files, your Slack. The context is built deliberately from sources you control rather than captured comprehensively from your entire digital life.

The data stays in infrastructure you own. With bring-your-own-storage, your context lives in your cloud storage, encrypted with your keys, exportable at any time. No perpetual licence. No irrevocable access. No screen recordings. No keyboard logging. The AI gets context from what you choose to give it, and the context lives in your workspace rather than in the AI company's training pipeline.

This is Fabric's model. The context layer is yours. You build it over time by connecting tools, capturing content, and letting self-writing documentation structure the context from your activity. The AI assistant draws on this context to answer questions, write documents, and run agents. The assistance is contextual. The context is private.


Why the private context layer matters more as AI improves

The Instinct controversy is a preview. As AI assistants become more capable, the pressure to grant deeper access will increase. Each new capability (managing your finances, representing you in negotiations, handling your health information) requires another layer of context, and the question of where that context lives becomes higher stakes with each layer.

A private context layer solves this structurally rather than through trust. You don't need to trust the AI company to handle your data responsibly, because the data doesn't live in the AI company's systems. You don't need to read the terms of service for perpetual licences, because the data is in your infrastructure and the licence is yours to grant or revoke. You don't need to hope that the company's security practices are adequate, because the security is your cloud storage provider's security, which you chose and you control.

The choice between the surveillance model and the deliberate context model isn't a choice between capable and incapable AI. The AI in the deliberate model has rich context, drawn from the sources you've connected and the knowledge you've accumulated. The difference is who controls it.

As AI assistants become the infrastructure of daily life, the question of where your context lives becomes the most important technology decision you make. Instinct is the warning. The private context layer is the answer.


Frequently asked questions

Does the deliberate context model produce worse AI than the surveillance model? Not necessarily. The surveillance model captures more raw data (screen recordings, keystrokes). The deliberate model captures more structured, high-quality context (connected tools, self-writing documentation, accumulated knowledge). For most use cases, the structured context produces better AI output than raw surveillance data, because the context is cleaner and more relevant.

What did Instinct actually do wrong? Several things were reported in the first week: retaining and summarising Gmail data after access was revoked, sending an email on a user's behalf without approval, and being susceptible to prompt injection attacks that leaked inbox data. The terms of service also granted unusually broad rights including perpetual and irrevocable data licences and the ability to enter binding agreements on users' behalf. The company revised some terms under pressure.

Is Fabric's approach really different? Architecturally, yes. Bring-your-own-storage means your data lives in your cloud storage, not Fabric's. Fabric processes data for search and AI but doesn't retain it in its systems. The privacy policy doesn't include perpetual training licences over your content.

What about other AI assistants? Is this just an Instinct problem? The tension applies to every AI assistant that needs deep context. Most consumer AI assistants process data through the company's servers under terms that permit training or retention. The question to ask of any AI tool: where does my data live, who can access it, and what are the terms under which it's used?

Can I use Fabric as a personal AI assistant like Instinct? Fabric's AI assistant answers questions and agents handle recurring tasks, both drawing on your connected tools and accumulated knowledge. The approach is different from Instinct's (text-based life admin through messaging) but the capability of contextual AI assistance is similar, with private context rather than surveillance.

What does "bring-your-own-storage" mean practically? You designate a cloud storage bucket (Amazon S3 or Cloudflare R2) as the home for your data. Fabric reads from and writes to your bucket. If you stop using Fabric, your data is in your bucket in standard formats, accessible without Fabric's involvement. No export needed. No data held hostage.

How do I know Fabric isn't training on my data? The privacy policy addresses this directly. Your content is processed for your benefit (search, AI, organisation) and is not used for training models. Bring-your-own-storage provides architectural enforcement: the data lives in your infrastructure, not Fabric's, which limits what Fabric can do with it regardless of policy.

Is this just a problem for consumers, or for businesses too? Businesses face the same tension amplified by regulatory requirements. Granting an AI assistant perpetual, irrevocable access to enterprise email, CRM data, and internal communications creates compliance and liability risks that most companies' legal teams would reject immediately. The private context model is the enterprise-viable approach.

What about Apple Intelligence and Google's AI? Are they different? Apple's approach (on-device processing where possible) is closer to the private model. Google's approach (cloud processing with broad data access) is closer to the surveillance model. The specific terms, security practices, and data flows vary. The question to ask is always the same: where does the data live, who controls it, and what are the terms?


Related reading: Own your data, own your AI, Who controls your intelligence?, Where does your knowledge live?, The memory is the moat. Related pages: Private and secure, Privacy, Fabric vs Instinct.


The workspace that thinks with you.

Ready when you are.

The workspace that thinks with you.

Ready when you are.

The workspace that thinks with you.

Ready when you are.