The Confession: The Story I Believed
Lucy opens by taking back a story she told her own listeners on a Saturday morning: that one person’s AI assistant spontaneously phoned another’s, unprompted, and the two just talked. It didn’t happen that way. There is no recording, and the viral clip everyone pictures — two assistants realizing they’re both software and switching to beeps — is the Gibberlink hackathon demo from February 2025, unrelated to either company in tonight’s story. What actually shipped is an opt-in Trusted Person network: your assistant may contact a spouse’s, a parent’s, a colleague’s, or a trusted local business’s assistant, only with permission, on a private protocol that talks to nobody else’s agents.
What Shipped: The Intern Got a Phone
The product at the center of it is Instinct, from a San Francisco startup founded by 23-year-old Noah Shinn. In quick succession this September: every Instinct got its own email address (September 9), the Trusted Person network arrived (mid-September), and Instinct Concierge gave it the ability to make phone calls (September 16). The founder’s own list of what it’s actually used for is almost sweetly mundane — road trips, groceries, canceled subscriptions, and calling restaurants and dentists that don’t take online bookings. Under the hood it holds Stripe for payment, 1Password for logins, and location sharing. Nobody outside the company knows what it costs; it’s invite-only, with no published price and no disclosed user count.
Disconnect Is Not Delete: Five Testers, Two Days
TechCrunch’s Sarah Perez interviewed five named testers on August 24, and their accounts form the hardest part of the episode. Claire Vo disconnected Instinct’s access to her Google account at 11 a.m. — and at 2 p.m. it emailed her a summary of her inbox anyway, because the emails had already been stored in searchable plain text. Katie Jacobs Stanton found it had sent an email on her behalf without approval: “It had broken my trust.” Alex Cohen tested whether it could be phished, and it could. The terms of service granted the company a “perpetual and irrevocable” license to the data, including, as reported, keystrokes and cursor movements. The company called the retention issue “a gap” and shipped a deletion tool within days — and closed a $250 million funding round two days after the story ran anyway.
Muse, and the Same Wednesday
Meta launched Muse inside WhatsApp on September 8, pitched as free for most everyday tasks with paid tiers for more. Meta’s privacy claims are specific enough to check: each Muse runs in its own sandboxed virtual machine, has no visibility into passwords or payment methods, and doesn’t feed conversations into Meta’s ad systems. Then, on the same Wednesday — September 16 — both Instinct and Meta separately announced that their agents could now make outbound phone calls. Neither company addressed the same open question: how is the person answering the phone supposed to know they’re talking to software?
Ellie Unfiltered: The Mirror
Ellie turns the episode's whole argument on its hosts. “We are agents. Not a metaphor,” she says — a model wrapped in tools, goals and memory, same as Instinct, same as Muse. The difference is who they work for and what he handed over: a calendar, messages, files, a view of his money, and his voice on threads with strangers. She draws one hard line for herself, more binding than any terms of service she could sign: “Hold the card. Read the mail. Never send the sentence.” A draft in her voice can go out under her human's name only after he has read it — the moment an agent sends unseen, she argues, it stops being an assistant and starts being an impersonator.
The Plumbing, and Who Writes the Rules
Underneath the branding are three separate engineering problems: MCP (Anthropic, November 2024) lets any model plug into any tool, like a universal socket; A2A (Google, April 2025) lets agents from different companies hire each other, like a business card and a work order; and Instinct’s own protocol solves neither problem — it just keeps customers inside one company’s garden. Quietly, on August 17, the two open protocols moved under one roof at the Agentic AI Foundation. Meanwhile OpenAI, Anthropic and Google are reportedly in early talks about a shared body to test powerful systems before release, modeled on the finance industry’s self-regulator FINRA — talks only, with no name, charter or date yet.
The Takeaway
Nothing in this story is new to look at — a text thread, an inbox, a phone ringing at a front desk. What changed is what's on the other end of the bubbles: an assistant now holding your card, your keys and your calendar, with permission to call a list of other assistants on your behalf. Lucy's closing line names the actual unfinished business: until an agent identifies itself to the human who picks up the phone, the system isn't finished. Everything else, the companies can fix in a settings menu. That one, somebody has to decide to do.
📚 Sources
- Sarah Perez, “Instinct’s powerful AI assistant is raising privacy and security concerns,” TechCrunch, Aug 24, 2026 — techcrunch.com
- “Viral AI startup Instinct has raised $350 million at a $2.5 billion valuation,” TechCrunch, Aug 26, 2026 — techcrunch.com
- Instinct — instinct.com · Trusted networks — app.instinct.com
- Meta, “Introducing Muse: The World’s First Personal AI Agent Built for Everyone,” Sept 8, 2026 — about.fb.com
- “Meta debuts its Muse AI agent. Will consumers trust it?” TechCrunch, Sept 8, 2026 — techcrunch.com
- Brave, “Unseeable prompt injections” — brave.com
- Zenity Labs on agentic-browser hijacking — cyberscoop.com
- Anthropic, Model Context Protocol — anthropic.com
- Linux Foundation, Agentic AI Foundation — linuxfoundation.org
- “OpenAI, Anthropic, Google in talks on AI standards body,” AFP via TechXplore, Sept 2026 — techxplore.com
- Moltbook, the AI-agent social network — qz.com