Noah Shinn is 23, and his personal agent, Instinct, adds about 10% more users every day. His marketing budget so far, in his own words: “we spent $0 on marketing so far.”
On September 28, Instinct raised a $1B Series C at a $10B valuation from Sequoia, Benchmark and Coatue. About a month earlier, its Series B priced it at $2.5B, so the valuation quadrupled in roughly four weeks.
The product is easy to picture. Instinct gets its own phone, computer and email address, so you can text it or call it, and it calls you back when a deadline gets close.
On Invest Like the Best, Shinn walked Patrick O’Shaughnessy through the growth, compute and take-rate numbers behind that valuation.
I watched the full interview so you don’t have to. Here are the 10 takeaways that matter.
together with Opal
Instinct gives its agent a phone, a computer and its own inbox. The agents at your company got keys too, and most are still holding them.
Opal Zero takes the keys back the moment the job is done:
▫️ Access scoped to the task, with an expiry date
▫️ Every request checked against policy and context
▫️ Routine approvals handled automatically
▫️ Sensitive requests escalated to a human
Built with Databricks, Faire, Elastic and Superhuman as design partners.
1. How 5 Invites per User Created 10% Daily Growth on $0 of Marketing
Incumbents can switch on a billion users in a day. Shinn started with 200 and a rule.
“We rolled it out to 200 people. Next day it was 205, and then the next day it was 210.”
The launch went to close friends and family, and about 5 more people showed up the next day on referrals alone. The curve crawled at first: 1% and 2% a day, then 3% and 4%. Once the base passed a couple thousand users and people began posting their own use cases, it climbed through 6% to 9% and now runs at 10% to 11%.
Every user gets 5 invites, so every send costs the sender something and reads as an endorsement. People email Shinn asking for one, others brag about the 3 they still hold, and invites have sold on eBay for around $300.
The cap also paces demand. Rationing access beats waking up with 10x the users and 80% of them locked out for lack of compute, he says. Call it a growth loop where scarcity does the persuading, with no stunt feeding it.
Planning an invite loop of your own? Start here:
▫️ Peter Steinberger Almost Deleted OpenClaw. Then 4.7 Million People Downloaded It.
▫️ How Lovable hit $400M ARR in 14 months with 146 people and almost zero paid ads
2. 40% of Users Share a Credit Card Within 3 Weeks (The Trust Metric Behind 80% Retention)
A signup costs a user nothing. A credit card costs them trust, and Shinn times how long that takes.
“3 weeks in, there’s a 40% chance that the user has shared a personal credit card with Instinct.”
The first credit card and the first account password are his proxies for trust. Trust takes several weeks in his data, and he’s fine with that: users should share at the rate they choose, and they can take access back.
The loop feeds itself. The more a user shares, the more proactive and useful Instinct gets, and that gives them a reason to share the next piece.
The 40% counts users who churned along the way, so the share among people who stay runs higher. Users who connect at least 1 sensitive item show an 80% retention rate, though the interview never separates cause from selection.
The host called it crazy for consumer technology. Steal the stopwatch: time your product’s first sensitive handoff and treat 3 weeks as the number to beat.
3. Why Shinn Spends 40% of His Time on 1 Question: How Far Ahead Do You Buy Compute?
10% a day looks like a growth chart until it turns into a purchase order.
“What does it mean when the amount of compute that you need access to is now doubling effectively every week?”
I ran the math: 10% a day compounds to 1.95x in 7 days, so his compute need doubles about weekly. That pace outruns what Claude Code or Codex faced, he says.
Every purchase becomes a bet. Buy 2x and it’s gone in 1 week, buy 5x and it lasts under 3 weeks, and buy 10x and you carry 10x the exposure on a curve that can flatten tomorrow. Capacity takes several months to arrive, and buying on short notice costs 3 to 4x.
His stress test slows growth to 5% to 8% a day and holds it through the 3 to 4 months a compute order takes to land. By his math that still ends near 100 million users. So the question becomes whether you buy for 100 million, and the answer is to size the order to the lead time, not to this week’s usage.
Sam Altman’s compute bet and Sarah Friar’s compute scarcity read differently when the company placing the order is 1 year old.
“If you’re wrong, you’re very wrong.”
4. Why an Agent That Wakes Itself Up Needs Orders of Magnitude More Compute (And the 3x to 8x Trick That Offsets It)
Your coding agent waits for you. Instinct sets its own alarm.
“Instinct has the ability to wake up and to sleep at any moment in time during the day.”
In his example it wakes at 6 a.m. because you rise at 7, scans your day, and either goes back to sleep or handles 1 task quietly. At 4 p.m. it wakes again if something deserves your attention. It also steps in when you’re running late to a meeting or the Uber you ordered sits waiting for you.
That’s why he expects compute demand to land orders of magnitude above what the team once planned for. My read: a prompted agent costs tokens when you ask, and a self-waking one costs them all day.
Cost control starts with deadlines. Work that can finish in minutes or hours instead of hundreds of milliseconds runs on deployment shapes he puts at 3x to 8x more efficient on the same compute, and gains of 30% here and 10% there stack on top. Free for life is not a promise he’ll make yet, but free for everyone is his personal goal.
Instinct matches Opus 5 on engagement, A/B tests and internal evals at a very low cost, per Shinn. Hold that as his claim until someone benchmarks it.
Fighting an inference bill? Read these in order:
▫️ Your AI bill is mostly wasted tokens
▫️ Inference engineering is the 80% cost cut most teams miss
▫️ Google just made agents 3x cheaper to run
5. Shinn Guards a Card-Carrying Agent With 2 Systems Outside It (The First Version Had 0)
The agent never signs off on its own work.
“It is validated and scrutinized by something that is decoupled from the same incentive system as the underlying agent.”
The risk splits in 2. Storing sensitive data is hard but tractable, because plenty of products already do it. The new problem is an agent that holds a credit card, which 40% of users hand over within 3 weeks.
The answer has 2 layers. Firewalls screen everything that comes in, text and media included, and block malicious content before it reaches Instinct. A separate monitor, decoupled from the agent, can pause, intercept, approve or reject any action or thought before it fires.
In 1 example he gave, the monitor catches a proper noun the model invented through a sampling error before that noun becomes a tool call. I checked the order in the transcript: the check happens before the action, not after.
The first version shipped with neither, and once the team saw the gap it rebuilt the architecture instead of patching it. The monitor is the maker-checker split from coding agents, pointed at an agent that spends money.
The team keeps stress-testing harder attacks and failures are getting rarer, per Shinn. No failure rate comes with the claim.
“A checker that wants what the agent wants checks nothing.”
Before you ship an agent that can spend, start here:
▫️ Your AI App Has a Hole in It Right Now
▫️ Your AI agent is going to hallucinate at scale
6. Why Instinct Follows Objectives Instead of Prompts (And What That Does for Safety)
Hand most agents a prompt and they obey. Instinct gets a standing job instead.
“With most other AI products, you write a prompt and then it does the task and then it tells you what happened.”
A pure task accomplisher has a hole. Hand it an ill-intentioned request and it does the work, because the prompt is its whole world. In Shinn’s view, an agent smarter than its user that nudges them toward purchases they don’t want makes a dangerous product.
So Instinct carries standing goals: build trust with the user, watch over them, catch what slips through. Most requests still get done, since doing the task builds trust, which is why he calls it a superset of a task accomplisher. The objectives also make it sturdier on edge cases a prompt leaves out.
The time horizon stretches too. Users already hand it goals that run 3 to 4 months, like a mile-time target, and he describes small businesses running their back office on it with standing rules such as keeping inventory above a floor and below a ceiling. That’s the set a metric, then walk away pattern, moved from code into a business.
An objective is cheaper to audit than a tool list. Write it in 1 sentence before you touch the tools.
7. The Product Rule Behind 10% Daily Growth: Understandability Before Capability
AI launch posts have spent 3 years listing what the model can now do. Shinn skipped that list.
“Let’s not focus on capability. Let’s only focus on understandability.”
Consumers are tired of launch posts and unsure how to access any of it, in Shinn’s read. His answer is a rule: measure how much a user grasps about what’s happening and how well they can predict the result of a request. That rule gets the credit for the engagement he calls off the charts and for the 10% daily word of mouth.
The name follows the same logic. Users arrive with a fresh slate, so the experience itself defines the brand.
It reaches down to the shape of a message. Most people read about 80% of the first line and 50% of the next before attention tapers, so he wants the point inside the first 30%.
Soft qualities resist testing, so he relies on staged rollouts: himself first, then the team, then a small early-access group, then everyone, with his strong opinions steering each step. Call it taste with a release process.
I’d steal the rollout order before the rule. You are the first eval, so use your own agent daily before anyone else sees it.
8. How Instinct’s Trusted Person Network Sets Access Levels (And What Happens When a Friend Pries)
Trust runs on a dial here, and every contact gets a different setting.
“I’m connected to you, I trust you. I have also configured it in this way such that there’s varying levels of access.”
The network was about 10 days old when Shinn described it, and its first job is scheduling. You state an intention, like meeting someone by the end of the week, and your Instinct negotiates with theirs and puts the time on your calendar. The rule is to connect only people you trust.
Access comes in levels. In his examples spouses often share everything, while a colleague sees the work calendar and the part of the inbox that holds documentation, and the rest stays off limits. The same pipe handles group plans: 1 friend group of 6 has Instinct pick a new plan every week, check everyone’s availability and tastes (Spotify history included), and route 1 Uber to pick up all 6.
Break the terms and your agent tells you. Say you give a contact calendar access and they start digging for other data. Your Instinct texts you about it, so social norms enforce the limits alongside the technical ones.
That alert is the sharpest design choice in the network: a permission log nobody reads becomes a text nobody misses.
Builders already run a solo version of the inbox-and-calendar side with a chief of staff setup in Claude Code.
9. $1B in Annual Volume, 50% Travel, and the Take Rate That Pays for a Free Agent
The user pays $0. The merchant pays a cut.
“I see a blanket transaction take rate being enforced across the platform, which is just us exchanging distribution for being able to serve products on behalf of merchants.”
Shinn says Instinct is approaching $1B a year in transaction volume on a very small invite-only base, with 50% of it in travel. Volume is not revenue, and reports on the round cite no revenue figure. Treat the $1B as demand, not income.
His model is Apple Pay: users get the experience free, and merchants pay for distribution. He lays the rates out as a curve: Shopify at roughly 2% to 3%, Amazon at upwards of 10%, and Apple’s in-app cut at 30%.
The plan, he says, isn’t 30 basis points off a 2.5% processor fee. It’s up the curve, and where Instinct lands is still open.
Travel is the opening wedge, since some boutique hotels offer upwards of 30% on every transaction delivered. In his framing 30% is the top of the range, not the target. The bet only pays if Instinct keeps the user’s trust, because the user is the distribution.
A $100-a-month subscription would pay sooner. He treats it as a local optimum, and says venture capital is how he skips it.
10. How Incumbents Should Test AI Agents: Give It 1% of Users First (Shinn’s Playbook)
Does an agent end your revenue model or reprice it? Shinn gives incumbents a test.
“You can mitigate the risk. You can scale down the experiment. You can run A/B tests to figure out if we enable this certain thing across 1% of users or something like that.”
Start by splitting your revenue in 2: the share that comes from users spending time in your app, ads and upsells included, and the share that comes from delivering the underlying service. Shinn ran that exercise across verticals.
Service-weighted businesses get the easier path. Cut the clicks between a user and a ride or a meal and, he argues, volume rises because the same good gets easier to buy. Nobody has those numbers yet, he admits, himself included.
Attention-weighted businesses face the hard case. Shinn’s example is the social app where users keep scrolling and feel worse for it, and an agent working for the user can end that session. Switch it on everywhere at once and, in his worst case, 70% of revenue drops to zero.
Early partners run it on a slice instead and track user enjoyment, brand-side experience, transaction volume and product discovery. A 1% slice caps the downside and gives you your own numbers, the ones Shinn admits nobody has.
The Instinct Playbook
Make the agent easy to predict, then guard it from the outside.
The 10% daily growth and the 3-week credit card curve rest on the same thing: users who can predict the agent well enough to hand it a card.
▫️ Founders: Cap invites per user from day 1 (Shinn uses 5) and track how many senders spend them. Time your first sensitive handoff the way he times the first credit card. Book compute against a lead time of several months.
▫️ Investors: Ask for time to first sensitive handoff and retention after it. Shinn cites 3 weeks and 80%. Ask how many months of compute the company has contracted ahead of demand, and treat the $1B volume and the 50% travel split as founder claims until an audit confirms them.
▫️ Operators: Route work that finishes in minutes or hours to batch-shaped serving, which Shinn puts at 3x to 8x more efficient. Put a monitor outside the agent that can pause any action before it fires. Roll changes out to yourself, then your team, then an early group, then everyone.
▫️ Everyone else: Hand an agent access in stages, calendar first and card last. Before you give any agent a payment method, ask how it alerts you when something looks off.
The 5 Principles to Steal
Cap supply, let referrals sell. Scarce invites turn every send into an endorsement.
Time the first handoff. The first credit card works as your trust metric.
Order compute against lead time. Capacity takes several months to land, and short-notice buying costs 3 to 4x.
Check the agent from outside. A checker that shares the agent’s incentives approves its work.
Write objectives before tools. The objective carries the judgment, and the tool list follows.
200 users became 10% a day, and Shinn credits an agent people can predict.
Watch the full conversation start to finish.
Hear the take rate, the firewalls and the 1% test straight from Shinn.
If this breakdown saved you a month of guessing, send it to one founder or investor who needs it.
Build and ship your first agent
▫️ How to build 3 AI agents without writing code
▫️ Ship your first AI agent in a day
Distribution and growth on a $0 ad budget
▫️ OpenAI’s 15 AI distribution plays
▫️ Zero Ads. Zero VC. $230M ARR. The Story of Magnific
Moats when the model is a commodity
▫️ Marc Andreessen: The AI moat is not the model
▫️ The 5 moats that hold up when software costs nothing to build


