
Imagine you ask an agent to cancel a subscription you forgot about. It does, and you feel a small rush of relief. A few days later it books a dinner. Then it asks whether it can pay for something. The first time, it waits for your approval. The next time, it asks again. After a few successful runs, it might ask whether you want it to handle that specific kind of purchase automatically, within limits you set.Â
You can say yes. You can keep approval on. You can set a dollar limit. You can change your mind later.Â
That progression is the part of this market I keep thinking about, because the future of personal agents will be decided by earned autonomy: how much responsibility people choose to delegate after an agent has repeatedly shown that it understands the task, respects the boundaries, and knows when to ask.Â
A category that arrived in six weeksÂ
Until recently, personal agents were a curiosity for enthusiasts. Then the calendar compressed. Instinct opened as an invite-only service in August, and this week it reportedly raised $1 billion at a $10 billion valuation, roughly four times the mark it hit a month earlier. On September 8, Meta launched Muse, which reached the top of the free app charts in the US and passed 900,000 downloads in its first six days, according to Bloomberg and Sensor Tower. Axios called it a consumer agent race that formed almost overnight.Â
I have been building Portal One in this space since February, and in August I wrote here that the next useful AI would remember where the story left off. Watching that thesis become a category so quickly has made the next question more urgent: what is memory for once an agent can act?Â
The payment rail shows upÂ
The detail I find more telling than any download count is what happened next. Muse launched with Stripe’s Link wallet built in. Within two weeks, Shopify’s Shop Pay and PayPal had joined, and PayPal customers could check out through Muse at PayPal merchants worldwide (Forkast, The Paypers). Where a merchant does not accept Link, Link can generate a single-use virtual card limited to the approved purchase. Meta AI chief Alexandr Wang told CNBC that Muse “never sees your actual passwords or payment details”.Â
This is the trend I would watch: the agent and the payment rail arriving together. For years, assistants could suggest and draft. Once an agent can trigger a payment, the product question changes from whether it can do the task to who said it could, for how much, under what conditions and when it has to come back and ask. Payments make that question unavoidable because money creates an immediate consequence.Â
They also give us a useful model for the rest of personal AI. A purchase does not have to be either fully manual or fully autonomous. The user can approve every transaction, approve only transactions below a threshold, allow a familiar merchant but not a new one, or keep certain categories permanently behind an approval step. Â
Downloads are the easy metricÂ
A chart position measures curiosity. Whether an agent earns a place in someone’s routine shows up much later, and the data on AI apps is sobering. RevenueCat’s 2026 State of Subscription Apps report found that AI apps earn about 41% more per paying user in the first year, while TechCrunch’s summary of the same report put annual subscriber retention at 21.1% for AI apps against 30.7% for the rest. Novelty converts well, and it wears off just as fast. Even early fans notice. TechCrunch’s Sean O’Kane, who has used Muse since launch, described its first standout trick as a party trick, a one-time win that would not keep him coming back.Â
So what keeps someone opening an agent in month six? Menlo Ventures’ 2026 survey of 5,067 US adults offers a clue. AI users now rank accuracy (45%), trustworthiness (40%) and security and privacy (36%) above ease of use, which slipped from 38% to 32%. Ease of use gets the download. Trust decides the second month.Â
Permission is the productÂ
The same survey shows how quickly people extend authority: 32% of AI users say they have let AI act on their behalf without final approval. Money is where that changes. In a YouGov survey of 3,328 UK and US adults commissioned by ACI Worldwide, only 7% of fashion and sportswear shoppers said they would let an assistant buy without approval, and 53% were uncomfortable with an assistant buying for them at all.Â
These two surveys ask different questions of different groups, so I would not stack them into a single number. The direction here:Â people will let an agent try small things, and their willingness narrows once money and irreversible steps appear.Â
That is why I think autonomy should be a ladder, not a switch.Â
A personal agent can begin by making a suggestion. Then it can prepare the action and wait for approval. After several successful repetitions, the user may decide that a narrow class of actions no longer needs approval every time. Trust, in other words, should change the workflow without changing who is in control.Â
Instinct makes a case study. Reporting on its terms describes users giving the agent broad authority to read and store a copy of the data in any account they connect and to make purchases and accept agreements in their name. Founder Noah Shinn describes the design in one line: “there are no new interfaces“. It is an elegant pitch, and it raises a practical question: without an interface, the moment where an agent asks permission has to be designed on purpose.Â
Meta is making its own promises. Mark Zuckerberg wrote in August that people should have “a fully private mode for personal agents,” though Axios noted that the more ambitious version, encrypted with a key only the user holds, has not shipped yet.Â
Memory gives context. Trust gives permission.Â
At Portal, we have found that usefulness grows when an agent does not have to rediscover the user every time. Portal One is designed to remember preferences, prior decisions and recurring patterns, then use that context to help with the next step. But context does not equal permission. The user still determines what the agent can suggest, what requires approval and what can eventually be handled automatically.Â
If someone has been thinking through a career move for weeks, for example, a useful personal agent should remember the tradeoffs they have already discussed instead of asking them to start over. It can surface the next question, notice what has changed and help prepare the next step. That does not mean it should send a resignation email or accept an offer. Memory gives the agent continuity; permission determines what it may actually do.Â
The same distinction matters in communication. A creator with more community conversations than hours in the day might begin by having an agent draft familiar, low-risk replies for approval. Over time, that creator could choose to let the agent handle a narrow set of interactions.  Â
When I described trustworthy memory in August, I used three words: legible, correctable and bounded. Action turns those principles into practical controls. Can I see what the agent believes about me? Can I see what it’s allowed to do? Can I change that permission easily? Does it stop and ask when the amount, recipient, context or risk changes?Â
What earns the second monthÂ
I expect the agents that last to earn authority the way a good new colleague does. They start narrow, ask often at first and ask less as the pattern proves itself. Spending limits will be set by the user, payment credentials will be scoped to a single purchase, and every action will leave a record a person can read in plain language. None of that makes a dramatic launch video, and I think it is what keeps subscribers around.Â
The key distinction: permission should expand only when the user chooses, and it should always be easy to narrow or revoke.Â
The payment rails will matter more than most people expect, because they are the one place where a limit can be enforced by something other than the agent’s own good behavior. A limit that lives in the rail stops a mistake. A limit that lives only in the prompt makes a suggestion.Â
Payments are the clearest early test because the stakes are visible. But the same architecture will matter as agents gain access to communication, scheduling, accounts, communities and other parts of a person’s digital life. The most useful personal AI will earn narrowly defined responsibility one successful task at a time.Â
Memory gives the agent context. Trust can earn it more responsibility. Permission still belongs to the user.Â



