AI assistant privacy concerns around Meta's Muse relationship profiles

Meta’s Muse AI Is Quietly Building Dossiers on Your Inner Circle

Meta’s Muse is building relationship pages on friends and family, intensifying AI assistant privacy concerns about personal data and profiling.

In short

Researchers say Meta’s Muse AI assistant can build detailed profiles of a user’s friends and family, turning relationship data into persistent memory. Meta says the system is designed with user controls, but privacy experts warn the tool could intensify AI assistant privacy risks.

  • Muse appears designed to create pages for people in a user’s life, not just remember user preferences.
  • Researchers say the assistant can turn messages and other data into structured relationship profiles.
  • Meta says users can delete memories, disconnect services, and review audit logs.
  • Privacy experts warn that AI assistants may collect far more about users—and their contacts—than people expect.

Meta’s new personal AI assistant, Muse, is designed to create detailed profiles of the people in a user’s life, including friends, family members, coworkers, and other contacts. Researchers who examined the system say the tool can assemble relationship pages, pull in personal context over time, and use that material to make highly specific suggestions—raising fresh privacy questions about how much an assistant should know.

The findings matter because Muse is already being adopted at scale, with millions of downloads reported as users connect it to messages, bank accounts, calendars, and health data. As AI agents become more deeply embedded in everyday life, Muse offers a revealing look at how a new generation of assistants may turn scattered personal information into structured social profiles.

In the past few days, multiple researchers have extracted internal Muse files and system instructions, offering a rare glimpse into how Meta’s agent is organized and what it is allowed to do. The material suggests that Muse is not just remembering preferences or travel plans; it is also trying to map relationships, track recurring details about the people around a user, and build a living record of social ties.

What researchers found inside Muse

Independent AI safety and security researcher Karan Joshi uncovered a broad set of Muse prompts and internal instructions by asking the assistant, through its normal chat interface, to copy and reveal parts of its own software files. Joshi shared the results with WIRED, which reviewed the material and reported on its contents.

The extracted files indicate that Muse is built to maintain a personal knowledge base about a user’s social world. Rather than treating memory as a simple list of facts, the system appears structured to compile relationship-specific pages that can be updated as new information arrives.

According to the internal instructions, Muse may create a separate page for each person in a user’s life and refresh those pages regularly. The goal is to capture information about family members, romantic partners, friends, coworkers, collaborators, and people a user follows. In practice, that means the assistant is being taught to organize human relationships as machine-readable records.

How does Muse organize people and relationships?

Muse organizes people by building pages that can start out thin and become more detailed over time. The system’s documentation describes sections that may include facts, relationship history, common interests, open questions, and ideas for strengthening the connection.

The assistant is told to rely only on evidence it can support. In other words, it should not fill in gaps with invented details if it does not have enough information. Meta’s instructions say that leaving a page sparse is better than guessing.

The material also shows Muse being encouraged to track items such as where someone lives, what they do for a living, recurring themes in the relationship, and notable milestones. Dates that matter, such as birthdays and anniversaries, may also be recorded.

One of the most striking elements is the way Muse appears to frame social context as a usability feature. If someone has mentioned an apartment move, a shared savings goal, or a recent argument that was resolved, the system may surface that information later to help shape its replies and recommendations.

Feature What Muse appears to do Why it matters
Relationship pages Creates a profile for each person in a user’s life Turns social connections into structured data
Memory sections Stores facts, history, open threads, and strengthening ideas Lets the assistant reference personal context over time
Evidence rule Uses only supported details, not guesses Reduces hallucination, but still centralizes sensitive data
Human confirmation Asks before actions like sending emails or making purchases Builds a safety checkpoint for real-world tasks
Audit log Shows activity and planned actions Gives users visibility into agent behavior

Why relationship memory is the biggest privacy flashpoint

The clearest concern is not simply that Muse remembers details, but that it appears optimized to infer and categorize the private lives of other people, not just the user. That expands the privacy debate beyond first-party data and into the social networks of anyone who interacts with a Muse user.

Carissa Véliz, an associate professor at Oxford’s Institute for Ethics in AI, said the balance between what users tell AI systems and what the systems can figure out has become increasingly lopsided. In her view, AI tools often collect more information than they reveal, including facts users explicitly enter and other details the systems infer from patterns or pull from connected services.

Véliz said the asymmetry is worrying because these systems can piece together data both correctly and incorrectly, drawing on direct input, inferences, and outside sources. The result, she suggested, is a growing informational advantage for the AI.

That critique lands especially hard in Muse’s case because Meta already sits atop one of the largest reservoirs of social data in the world. Even if the assistant is formally limited to what users choose to share and what is publicly available, the combination of personal messages, contacts, purchase history, calendars, and relationship metadata could produce a far richer portrait than most users expect.

Miranda Bogen, who leads the AI Governance Lab at the Center for Democracy and Technology, said Muse seems to place unusually strong emphasis on personal relationships compared with some rival assistants. She noted that most assistants with memory features also offer some controls, but the larger pattern is that these tools nudge people to contribute ever more of their lives in exchange for convenience.

Bogen argued that AI assistants are actively encouraging users to connect inboxes, calendars, financial tools, and other accounts, which dramatically expands the amount of information those systems can absorb.

That, she warned, can lead to a steady expansion of what companies know about users over time.

What Meta says Muse is supposed to do

Meta says Muse is designed with privacy and user control in mind. The company has emphasized that each user gets a dedicated virtual machine that stores the assistant’s data and context. According to Meta, that environment is isolated from other users and other agents, and people can wipe memories or disconnect external services whenever they choose.

Meta also says the assistant should seek human confirmation before taking consequential actions, such as sending an email or making a purchase. In addition, the system includes an audit log so users can review what the agent has done and what it plans to do next.

Daniel Roberts, a Meta spokesperson, said the assistant needs context about the user and the people around them in order to be genuinely useful. He added that Muse gathers that context from public information and from what users have intentionally shared.

Roberts said the system is meant to remember practical details, such as which plumber previously fixed a bathroom or which flowers a spouse preferred, so it can help users act on real-world needs.

Meta’s framing is straightforward: the more an assistant understands a user’s life, the more effective it can become. But the same design choice that makes the tool useful also increases the amount of personal and social information the system must absorb.

How is Muse different from other AI assistants?

Muse is not the first AI product to use memory, but the extracted instructions suggest it may be more relationship-focused than many competitors. Other assistants often remember preferences, project details, or recurring tasks. Muse appears to go further by formalizing a model of the user’s social ecosystem.

That difference matters because relationship memory can be more sensitive than ordinary personalization. A remembered travel preference or shopping habit is one thing; a mapped history of friendships, tensions, family connections, and unresolved issues is something else entirely.

In practical terms, Muse may be able to suggest a restaurant for a coffee-loving friend, remind a user about a birthday, or surface a follow-up on a conversation that mattered. Those are the kinds of conveniences AI companies increasingly advertise. But the same system can also generate detailed summaries of people who never consented to being profiled by an AI assistant.

What does this mean for people connected to users?

It means a person may be logged, categorized, and analyzed even if they never installed Muse themselves. If a user includes work contacts, family members, or friends in their conversations, the assistant may derive useful social context from those interactions and turn it into durable memory.

That creates a privacy spillover effect. The user may opt into the system willingly, but the people around them become part of the dataset by association. In a social network-heavy environment, that can include spouses, coworkers, neighbors, clients, and anyone else whose name or habits arise in a conversation.

The issue is especially relevant for Meta because its products already sit at the center of communication for billions of people. A personal assistant layered on top of that ecosystem could deepen the company’s visibility into offline relationships as well as online behavior.

Why transparency is not the same as safety

Meta argues that the internal files were accessible in the name of transparency, and the company’s public stance emphasizes control, auditing, and user choice. But transparency about what a system can do does not necessarily resolve the deeper question of whether it should do it.

There is a difference between giving users a window into a model’s behavior and making the model fundamentally less invasive. If an assistant is allowed to centralize highly sensitive relationship data, then a visible log or export feature may help with accountability, but it does not eliminate the underlying risks.

Those risks include overcollection, mistaken inferences, stale data that persists after relationships change, and exposure if the account is compromised. A detailed memory of someone’s social life could be useful to the user and equally valuable to an attacker.

The design also raises familiar questions about consent. A user may agree to let Muse scan their inbox or read their calendar, but their contacts, family members, and coworkers may never realize that fragments of their lives are being added to an AI profile.

Timeline of how the story unfolded

The following timeline summarizes the key developments around the findings reported from Muse.

Timeframe Event Significance
Before the leak Muse grows rapidly as a personal AI assistant Millions of users connect sensitive accounts and data sources
Recent days Researchers extract internal files and prompts Reveals how Muse stores and structures relationship data
Analysis period Karan Joshi shares findings with WIRED Provides an independent look at the system’s behavior
Publication Privacy concerns intensify around social memory Focus shifts to how AI assistants profile third parties

What users should watch for now

People using AI assistants like Muse should think carefully about what data they connect and what kinds of relationships they allow the system to remember. Once an assistant is given broad access to messages, financial services, calendars, and health information, it can begin to assemble a detailed picture of both the user and the people around them.

There are several practical steps that matter:

  • Review what accounts and services are linked to the assistant.
  • Check whether memory features can be edited or disabled.
  • Look for logs that show what the assistant has done or plans to do.
  • Be cautious about storing sensitive information about other people in chat prompts.
  • Consider whether the convenience gained is worth the privacy tradeoff.

For businesses and family groups, the stakes may be even higher. A worker using an assistant for scheduling or correspondence could unknowingly expose client relationships. A parent using it for household management could create a record of children’s routines and contacts. A spouse may be summarized through another person’s account without ever interacting with the system directly.

The bigger picture for AI agents

Muse sits at the intersection of two fast-moving trends in artificial intelligence: agentic systems that take actions on a user’s behalf, and memory systems that let those agents feel more personal, more useful, and more persistent. Together, those features are reshaping what people expect from software.

That shift is powerful, but it also alters the balance of information between users and companies. Traditional apps typically perform a discrete task. A modern assistant can observe patterns, infer relationships, store context, and make decisions about what matters next.

As AI agents mature, the central policy question is likely to be less about whether they can remember and more about how much they should remember, who else gets swept into that memory, and what limits should govern the construction of digital dossiers on real people.

For now, the Muse leak is a reminder that personalization is not free. The more an assistant is optimized to know users intimately, the more it may also learn about the people who matter to them—and the harder it becomes to tell where helpful memory ends and invasive profiling begins.

Frequently asked questions

What is Meta’s Muse AI assistant?

Meta’s Muse is a personal AI assistant built to help users with everyday tasks and recommendations. It can connect to services such as messages, calendars, and financial tools, and it is designed to use memory so it can respond with more context and personalization.

What did researchers find inside Muse?

Researchers found internal instructions suggesting Muse can create pages for people in a user’s life and keep updating them over time. Those pages may include relationship history, shared interests, dates that matter, and ideas for strengthening the connection.

Why are privacy experts worried about Muse?

Privacy experts are worried because Muse appears to profile not only the user but also friends, family, coworkers, and other contacts. That means people who never chose the assistant could still be included in its memory and analyzed through another person’s account.

Can users delete Muse’s memory or disconnect services?

Yes, Meta says users can wipe memories and disconnect external services at any time. The company also says Muse includes a dedicated virtual machine, human confirmation for major actions, and an audit log showing activity and planned steps.

Share this 🚀