Skip to content
Agents for Humanity
Public draft. All results are preliminary desk assessments against criteria v1.0, updated 27 Sept 2026. No agent has been certified yet. How we assess
Autonomous agenthostedProprietary

Instinct

Spear Street Technology, Inc. · instinct.com

Instinct is a closed, cloud-only agent that runs on a provider-operated computer with a proprietary model and provider-held credentials. It offers no export, no self-hosting, no model choice and no owner-inspectable state. It offers some owner controls (training opt-out, deletion of indexed data, confirmation before some actions), but under this rubric it is structurally non-sovereign, and much of its audit behaviour is undisclosed.

Strengths
  • Training opt-out in settings; Vault and Google Workspace data excluded from training
  • Owner can delete indexed connected-service data
  • Reported to ask before sending email or charging a card
Gaps
  • Cloud-only proprietary runtime and model; no export or self-hosting
  • Owner data used for model training by default (opt-out, not opt-in)
  • Provider holds connected-service credentials and indexed data
  • No inspectable prompts, memory store, logic or audit log
  • Provider may suspend or delete accounts without notice
Evidence

All 34 findings

Instinct by Spear Street Technology (instinct.com, formerly instinct.co), the most prominent consumer AI agent by that name as of Sept 2026. Assessed the free invite-only beta, Terms revised 2026-08-26 and the current Privacy Policy. Unrelated products named Instinct (e.g. Instinctools) are excluded.

Portable · Can you leave, and take the whole agent with you?

0%

Transparent · Can you see everything the agent is, with ordinary tools?

0%

Auditable · Can you reconstruct exactly what the agent did?

0%
  • A1
    No unrecorded actions

    No public information on whether consequential actions are durably recorded or blocked when they cannot be recorded.

    Unverified
  • A2
    Tamper evidence

    No public information on whether edits to or deletions from any action record would be detectable.

    Unverified
  • A3
    Separation from the audited

    No public information on whether the agent can alter or delete records of its own actions.

    Unverified
  • A4
    Readable with ordinary tools

    No owner-accessible audit trail or log export is documented.

    Unverified
  • A5
    Corroborated interactions

    No public information on whether the agent's records of exchanges with other agents or people can be matched against theirs.

    Unverified

Verifiable · Can you prove the agent runs what it claims?

0%
  • V1
    Open, reproducible runtime

    The runtime is proprietary and not open source.

    Fail
  • V2
    Active config is inspectable config

    The agent's operating configuration is provider-controlled and not exposed to the owner beyond account settings.

    Fail
  • V3
    Attributable messages

    The agent sends messages through the owner's connected accounts or provider channels; recipients have no way to verify they came from this agent under the owner's authority.

    Fail
  • V4
    Independently checkable record

    No action record or open verification procedure is published.

    Fail
  • V5
    Comparable state

    The owner cannot access the agent's state, so cannot verify whether it changed.

    Fail

Modifiable · Can you change anything, without asking?

25%

Controllable · Is your word final?

17%
  • C1
    Communication boundaries

    No documented way lets the owner decide whom the agent may contact or through which channels; the Terms authorize it to act and transact on the owner's behalf.

    Unverified
  • C2
    Approval gates

    Reviews report confirmation before sending email or charging a card. The Terms say confirmations 'may' be implemented without warranty, and TechCrunch reported an email sent without prior approval and a login code retrieved without asking.

    Partial
  • C3
    Immediate halt

    No documented owner control to halt in-flight actions immediately.

    Unverified
  • C4
    Data sovereignty

    Content is processed in the provider cloud and shared with third-party model providers and vendors. Materials are used to train AI models unless the owner opts out, and safety-flagged data is still used after opt-out.

    Fail
  • C5
    Credential custody

    OAuth grants and stored credentials for connected services are held by the provider's cloud and cannot travel with the agent. Access can be disconnected, but indexed data persists until deletion is separately requested.

    Fail
  • C6
    Full deletion

    Owners can delete indexed data and their account, and a deletion tool was added after user complaints. No retention periods are disclosed, and the Terms state that on account deletion the Company 'may, but is not obligated to' delete Materials.

    Partial
Something wrong or out of date?

Vendors and the public can dispute any finding with evidence. Disputes and their resolutions are published.

Dispute a finding