- TechCrunch's roundup shows two text-message AI agents with their own identity: Instinct gives assistants email addresses, and Wajo's Fo also has a phone number and card.
- An agent with its own identity is a new kind of account holder, and the sources do not say how companies should govern one.
- Leaders should ask which agents staff connect to work email, calendars and Slack, and who can see the data.
The assistant is becoming an account holder
The news is not that you can text an AI assistant. The change is that a few assistants are starting to hold accounts of their own. An agent with its own email address, and in one case its own phone number and payment card, is a new kind of actor. It is neither a tool you use nor a person you hired.
A TechCrunch roundup published October 3 lists a growing set of agents that live in iMessage, RCS, WhatsApp, Telegram and SMS. Users text a request. The agent remembers context, connects to the apps they already use and completes tasks such as booking, shopping, emailing and cancelling subscriptions.
Two ways to give an agent access
Most of these agents work by delegation. You connect your Gmail, calendar or Slack, and the agent acts through your accounts. Fambot, for example, connects to Gmail and Google Calendar. Town connects to email, calendars, documents and Slack.
Connecting an account generally means giving the agent permission to read that account's data and act inside it, within whatever limits you approve. The agent keeps that access until someone removes it. The roundup does not describe how any of these products handle this.
Two products in the roundup take a different route. In September, Instinct added a feature that lets each assistant work from an inbox separate from its owner's. The agent can use that address to sign up for services and contact businesses. TechCrunch notes that this level of autonomy has raised privacy and security concerns.
Wajo goes further. It gives its agent, Fo, three identifiers of its own: an inbox, a phone line and a payment card. Wajo says this lets Fo deal with businesses without users handing over their own credentials. Wajo also says a person can step in to finish jobs that Fo cannot handle alone.
Think of the difference between lending someone your wallet and issuing them a company card. The card limits what they can reach. It also creates a new account that someone has to track.
What the sources do not tell us
The roundup describes features and funding. It does not report any security incident, test or audit of these agents. It also does not say how an agent's own accounts are protected, or who can see its messages.
Some details show the range of design choices. Folk operates from a dedicated cloud machine that belongs to it, and it can run code and execute multi-step tasks. Tomo can join group conversations. Ollie is described as one of the first mainstream family-focused assistants to reach SOC 2, a widely used security standard. Poke became the first AI agent approved on Apple's Messages for Business platform in June 2026.
These are vendor-reported facts about individual products. They show the design choices being made. They do not show how well any of them work.
Where the risk lands
The lesson here is that identity is now the design question. When an agent acts through your login, a mistake looks like your mistake. When it acts through its own address and card, a mistake looks like a stranger's. Both cases need an owner who is answerable for the agent's actions.
Most products in the roundup are aimed at consumers and families. Town is aimed at professional work. The line between the two is thin. A parent's assistant and an employee's assistant may reach the same phone. Whether staff connect personal agents to work accounts is not something the sources answer. Leaders should find out.
Questions to put to your team
Ask which AI agents staff have connected to work email, calendars, documents or Slack, and whether anyone approved that. Ask whether your acceptable-use policy covers agents that act on a person's behalf, not only chatbots that answer questions.
Ask what happens when an outside agent emails, calls or pays your company. Can staff tell it from a person? Ask how you would find and shut down an agent account created in an employee's name.
For vendors you evaluate, ask where the agent runs, who can read its messages, and whether humans can step in on tasks. Fo's human fallback is a useful example: it means a person may see the task.
A text box is easy to adopt because it asks nothing of the user. That is also why it needs a policy. An agent that holds its own accounts needs an owner.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: TechCrunch.





