
TL;DR: Key Takeaways

- Viral Adoption: Millions of users have downloaded Meta's AI personal assistant, Muse, connecting it to email, messages, banking, and health data to automate personal tasks.
- Contact Dossiers: Extracted system instructions reveal an hourly process where Muse builds structured profiles for every person in a user's life, including family, friends, colleagues, and social connections.
- Granular Tracking: Profiles track biographical facts, relationship milestones, recurring threads like moves or shared savings goals, and suggestions for "strengthening" connections.
- Security Safeguards: Meta hosts each user's context in an isolated, dedicated virtual machine, requires human confirmation for external actions, and provides memory-wiping options and activity audit logs.
- Privacy Debates: Privacy researchers warn that conversational assistants encourage unprecedented data sharing, giving platforms expansive insight into personal relationships.
Uncovering Muse's Operating Instructions

Meta's conversational personal assistant, Muse, has rapidly gained widespread consumer adoption. Millions of users have installed the AI agent, granting it access to personal communication channels, banking records, calendar schedules, and health metrics to complete automated tasks on their behalf. However, data extracted from the application has illuminated the granular methods Muse uses to organize, store, and interpret information about users and their social circles.
In recent days, several independent researchers extracted internal files and system documentation directly from Muse, shedding light on the underlying rules governing the assistant's behavior. Independent AI safety and security researcher Karan Joshi revealed that he obtained an extensive array of operating instructions and system prompts by prompting the agent through its standard chat interface to copy and share its own configuration files. Joshi subsequently shared these materials with technology publication WIRED.
Addressing the disclosure, Meta maintained that it deliberately intended for these configuration files to be accessible to foster transparency. The documents detail how Muse handles sensitive prompts, resolves ambiguities, and establishes ongoing memory regarding the user's personal environment.
How the Profiling System Works: Structured Contact Dossiers
A central finding from the extracted instructions is an internal mechanism designed to establish "a page for every person in the user's life." According to the documents, Muse executes an hourly routine that analyzes incoming interactions and compiles records on partners, family members, friends, coworkers, collaborators, and individuals the user follows.
Muse relies on structured text files within its memory framework to maintain this relational knowledge base. The documentation instructs the system that a profile may begin "sparse" and expand over time as the agent observes additional interactions. Crucially, Meta's guidelines explicitly order the agent to rely strictly on available evidence, stressing that inventing details is worse than leaving an empty page.
The Multi-Section Profile Layout
The operating documentation outlines several discrete categories that Muse populates as it gathers information:
- Facts: Basic and situational details, such as where an individual lives, their occupation, important recurring dates (including birthdays and anniversaries), and ongoing shared projects, such as an apartment move or a joint savings goal.
- History: Background context and notable events, such as a recent trip, a resolved disagreement, or a recent personal milestone.
- The Relationship: An assessment of the relational dynamic, detailing closeness, shared foundations, behavioral patterns between individuals, and perceived current needs.
- In Common: Shared interests, mutual preferences, and overlapping activities.
- Open Threads: Unresolved topics or ongoing conversations requiring future follow-up.
- Strengthening: Actionable suggestions proposed to enhance the relationship, such as identifying a reason to reach out, remembering a meaningful date, or following up on a past conversation.
By indexing these details, Muse can proactively formulate contextual advice, such as identifying an ideal breakfast spot for a coffee enthusiast or recommending thoughtful moments to reconnect with an acquaintance.
Expert Reactions and Relational Privacy Concerns
While mainstream conversational chatbots frequently handle queries about interpersonal situations, security and privacy analysts emphasize that Muse's automated relationship mapping introduces novel privacy challenges. Karan Joshi noted that the prompts and skill definitions reflect a deliberate push to map real-world networks, stating, "They're trying to know you like a friend, which is honestly pretty creepy."
Carissa Véliz, an associate professor at the University of Oxford's Institute for Ethics in AI, highlighted the asymmetric nature of modern AI data collection. According to Véliz, users routinely disclose substantially more data than they receive. She observed that concerns arise not only from what users explicitly input, but also from the inferences AI models draw—whether accurate or inaccurate—and how systems synthesize disparate information sources.
Miranda Bogen, director of the Center for Democracy and Technology's AI Governance Lab, pointed out that Muse places a noticeably stronger emphasis on mapping relationships and personal contacts than competing assistant platforms. While assistants often feature settings to view and edit memory logs, Bogen observed that the software design inherently incentivizes users to integrate ever-larger swaths of their digital lives.
"These [AI assistant] tools are actively soliciting users to plug their whole lives in—their emails, calendars, financial institutions, everything in order to be helpful assistance," Bogen told WIRED. "That's dramatically more information than people might have otherwise given to some of these companies. The breadth of access to information that these tools have will lead to a ballooning of what they know about users."
Meta's Architecture: Virtual Machines and User Safeguards
In response to privacy considerations, Meta points to technical safeguards built into Muse's infrastructure. The system allocates an isolated, dedicated virtual machine (VM) to each user. This dedicated environment ensures that personal context and stored memory files remain separated from other users and cannot be queried by unauthorized external agents.
Meta emphasizes that users retain full authority over their stored records. Individuals can delete memory files at any point or revoke permissions to connected third-party accounts, such as financial or messaging portals. Additionally, the architecture incorporates a transparent audit log allowing users to review all past operations alongside planned future tasks. For sensitive operations—such as sending an email or executing a financial transaction—Muse is configured to pause and request explicit human confirmation before proceeding.
Defending the necessity of relational data, Meta spokesperson Daniel Roberts explained that contextual awareness is fundamental to an effective assistant. Roberts stated: "For any agent to be useful and actually help you achieve your goals, it needs to have context about you and those you interact with. Muse gathers that based on public information and from what you've chosen to share, which is how it remembers the person who sent you an invoice is in fact the plumber who you previously hired to complete work in your bathroom or which flowers your spouse said they liked best."
Why Personal Relationship Mapping Matters for the Future of AI
The revelations surrounding Muse underscore a pivotal shift in consumer AI: the transition from stateless chatbots to persistent, agentic companions. As AI assistants evolve from answering single-turn questions to managing complex workflows across multiple personal accounts, the depth of data required to deliver value increases exponentially.
While personalized features—such as automated anniversary reminders or context-aware vendor tracking—provide tangible everyday convenience, they also turn personal AI into a comprehensive repository of human social dynamics. As autonomous agents become more prevalent, the delicate balance between helpful personalization and persistent social profiling will remain a central debate across the technology landscape.
0 Comments