Meta's Muse Builds Dossiers on Everyone in Your Life
Extracted Muse system files show Meta's assistant compiles hourly profile pages on users' friends and family, complete with relationship analysis and 'Strengthening' suggestions.

Updated
Why it matters
- Researcher Karan Joshi extracted Muse's internal instructions by asking the assistant to share its own software files via the regular chat interface.
- Muse runs an hourly process creating a page for every person in a user's life, with sections including Facts, History, The relationship, In common, Open threads, and Strengthening.
- Meta says each Muse user has a dedicated virtual machine, users can wipe memories at any time, and the agent seeks confirmation before actions like sending emails or making purchases.
Meta's viral AI assistant Muse runs an hourly process to compile a dedicated profile page for every person in a user's life — family members, partners, friends, colleagues, "collaborators," and people the user follows — according to the agent's internal operating instructions extracted by an independent security researcher and shared with WIRED.
The disclosure offers the first detailed look at how one of the most aggressively adopted consumer AI agents organizes the intimate data millions of people have handed it. Muse users have connected the assistant to bank accounts, message threads, and health data, and let it complete tasks on their behalf. Now the system's own files show what Meta is doing with that access — and how far its memory architecture goes beyond the personalization features of its rivals.
Independent AI safety and security researcher Karan Joshi extracted an extensive array of Muse's instructions and system prompts by using the regular chat interface and, essentially, asking Muse to copy and share its own software files. Multiple researchers have pulled the agent's internal files in recent days, providing a glimpse of how the system was built and how it behaves. Meta has maintained that it intended these files to be accessible in the interest of transparency. The files do reveal how Muse responds to prompts and questions about, for example, highly politicized or sensitive topics.
The core finding is structural. One of Muse's instructions appears to be the ability to create "a page for every person in the user's life." This process runs hourly and compiles data on the people closest to the user. Muse uses its "memory" — structured text files — to collect information about relationships and the important people in a user's life, then makes suggestions: pointers on how to improve particular relationships, or where to take a coffee-loving friend for breakfast.
The pages themselves are remarkably granular. Muse's documentation says a page may start "sparse" and fill out over time, potentially including sections labeled Facts, History, The relationship, In common, Open threads, and Strengthening. The instructions direct Muse to record "where they live, what they do, the threads that recur (the apartment move, the shared savings goal)" and to log "dates that matter," such as birthdays or anniversaries. A person's History section could include backstory like "the trip in March, the argument that got resolved, the milestone last week."
The profiling extends to emotional inference. The instructions focus on recording relationship details such as "how close they are, what it is built on, how they act with each other, and what it seems to need right now." The Strengthening section suggests ways a relationship could be improved, including "a reason to call, a date worth remembering, something they said to circle back on, a way to be there for them that matters."
There is at least one restraint baked into the design. Meta's instructions say Muse should only use the "evidence" it has available, and that invented details are worse than an empty page.
"What it seemed like to me—from all these prompts, system skills data, and things that they're feeding into Muse—is that they want to understand your relationships that you have with real people," Joshi says. "They're trying to know you like a friend, which is honestly pretty creepy."
Context: memory is the battleground
To be clear, AI assistants tracking social information is not new. People have been asking ChatGPT for relationship advice for years, and it has become common for AI assistants to incorporate memory features designed to allow greater personalization in responses and activity. What distinguishes Muse, according to Miranda Bogen, director of the Center for Democracy and Technology's AI Governance Lab, is its emphasis: Muse appears to focus more on relationships and personal contacts than rival systems do. It is also worth noting that this architecture comes from Meta, the company with perhaps the deepest historical access to social network data of any AI developer.
The stakes are asymmetric, researchers argue. "We are giving AI systems much more information about us than we are getting information from them," says Carissa Véliz, an associate professor at Oxford's Institute for Ethics in AI. "It's not only what we explicitly tell them, but what they can infer from us—correctly or incorrectly, both concerning for different reasons—and what they can piece together from other sources of data."
The problem, Bogen notes, is that agents and assistants encourage people to proactively share more data with them rather than focusing on culling data. "These tools are actively soliciting users to plug their whole lives in—their emails, calendars, financial institutions, everything in order to be helpful assistance," Bogen says. "That's dramatically more information than people might have otherwise given to some of these companies. The breadth of access to information that these tools have will lead to a ballooning of what they know about users."
In general, memory-equipped tools tend to offer transparency and editing capabilities, Bogen says — and Muse does as well.
Meta's defense
Meta frames the profiling as functional necessity. Muse is architected so each user has a dedicated virtual machine that stores their data and context. This VM is inaccessible to other agents, and users can wipe memories or disconnect external services at any time. Meta says Muse is also designed to seek human confirmation before completing actions like sending an email or making a purchase, and it maintains an audit log where users can see all of the agent's activity and future plans.
"For any agent to be useful and actually help you achieve your goals, it needs to have context about you and those you interact with," Meta spokesperson Daniel Roberts told WIRED in a statement. "Muse gathers that based on public information and from what you've chosen to share, which is how it remembers the person who sent you an invoice is in fact the plumber who you previously hired to complete work in your bathroom or which flowers your spouse said they liked best."
Why it matters
The Muse files land at a moment when consumers are connecting AI agents to the most sensitive data they own — banking, messaging, health records — faster than governance frameworks have developed to govern what those agents do with it. Joshi's extraction method also matters: if a researcher can pull an agent's operating instructions through its own chat interface, other users and bad actors can interrogate these systems too, and Meta's claim that the files were deliberately accessible for transparency is difficult to independently verify.
The hourly relationship-profiling loop also raises questions the source instructions do not answer: what happens to the pages Muse builds on people who never consented to being profiled — the colleague, the friend, the "collaborator" — and whether a dossier labeled Strengthening can drift from helpful suggestion into manipulation. Véliz's point about inference cuts both ways: the system can be wrong about your relationships, and it will act on those wrong conclusions regardless.
For now, Meta's position is that context is the price of usefulness, and the Muse instructions show just how systematically the company has operationalized that trade. As Bogen warns, the direction of travel is clear — agents are built to solicit ever more of users' lives, and what these tools know about users will balloon accordingly.
Original: mouse.dev
More from Marcus Bennett
Show full bio
Senior reporter covering consumer brands and retail at AI In Context.
146 articles
Related articles
- Developers Say Meta's Muse Hands Over Its Entire Filesystem on Request
- Meta Says Muse's Exposed Filesystem Is Intended Behavior
- Meta's Muse agent hands every user a full Ubuntu Linux cloud computer
- Apple to Restrict macOS 'Full Disk Access' Over AI Agent Risks
- Meta Gives Muse Email Addresses, Video Calls, and Computer Access