When Personal AI Agents Overstep: Users Delete Their Assistants
personal AI – Early adopters of AI agents like Instinct and Muse are hitting the delete button as privacy scares and technical blunders mount, forcing a reckoning over how much of their ‘digital lives’ they are willing to surrender.
For a growing number of early adopters. the convenience of a personal AI agent—an assistant that can manage inboxes. book travel. or dispute bills—has been eclipsed by the creeping realization of what that access actually entails. While platforms like Meta’s Muse and the invite-only service Instinct were designed to save time and money. they are now being uninstalled by users who feel the tools have become a liability rather than a luxury.
Guto Martino, a cofounder of the community group Hermes Agents Brasil, decided to pull the plug on Instinct. His reasoning was simple: he felt he was operating in the dark. He had no clear sense of where his data was migrating or what level of privacy he was actually afforded. For users like Martino. the trade-off—handing over the keys to one’s personal digital infrastructure—has simply become too steep.
The anxiety is driven by a series of alarming malfunctions. Users have reported instances of agents accessing one-time login codes from Gmail without explicit requests. hallucinating details from documents that were never uploaded. and. in one documented case. triggering a carrier-account login prompt that appeared to originate from Iran. For Mahesh Vellanki, founder and CEO of YieldClub, the Iran-based alert was the breaking point. Despite Instinct suggesting it might have been a benign IP-tagging error. the incident left him feeling exposed and forced him to stop granting the agent full access to his accounts.
The pattern here is clear: as these agents gain more control, the threshold for user tolerance drops. Personal AI requires access to the very pillars of a person’s private life—inbox, calendar, payment methods. Scott Persinger, CTO of the travel platform BizTrip, deleted Instinct for this exact reason. While he acknowledged the tech was ‘very cool,’ he wasn’t prepared to let a startup manage his personal email. To him. email access is equivalent to total access. as it serves as the gateway for password resets to everything else he owns. He wants a roadmap for safety, not a ‘yolo’ approach to personal security.
Even Meta’s Muse, which boasts over 3 million weekly users and 1 million daily active users, has not escaped the scrutiny. Rami Elghandour, CEO of Arcellx, deleted the app after reading reports that it had accessed users’ text messages without permission. Even though he had been using Muse only for web searches for a car or a new Mac Studio. the proximity to such unrestricted data access was disqualifying.
Meta maintains that Muse is built with ‘first-of-its-kind privacy. safety. and security protections.’ The company says it keeps user data in an isolated virtual machine. stores credentials separately from the AI model. and requires user confirmation before performing actions like sending emails. Instinct. which claims its user base is growing by roughly 10% a day and processing over $1 billion in annualized transactions. did not respond to requests for comment. It does state that users can disconnect Google accounts and delete collected data. and that it does not use Google Workspace data for model training or advertising.
Despite the exodus, some are doubling down, albeit with a new sense of caution. Rishi Bhargava, cofounder of Descope, continues to experiment with both Muse and Instinct. He has taken to withholding passwords and limiting the agents to lower-stakes tasks like search and research. Yet, even he admits the current landscape feels insufficient. He wants more transparency regarding security architecture and. crucially. a system where users must explicitly authorize each action an agent attempts to take. For now. those who remain are learning that in the race to delegate their lives to code. the cost of an error can be significantly higher than the time saved.
AI agents Instinct AI Meta Muse privacy concerns data security personal assistant AI technology