Why Meta's Muse memory raises new AI privacy questions

Meta's Muse has become a widely downloaded AI assistant, but extracted internal instructions show how deeply it may organize information about the people in a user's life. The system can build relationship-focused pages from available evidence, while privacy experts warn that AI agents are encouraging users to connect more of their personal data.

WTF Index TERMINATOR
◄ Terminator 4 Idiocracy 1 ►

The story centers on an AI assistant aggregating sensitive personal data, mapping relationships, and acting autonomously, raising clear privacy and control risks.

Why Meta's Muse memory raises new AI privacy questions

Meta's Muse is being positioned as a personal assistant that can act with broad context about a user’s life. According to internal files and operating instructions extracted by researchers and shared with WIRED, that context can include detailed information about family, partners, friends, colleagues, “collaborators,” and people users “follow.”

The picture that emerges is not just an assistant remembering a preference or a task. Muse appears designed to map relationships, preserve relevant details, and use those records to suggest actions that feel personal.

What Muse appears to remember

Muse has become a viral hit, with millions downloading the AI agent and connecting it to bank accounts, messages, or health data. Users can let the assistant complete tasks on their behalf, which makes its memory system central to how it works.

In recent days, multiple researchers extracted Muse’s internal files and dumped the agent’s operating instructions. Meta has said these files were meant to be accessible for transparency. The instructions reveal how Muse is expected to respond to prompts and questions, including on highly politicized or sensitive topics.

Independent AI safety and security researcher Karan Joshi extracted a broad set of Muse instructions and system prompts through the regular chat interface, essentially asking Muse to copy and share its own software files. Joshi then shared the findings with WIRED.

One instruction appears to describe an ability to create “a page for every person in the user’s life.” The process is described as hourly and includes compiling data on people connected to the user across personal, work, and social contexts.

Relationship pages are the key concern

The system uses what Muse calls “memory,” described as structured text files, to collect information about important people and relationships. That memory can support suggestions, such as how to improve a relationship or where to take a coffee-loving friend for breakfast.

AI chatbots have handled relationship advice for years, but Muse is notable because of Meta’s history and access to social network data. The concern is not only that an assistant can remember social information, but that its instructions appear to formalize relationship profiling as a recurring function.

Joshi summarized the issue this way: “What it seemed like to me—from all these prompts, system skills data, and things that they’re feeding into Muse—is that they want to understand your relationships that you have with real people,” says Joshi. “They’re trying to know you like a friend, which is honestly pretty creepy.”

Muse’s documentation says a page may begin “sparse” and fill in over time. Potential sections include Facts, History, The relationship, In common, Open threads, and Strengthening. Meta’s instructions also say Muse should rely only on available “evidence,” and that invented details are worse than an empty page.

The details can get personal

The instructions describe relationship memory in concrete terms. A page could include “Where they live, what they do, the threads that recur (the apartment move, the shared savings goal).” It could also include “dates that matter,” such as birthdays or anniversaries.

The History section could preserve backstory, including “the trip in March, the argument that got resolved, the milestone last week.” These examples show how Muse may connect practical details with emotional context, creating a record that can become more complete as the user continues interacting with the system.

The instructions also focus on the state of the relationship itself, including “how close they are, what it is built on, how they act with each other, and what it seems to need right now.” The Strengthening section points toward suggested actions, including, “A reason to call, a date worth remembering, something they said to circle back on, a way to be there for them that matters.”

For users, this is the tradeoff at the center of AI personalization. The assistant may be more helpful when it understands context, but the same context can reveal intimate patterns about social life, habits, commitments, and unresolved threads.

Meta says users have controls

Muse is built so each individual user has a dedicated virtual machine that stores user data and context. According to Meta, that virtual machine is inaccessible to other agents. Users can also wipe memories or disconnect external services at any time.

Meta says Muse is designed to ask for human confirmation before completing actions such as sending an email or making a purchase. The company also says the assistant includes an audit log where users can see all of the agent’s activity and future plans.

Meta spokesperson Daniel Roberts told WIRED: “For any agent to be useful and actually help you achieve your goals, it needs to have context about y ou and those you interact with,” Meta spokesperson Daniel Roberts told WIRED in a statement. “Muse gathers that based on public information and from what you’ve chosen to share, which is how it remembers the person who sent you an invoice is in fact the plumber who you previously hired to complete work in your bathroom or which flowers your spouse said they liked best.”

That explanation frames relationship memory as practical. If Muse can identify a plumber from a past job or remember a spouse’s flower preference, it can act more like a personal assistant than a generic chatbot.

The bigger privacy question

Memory features are becoming common in AI assistants because they can make responses and actions feel more personalized. Miranda Bogen, the director of the Center for Democracy and Technology’s AI Governance Lab, says Muse appears to place more emphasis on relationships and personal contacts than rival systems.

These tools generally offer some transparency and editing options, and Muse does as well. But Bogen notes a broader shift: AI agents and assistants encourage people to share more data with them, rather than focusing on reducing the data they hold.

“These [AI assistant] tools are actively soliciting users to plug their whole lives in—their emails, calendars, financial institutions, everything in order to be helpful assistance,” Bogen says. “That’s dramatically more information than people might have otherwise given to some of these companies. The breadth of access to information that these tools have will lead to a ballooning of what they know about users.

Carissa Véliz, an associate professor at Oxford’s Institute for Ethics in AI, raised a related concern about the imbalance between what users provide and what systems reveal in return. “We are giving AI systems much more information about us than we are getting information from them,” she says. “It’s not only what we explicitly tell them, but what they can infer from us—correctly or incorrectly, both concerning for different reasons—and what they can piece together from other sources of data.”

The central issue is therefore not only whether Muse can be useful. It is whether users understand how much context a personal AI assistant may gather, how it structures that context, and how relationship data can expand once an agent is invited into more parts of daily life.