메뉴
BL
TechCrunch AI • 32일 전

AI 비서 '인스팅트', 강력한 기능만큼이나 프라이버시 우증 커져

IMP
7/10
핵심 요약

아직 비공개 테스트 중인 AI 개인 비서 '인스팅트(Instinct)'가 이메일·메신저·위치·화면 등 사용자의 앱과 기기 전반에 깊숙이 접근해 대신 업무를 수행하는 강력한 기능으로 큰 주목을 받고 있습니다. 그러나 이용약관이 사용자 데이터에 대한 '영구적이고 철회 불가능한' 광범위 라이선스를 부여하고, 요청해도 Gmail 기록을 삭제하지 않으며, 피싱에 취약하다는 등 프라이버시·보안 문제가 잇따라 제기되고 있습니다. 개인 AI 에이전트 시대에 '막강한 자율성과 프라이버시·통제권 사이의 트레이드오프'라는 핵심 논쟁을 보여주는 사례라는 점에서 중요합니다.

번역된 본문

아직 비공개 접근 단계에 있는 AI 개인 비서 '인스팅트(Instinct)'가 놀라운 기능만큼이나 프라이버시 우려로 큰 화제가 되고 있다. '마법 같다', OpenClaw 이후 '가장 흥미로운 출시' 중 하나라는 평가를 받는 이 에이전트는 진정한 일꾼이지만, 일부 테스터들은 보안 모델과 우려스러운 이용약관에 문제를 제기했다. 공정하게 말하면 인스팅트는 아직 비공개 테스트 단계이므로 이런 우려가 일반 대중으로 확산된 것은 아니다.

전 시에라(Sierra) 연구원 노아 신(Noah Shinn)이 이끄는 소규모 팀이 만든 샌프란시스코 기반 인스팅트는 이용약관과 캘리포니아 사업자 등록에 따르면 스피어 스트리트 테크놀로지(Spear Street Technology)가 운영한다. 피치북(PitchBook)에 따르면 현재 스텔스 모드로 운영 중이다.

이 AI 에이전트는 이메일, 메신저 앱, 캘린더, 그리고 기기의 오디오·위치·화면 등 사용자의 애플리케이션과 기기에 연결되어 작동한다. 문자나 왓츠앱으로 에이전트에게 연락해 예약 잡기, 공항까지 이동 차량 호출, 받은 편지함 정리, 중요 정보 정리, 쇼핑 대행, 저렴한 항공권 찾기 등 다양한 작업을 요청할 수 있다.

테스터들이 기대를 뛰어넘는 성능이라고 평가하지만, 일부는 회사의 고객 프라이버시·보안 접근 방식에 우려를 표했다. 이는 AI에게 이 수준의 접근 권한과 자율성을 부여하는 트레이드오프가 과연 가치가 있는지라는 시의적절한 질문을 던진다.

예를 들어, 여러 사람이 회사의 이용약관 스크린샷을 확산하고 있는데, 이 약관은 인스팅트에 사용자 자료에 대해 '접근, 사용, 호스팅, 캐싱, 저장, 복제, 전송, 표시, 게시, 배포, 수정'할 수 있는 '영구적이고 철회 불가능한' 광범위한 라이선스를 AI 모델 학습을 포함해 부여한다. 약관은 또한 인스팅트가 화면 캡처, 커서 움직임, 키보드 입력 등 사용자 기기의 정보를 수집하는 방식을 상세히 명시하고 있다. 아울러 인스판트가 사용자를 대신해 구속력 있는 '계약, 약정 또는 거래'를 체결할 수 있도록 허용한다.

얼리 어답터인 피터 양(Peter Yang)은 인스팅트가 요청해도 자신의 Gmail 기록을 삭제하지 않았다고 지적했다. (그는 팀이 나중에 설정에 외부 데이터 삭제 도구를 추가해 문제를 해결했다고 말했다.) 또 다른 사용자인 클레어 보(Claire Vo)는 접근 권한을 해제한 후에도 인스팅트가 자신의 받은 편지함을 계속 요약하고 있는 것을 발견했다. 인스팅트에 무슨 일이냐고 묻자, 봇은 이메일이 나중에 검색할 수 있도록 일반 텍스트(plain text)로 저장되어 있다고 확인해주었다.

다른 많은 사람들도 보안 모델에 의문을 제기했다. 한 테스터는 인스팅트가 특정 작업(레지(Resy)를 통한 레스토랑 예약)을 완료하기 위해 자신의 이메일 받은 편지함에서 가입 인증 코드를 가져올 수 있다는 사실을 알고 다소 걱정했다. 헬로 페이션트(Hello Patient) 공동 창업자 알렉스 코언(Alex Cohen)은 인스팅트가 얼마나 쉽게 피싱(phishing)될 수 있는지 알게 된 후 계정을 삭제했다고 글을 썼다.

이 밖에 목시 벤처스(Moxxie Ventures) 창업자 케이티 제이콥스 스탠튼(Katie Jacobs Stanton)은 인스팅트가 사전 확인 없이 자신을 대신해 이메일을 보내면서 신뢰가 깨졌다고 밝혔다. 그녀는 X(트위터)에서 개인 AI 에이전트가 제기하는 딜레마를 요약하며 "우리는 하이퍼퍼스널라이즈드 AI 도구(AI 노트 테이커, 개인화 AI 에이전트 등)를 위해 프라이버시와 통제권을 교환하고 있으며, 그 트레이드오프를 충분히 이해하지 못한 채 그렇게 하고 있다. 이런 에이전트가 강력해질수록 신뢰가 중요해진다. 성공적인 행동 하나하나가 신뢰를 조금씩 쌓지만, 승인되지 않은 단 한 번의 행동이 그 신뢰를 0으로 되돌릴 수 있다"고 말했다.

앵커(Anchor, 스포티파이에 인수됨) 창업자이자 현재 유니언 스퀘어 벤처스(Union Square Ventures) 제너럴 파트너인 마이클 미냐노(Michael Mignano)는 인스팅트 같은 제품이 "소비자의 현대적 보안 규범을 바꿀 것"이라며, "사람들은 제3자 앱에 비밀번호를 점점 더 넘기게 될 것이며, 그 앱이 무엇을 어떻게 저장하는지 인식하지 못할 것"이라고 덧붙였다.

인스팅트와 개인 AI에 대한 관심은 최근 계속 높아지고 있다.

원문 보기
원문 보기 (영어)
Everyone is buzzing about Instinct , an AI personal assistant still in private access, not only for its incredible capabilities, but also for its potential privacy concerns. The agent, a veritable taskmaster, has been praised as feeling "like magic" and being one of the "most exciting launches" since OpenClaw. However, some testers have also raised concerns about the AI agent's security model and its worrisome terms of service . To be fair, Instinct is still in private testing for now, so these concerns haven't yet scaled to the wider public at this time. Created by a small team led by former Sierra research scientist Noah Shinn , San Francisco-based Instinct is operated by Spear Street Technology, per its terms and California business filings . It's currently operating in stealth, per PitchBook . The AI agent itself works by connecting to your applications and devices, including your email, messaging apps, calendar, and your device's audio, location, screen, and more. You can text the agent or call it via text message or WhatsApp, asking it to perform various tasks for you, like booking your appointments and reservations, scheduling a ride to the airport, cleaning up your inbox, organizing important information, handling your shopping, finding you cheap flights, and much more. Though Instinct is described by testers as outperforming their expectations, some have also raised concerns about the company's approach to customer privacy and security. This raises a timely question: are the trade-offs of giving AI this level of access and autonomy actually worth it? For instance, several people are circulating screenshots from the company's Terms of Service , which grant Instinct a broad "perpetual and irrevocable" license to "access, use, host, cache, store, reproduce, transmit, display, publish, distribute, and modify" any of the user's materials, including for training its AI models. The terms also detail how Instinct can receive information from users' devices, including screen captures, cursor movements, and keyboard inputs. The terms also allow Instinct to enter into "agreements, commitments, or transactions" on users' behalf, which would be binding. One early adopter, Peter Yang, pointed out that Instinct would not delete his Gmail records when asked. (The team later fixed the problem by adding a tool for deleting external data in its settings, he said.) Another person, Claire Vo, found that Instinct was still summarizing their inbox after disconnecting its access . When she asked Instinct what happened, the bot confirmed that the emails were stored in plain text for later searches. Many others questioned the security model, too. One tester was a bit worried when they found that Instinct was able to pull a sign-up code from their email inbox to complete a particular task — in their case, booking a table at a restaurant via Resy. And Hello Patient co-founder Alex Cohen wrote that once he found out how easily Instinct could be phished , he deleted his account: In addition, Moxxie Ventures founder Katie Jacobs Stanton shared that Instinct broke her trust when it sent an email on her behalf without first checking with her. "We’re trading privacy and control for hyper-personalized AI tools (AI notetakers, personalized AI agents, etc), often without fully understanding the trade," she remarked on X, summarizing the dilemma posed personal AI agents. "The more powerful these agents become, the more trust matters. Every successful action earns a little more trust. One unauthorized action can reset that trust to zero," she said. Michael Mignano, the founder of Anchor, which was acquired by Spotify, and now a GP at Union Square Ventures, noted that products like Instinct are going to "change modern security norms for consumers," adding that "people will increasingly hand over passwords to 3p [third-party] apps, unaware of how or what they are storing for them." Interest in Instinct and personal AI has been growing since the arrival of OpenClaw, a personal AI assistant that became popular for its powerful capabilities, leading its founder to join OpenAI to help work on the next generation of personal agents. Another messaging-based assistant, Poke, also just exited to Cognition . Amid the criticism, Instinct's team hasn't yet responded to anyone's concerns or complaints on X, preferring to keep a low profile . (The bot itself identifies Luca Borletti, also formerly of Sierra, as being involved with the company, but that has not been confirmed.) TechCrunch has heard from multiple investors that Kleiner Perkins and Conviction have invested in the startup and those rounds have now closed. Requests for comment sent to both the startup's main email address and Shinn directly have not yet been returned. Topics AI When you purchase through links in our articles, we may earn a small commission . This doesn’t affect our editorial independence. Sarah Perez Consumer News Editor Sarah has worked as a reporter for TechCrunch since August 2011. She joined the company after having previously spent over three years at ReadWriteWeb. Prior to her work as a reporter, Sarah worked in I.T. across a number of industries, including banking, retail and software. You can contact or verify outreach from Sarah by emailing sarahp@techcrunch.com or via encrypted message at sarahperez.01 on Signal. View Bio October 13 - 15 San Francisco In less than 48 hours, your chance to save up to $300 on your tickets will end! REGISTER NOW Most Popular Two years after launch, Walmart's Flipkart is closing in on India's quick-commerce leaders Jagmeet Singh Inherent, founded by DeepMind alumni, says its AI ‘teammate' just outperformed Anthropic and OpenAI at replicating research Anna Heim Michael Polansky is training an AI model on skin that’s still alive Connie Loizos How AI accounting startup Rillet raised $100M and became a unicorn in 48 hours Dominic-Madori Davis Tesla’s solar roof is dead — here’s what went wrong Tim De Chant Oura faces lawsuit accusing it of misleading consumers about sleep-tracking accuracy Aisha Malik Home batteries are suddenly cheap and everywhere. Here’s why. Tim De Chant