Blog

What Instinct gets right and what it misses


Instinct proved that AI assistants with deep context are transformatively useful. It also proved that the surveillance model for acquiring that context doesn't scale trust. Both lessons matter.



Instinct is the most interesting AI product launch of 2026, not because the product is flawless but because it illuminated a question that every AI company will need to answer: how much context should an AI assistant have, and how should it acquire that context?

The answer Instinct gave, maximum context through surveillance (screen capture, keyboard logging, email access, location tracking), produced the most capable personal AI assistant most testers had ever used. It also produced a privacy controversy that overwhelmed the product story within days of launch.

Both outcomes matter. The capability proves the thesis. The controversy proves the model needs to change.


What Instinct gets right

Deep context produces transformatively useful AI

Instinct's core insight is correct: an AI assistant that knows your schedule, your email, your messages, your preferences, your relationships, and your patterns can provide assistance that's qualitatively different from a generic chatbot. The early testers who reported that Instinct felt like a "real assistant" rather than a chatbot were describing the result of deep context: the AI could anticipate needs, coordinate across tools, and take actions informed by comprehensive understanding.

This isn't a minor improvement. The gap between a context-free AI ("what's the weather?") and a context-rich AI ("you have a client meeting in thirty minutes in the part of town where it's raining, here's a restaurant nearby for the lunch you mentioned wanting to schedule") is the gap between a novelty and essential infrastructure.

AI that acts, not just answers

Instinct demonstrated that an AI assistant should do things, not just answer questions. Scheduling appointments, sending follow-ups, negotiating bills, coordinating with vendors: the assistant that handles tasks is categorically more useful than the assistant that only answers questions. The vision of an AI with a body, one that can take action on your behalf, is the right vision.

Text-first interaction works

The text message interface (you text the assistant like a friend) was praised by early users as more natural than opening an app. The insight that AI assistance should meet you where you are (in your messaging app) rather than requiring you to go somewhere specific (a separate AI app) is sound and influences how products like Fabric Tag bring AI into Slack.


What Instinct misses

The surveillance model doesn't scale trust

Screen capture. Keyboard logging. Continuous audio access. Location tracking. Email scanning. Each of these capabilities makes the AI more useful. Each also makes the privacy exposure more severe. The terms of service granted Instinct a perpetual, irrevocable, sub-licensable licence to the collected data, including for training AI models.

This model works when trust is absolute and permanent. In practice, trust is conditional and fragile. A single data breach, a single policy change, a single acquisition by a company with different values can retroactively compromise years of accumulated personal data. The perpetual licence means the data rights persist even after you leave the service. The irrevocable licence means you can't change your mind.

The early incidents confirmed the fragility: Gmail data retained after access was revoked, an email sent without user approval, a prompt injection vulnerability that could leak inbox summaries. Each incident was individually small. Collectively, they demonstrated that the surveillance model's attack surface is enormous and growing.

Context should be chosen, not captured

The alternative to the surveillance model is the deliberate context model: you choose which sources the AI can access, which tools it can connect to, and what data it can query. The context is built deliberately from sources you control rather than captured comprehensively from your entire digital life.

Fabric's approach demonstrates this: you connect the tools you want the AI to access. Your email, your calendar, your files, your Slack. The AI gets rich context from the sources you've chosen. The context lives in your infrastructure with no perpetual training licence. You can revoke access at any time and the data stays yours.

The deliberate model produces less raw data (no screen captures, no keyboard logging) but more structured, higher-quality context (connected tool content, self-writing documentation, semantic search). For most use cases, the structured context produces better AI output than raw surveillance data because the signal-to-noise ratio is dramatically higher.

Data ownership is non-negotiable

When the product is free and the terms grant perpetual data rights, the user isn't the customer. They're the product. Instinct's $250 million raise at a $2.5 billion valuation, before any revenue model was announced, suggests the value is in the data, not in subscription revenue.

The private context layer model, where data ownership is architectural (bring-your-own-storage) rather than policy-based (trust our terms), is the approach that scales to enterprise adoption. No corporate legal team will approve a perpetual, irrevocable data licence over employee email, internal communications, and screen recordings. The enterprise-viable model is the one where the data stays in the company's infrastructure.


The synthesis

Instinct's thesis (deep context produces transformatively useful AI) is correct. The implementation (surveillance plus perpetual licence) is wrong. The synthesis is an AI assistant with deep context acquired through deliberate connection rather than comprehensive surveillance, stored in infrastructure the user controls rather than the AI company's servers, and governed by terms the user can revoke rather than a perpetual licence.

This synthesis is what Fabric is building: the context warehouse where rich context accumulates from the tools you choose to connect, the self-writing documentation structures that context into queryable knowledge, the AI assistant draws on it for every interaction, and the agents act on it on your behalf. The context is as rich as Instinct's. The privacy model is its opposite.

The Instinct story isn't a cautionary tale about AI assistants. It's a validation of the goal (deep context) and a rejection of one approach to achieving it (surveillance). The AI assistants that win will be the ones that achieve Instinct-level usefulness through user-controlled context rather than comprehensive surveillance. The question was never whether AI should know you. It was how it should come to know you.


Frequently asked questions

Is Instinct a bad product? The capability is impressive. The privacy model is the problem. The AI's usefulness, based on tester reports, was genuine and significant. The question is whether that usefulness justifies the data access and the terms of service. For some people, it does. For most, the terms are too aggressive.

What happened to Instinct after the controversy? The company revised some terms under pressure. The core data access model (screen capture, keyboard logging, email access) remained. The long-term viability depends on whether the revised terms satisfy users and whether the product's capability is compelling enough to overcome the trust deficit.

Can Fabric really match Instinct's context depth? For most professional use cases, yes. Fabric's connected tools (email, Slack, meetings, files, CRM) provide rich, structured context. Instinct's additional data (screen captures, keyboard inputs, location) provides marginal context for most knowledge work. The cases where surveillance data is essential (ambient computing, physical-world assistance) are real but narrow.

What about Apple Intelligence? Is that the surveillance model or the deliberate model? Apple's approach is closer to the deliberate model: on-device processing where possible, user-controlled permissions, and privacy as a design principle. The limitation is that Apple's AI capabilities are less advanced than dedicated AI assistants. The privacy model is right. The AI quality is catching up.

Should I try Instinct? Read the terms of service and the privacy policy first. Understand what data is collected, how it's stored, and what rights you're granting. If you're comfortable with the terms, the product is capable. If you're not, Fabric provides deep context through a fundamentally different privacy model.

Will other AI assistants follow Instinct's surveillance approach? Some will. The surveillance model produces the most immediately impressive demos because the context is maximal. The market will likely split between surveillance-model assistants (maximum convenience, maximum exposure) and deliberate-context assistants (controlled convenience, controlled exposure). Enterprise adoption will overwhelmingly favour the deliberate model.

What's the long-term risk of the surveillance model? The accumulated data from screen captures, keyboard inputs, emails, messages, and location creates a comprehensive digital profile that's a high-value target for breaches, a liability in acquisitions, and a risk in regulatory changes. The perpetual licence means the risk doesn't end when you stop using the product. The deliberate model (data in your infrastructure, revocable access) limits these risks architecturally.

Is this the same debate as the encryption debate? Similar structure. Maximum access produces maximum capability (for the tool, for law enforcement, for whoever). Maximum privacy produces reduced capability but reduced risk. The answer in encryption (strong encryption by default, user-controlled access) is analogous to the answer for AI context (user-controlled context, stored in user infrastructure, revocable access).


Related reading: Instinct and the case for a private context layer, Own your data, own your AI, Who controls your intelligence?, Where does your knowledge live?. Related pages: Private and secure, Privacy policy, Fabric vs Instinct.


The workspace that thinks with you.

Ready when you are.

The workspace that thinks with you.

Ready when you are.

The workspace that thinks with you.

Ready when you are.