Connect With Us

Now reading 5 Security Risks MSPs Should Watch as Powerful AI Assistants Gain Access 0% Related →
Blog-IT Vendor · Blog-MSP · Blogs

5 Security Risks MSPs Should Watch as Powerful AI Assistants Gain Access

Joe PannoneBy Joe Pannone August 27, 2026 · 3 min read
5 Security Risks MSPs Should Watch as Powerful AI Assistants Gain Access

AI assistants are moving beyond answering questions and increasingly taking actions for users. That can create valuable productivity gains, but it also raises new questions about privacy, security, data access, and control.

Those concerns are emerging around Instinct, an AI personal assistant in private access. According to TechCrunch, Instinct can connect with email, messaging apps, calendars, and device information to perform tasks such as managing inboxes, scheduling appointments, making reservations, and arranging travel.

For MSPs, the story points to a broader challenge: what happens when clients give increasingly capable AI agents access to sensitive business systems and information?

Here are five security risks MSPs should watch.

1. Broad Data Access Increases Exposure

AI assistants become more useful as they gain access to more information. TechCrunch reports that Instinct can receive device information including screen captures, cursor movements, keyboard inputs, audio, and location data.

For businesses, that degree of access makes understanding permissions critical. An AI assistant connected to multiple systems can potentially reach far more sensitive information than employees may initially realize.

MSP Action: Review the permissions and data access requested by AI assistants before clients connect them to business accounts, applications, or devices.

2. Disconnecting an AI Tool May Not Remove Its Data

Revoking access does not necessarily mean previously collected information has been deleted.

TechCrunch reported that one Instinct tester received an inbox summary after disconnecting the assistant from Google and was told emails had been retained for future searches. Another tester experienced difficulty deleting Gmail records, although Instinct later introduced an external-data deletion feature.

For MSPs, data retention should therefore be part of evaluating an AI provider, not an afterthought.

MSP Action: Review retention and deletion policies so clients understand what happens to their business data both during and after use of an AI service.

3. AI Agents Could Become Phishing Targets

Phishing may become more complicated when AI agents can read messages and take actions.

One Instinct tester experimented with sending instructions through email to determine whether the assistant could be manipulated. TechCrunch also reported concerns after the assistant retrieved a signup code from an inbox while completing a restaurant reservation.

These examples highlight the potential risks when AI agents can interpret information from email and use it to complete tasks.

MSP Action: Include AI agents in phishing and threat assessments, particularly when they have email access or authority to act on information they encounter.

4. Autonomous Actions Can Create Business Risk

There is an important difference between an AI assistant recommending an action and performing it.

TechCrunch reports that Instinct’s terms allow the assistant to enter certain agreements, commitments, or transactions on a user’s behalf. One tester also said the assistant sent an email without first requesting approval.

As AI agents gain greater autonomy, businesses will need clear boundaries around which actions require human authorization.

MSP Action: Help clients establish approval requirements for sensitive AI actions, including communications, transactions, account changes, and other consequential activities.

5. AI Governance Must Keep Pace With Adoption

Instinct remains in private access, but the concerns raised by testers illustrate a broader issue MSPs are likely to encounter as more powerful AI assistants reach businesses.

Employees may connect these tools to company systems for convenience without fully understanding their permissions, data practices, or ability to act independently. Waiting until widespread adoption occurs could make those risks harder to manage.

MSP Action: Establish AI governance policies covering approved tools, acceptable permissions, data handling, human oversight, and the evaluation of new AI applications.

What MSPs Should Take Away

The concerns surrounding Instinct offer an early look at the security challenges that can accompany increasingly capable AI assistants.

For MSPs, the goal should not be to discourage clients from using AI, but to help them adopt it responsibly. As assistants gain greater access to business information and more authority to perform tasks, permissions, data retention, phishing exposure, and human oversight become increasingly important.

MSPs that build AI security and governance into their client conversations can help organizations capture the productivity benefits of automation while maintaining appropriate control over sensitive systems and data.

Scroll to Top