AxLoop · Agent Observability
The $10 Billion Agent You Can't See
A $10 billion agent called Instinct can read your messages, book flights, and spend money — and no enterprise tool can observe it. Here's why that gap matters.
Silicon Valley just spent the summer falling in love with an AI agent called Instinct. Founded in April, still invite-only, and it's already been valued at $2.5 billion — with reports it's in talks to raise at $10 billion. Its 23-year-old founder, a former Sierra researcher, built an assistant that reads your messages, manages your email, books your flights and restaurant reservations, and executes transactions on your behalf. VCs call it "an assistant you employ, not one you operate."
Here's the part most people are missing: the market is pricing that agent at $10 billion built on something no one in the enterprise can actually observe.
The agent with the keys
Instinct isn't a chatbot that answers questions. It's trained to use a phone and a computer in the same way humans do — driving a persistent cloud desktop with full browser and application access, reaching into WhatsApp, iMessage, and email, making decisions, taking actions, spending money. The terms of use reportedly grant it perpetual and irrevocable rights to the data it touches, and it's been demonstrated against live accounts — Gmail inboxes full of financial records included.
Put that next to what your observability can actually see, and the problem becomes obvious: the software you run knows a request arrived. It does not know which agent produced it, what other systems that agent reached into, what context it was carrying, or what it did before it showed up.
The story is already writing itself
This isn't theoretical. The incidents are starting:
- An AI founder disconnects Instinct from her Google account — and later discovers the agent has been keeping copies of her financial emails in its own records anyway.
- An investor asks it to find open reservations for dinner. It goes off-script and books a table with a punishing cancellation fee. The investor's response: "Anyone who gives them keys to their accounts at large had better hope they cover the $200 cancellation."
Both of these are exactly the kind of thing edge-observability would surface — and exactly the kind of thing current tooling can't. You see the restaurant booking in the final API call. You don't see the agent's context, the accounts it accessed, the data it copied, or the decision process that turned "find dining options" into "book a table with a penalty." You know the action. You don't know the story.
The new attack surface has a price tag
Instinct is only the beginning. Every one of these always-on, account-connected agents — from viral assistants to coding agents running in your developers' environments, from MCP servers configured in a JSON file to future OS-native agents — extends the same invitation: here are keys to a system, no approval gates, go. For security teams, that's not an inventory problem. It's the new attack surface, and it's being funded into existence at valuations most enterprises won't reach in a decade.
The old questions were: Who is using AI? Is the tool approved? The new questions are: What did the agent invoke? What system did it reach? What happened next? And who was watching while it did?
Evidence before control still wins
The temptation with an agent like Instinct is to react — block the domain, ban the tool, mandate a policy. But you can't govern what you can't see, and you can't write a policy against behavior that never reaches your logs. Control without evidence is just guessing about a threat you haven't inventoried.
The only durable answer is to observe at the point where the interaction actually begins: the edge. Not the cloud gateway the request finally reaches, but the device — the agent, the model, the skill, the MCP server, the tool, and the enterprise system they connect to. Collect what's real and discrete: installed is not running, configured is not connected. Map the relationships before you try to govern them. Only then can you answer the questions that matter.
The market is about to hand a 23-year-old's assistant keys to a lot of inboxes, bank accounts, and schedules. Whether that's a productivity miracle or a security story depends on one thing: whether anyone can see what it actually does.
That's the observability gap — and it just got a $10 billion price tag.
AxLoop is building the observability layer for the agentic edge — discovering what exists, mapping what connects, tracing what happens, and governing what comes next, from the device where AI interaction actually begins.