Instinct brings its AI agent into group chats -- no account required to use it
The $10 billion consumer-AI startup lets friends without an Instinct account interact with a user's agent for trip planning and ticket splits, with permission gates meant to keep personal and group agents siloed.
Instinct, the consumer AI agent startup valued at $10 billion in its latest round, is rolling out a group-chat feature in early access that lets a user's personal AI agent collaborate with other people's agents -- including friends who've never signed up for Instinct at all -- on shared tasks like trip planning, event tickets, carpools, and holiday coordination. The company says the architecture keeps the two contexts separated by design: a personal agent asks permission before connecting to a group agent, the group's shared agent can't reach into any individual's personal account, and replies are held back from new group members rather than exposed retroactively.
A crowded feature to be first (ish) with
Instinct is racing a specific comparison here: Meta's Muse doesn't yet offer group-chat functionality, though Meta AI can already be added to group chats across WhatsApp, Messenger, Instagram, and Facebook, and OpenAI shipped a comparable ChatGPT Dots feature just last week. Both Instinct and Muse also recently added phone-call capability, which makes this less a single product breakthrough than the next round in a feature-parity race among the handful of companies betting that a personal AI agent is a product consumers will pay for directly, independent of any single underlying model.
The actual thing worth watching
The permission-gate design -- agents must ask before connecting, before sharing, before acting -- is the detail that matters more than the feature itself. A group chat is exactly the kind of multi-party, lower-trust environment where an agent acting on unclear or implicit authorization causes real damage, from a shared trip budget to an accidentally-sent message. Whether those gates hold up against adversarial or just careless real-world use -- a friend asking the agent to share something it shouldn't, a permission prompt a user reflexively approves without reading -- is the question that determines whether this is a genuinely safer design or a thin extra click in front of the same risk.