Meta’s Muse personal assistant is designed to build structured, evolving files about the people in a user’s life, according to internal instructions obtained by independent researcher Karan Joshi and reviewed by WIRED. The finding offers a detailed look at how a consumer AI agent turns conversations and connected data into a working model of a user’s relationships.
Joshi accessed Muse’s operating instructions and system prompts through the regular chat interface by asking the agent to reproduce its own files, WIRED reported. Meta has said those materials were intentionally accessible as part of its transparency approach. The exposed instructions therefore illuminate the product’s intended behavior rather than, on their own, proving that an unauthorized breach occurred.
One instruction describes an hourly process that can create a page for each significant person connected to the user, including relatives, partners, friends, coworkers, collaborators, and followed individuals. A page can begin with limited information and expand as Muse gathers evidence, organizing details such as basic facts, shared history, unresolved topics, common interests, and the current state of the relationship.

The purpose is practical personalization. A richer social memory could help Muse remember important dates, suggest an appropriate place to meet a friend, or remind a user to revisit something another person mentioned. The instructions also emphasize that the agent should rely on available evidence and leave a page incomplete rather than invent missing details.
The privacy concern is broader than any single stored fact. Oxford Institute for Ethics in AI associate professor Carissa Véliz told WIRED that assistants can combine what people explicitly disclose with inferences—accurate or mistaken—and information drawn from other sources. A system that continuously organizes those fragments can develop consequential profiles not only of its user, but also of people who may never have chosen to interact with the agent.
Meta says context about a user and the people around them is necessary for an agent to complete useful work. Spokesperson Daniel Roberts told WIRED that Muse draws on public information and material users choose to share, allowing it to connect details such as the identity of a previously hired contractor or a spouse’s preferences.

The company also points to technical and product controls. Each Muse user receives a dedicated virtual machine that stores their data and context and is inaccessible to other agents, according to WIRED. Users can erase memories or disconnect external services. Meta says Muse asks for confirmation before sensitive actions such as sending an email or completing a purchase, and provides an audit log showing activity and planned steps.
Those safeguards address who can access the agent and what actions it may take, but they do not eliminate questions about how much information should be collected or inferred in the first place. Miranda Bogen of the Center for Democracy and Technology’s AI Governance Lab told WIRED that Muse appears to place greater emphasis on personal relationships than competing systems, even though memory, review, and editing tools are becoming common across AI assistants.
The central tradeoff is not unique to Meta: an assistant becomes more capable as users connect more of their email, calendars, finances, messages, and other personal context. Muse makes that tradeoff unusually visible by formalizing social relationships into persistent files. Whether users find that helpful or intrusive will depend partly on how clearly the product reveals what it has assembled, how easily those records can be corrected or deleted, and whether people understand that information about others may be captured alongside their own.
