Enterprise Adoption 2026-10-04

Texting Your Agent: TechCrunch's Survey of Assistants That Live in iMessage, WhatsApp and SMS Shows Where the Permission Problem Moves

An October 3 TechCrunch roundup lists close to twenty assistants you reach by text message instead of an app -- Poke, Instinct, Ollie, Wajo's Fo, Town and more. The interesting part is not the interface but what each one is allowed to touch: inboxes, calendars, phone numbers and payment cards.

On October 3, 2026, TechCrunch published a guide to "all the AI agents that can live in your text messages." Its premise: "Rather than downloading another app, a growing number of agents can simply be texted like an ordinary person. You text it what you need, and it can remember context, connect to the apps and services you already use, and complete tasks on your behalf."

The guide is a snapshot, not a launch: most of the products it lists launched or raised money earlier in 2026. What makes it useful is that it lines up how people are actually using these assistants, and what each one needs access to.

  • Poke launched in March 2026 as a general-purpose assistant reached by text, handling calendars, planning, health and fitness, smart-home controls and photos. TechCrunch notes Apple approved it as "the first AI agent on the Apple Messages for Business platform," and that its parent company was later acquired by Cognition.
  • Instinct, which TechCrunch calls one of the buzziest agents after a $1 billion round at a $10 billion valuation, "can take actions on your behalf, rather than simply answer questions," connecting to email and calendar. It can create and manage accounts for the user "without filling the user's personal inbox." TechCrunch adds that "this level of autonomy has also raised concerns about privacy and security." It remains in private beta.
  • Wajo's Fo can call businesses, send emails, join group chats and make bookings and purchases. "The agent has its own email address, phone number, and payment card, allowing it to interact with businesses without requiring users to hand over their own credentials," and it can hand a task to a human assistant when it gets stuck.
  • Ollie, a family organizer, is described as "one of the first mainstream, family-focused AI assistants to achieve SOC 2 compliance."
  • Town targets professionals and is "designed to learn how they work and handle recurring professional tasks."

How people use them, in practice. The workflow is the same across most of the list: the user texts a request into an existing thread; the agent reads connected Gmail, calendar or message history for context; then it acts -- adds an event, books a table, places a call, buys something -- and reports back in the same thread. The messaging app is only the front door. The real system is the set of accounts behind it.

The adoption constraint is permissions. The products split into two designs. One reads and acts through the user's own accounts, which is convenient but means a mistaken or manipulated agent acts with the user's full identity. The other, as with Fo and Instinct, gives the agent its own email address, phone number or card, so it can be scoped, monitored and cut off separately. On October 2, Apple said it would tighten macOS Full Disk Access because of agent risk (TechCrunch); texting agents raise the same question on the server side, where the user cannot see what was read.

Analysis: the separate-identity design is the one to prefer, for consumers and for any company tempted to let staff use these tools at work. An agent with its own card and inbox can be given spending limits and an audit trail, and revoking it does not mean changing the user's passwords. Before connecting a work calendar or mailbox, check three things: which accounts the agent reads, whether it acts under your identity or its own, and whether there is a log of what it did. SOC 2, which Ollie advertises, is a reasonable minimum but says nothing about how the agent decides when to act.

TechCrunch's October 3 survey of text-message AI agents shows the interface is trivial and the permissions are not; agents that act through their own email, phone number or card are easier to scope, audit and revoke than ones that act as the user.