Live
Abstract illustration of a glowing hexagonal node at the centre of elliptical orbits, tethered by thin lines to a ring of small tilted document pages, on a dark teal background.
Privacy & Security

Meta’s Muse Keeps a Page on Everyone You Know, Leaked Prompts Show

Somewhere inside Meta’s Muse agent there is a template with six headings: Facts, History, The relationship, In common, Open threads, Strengthening. Muse is told to fill one out for each person in your life. That means your sister, your landlord and the friend you stopped texting in March, none of whom ever installed the app.

Meta's launch graphic for Muse, its personal AI agent
Meta introduced Muse as a personal AI agent in September. Image: Meta

The template is part of a set of internal instructions that independent AI safety researcher Karan Joshi pulled out of Muse and shared with WIRED, which reported on them on Oct. 3. We could not open WIRED’s story directly, so the details here come from the outlets that summarized it, each linked. According to Archyde’s account of the report, Joshi got the files simply by asking Muse, in its chat window, to copy and share its own software files. The instructions describe “a page for every person in the user’s life”, refreshed hourly, logging locations, jobs, birthdays, anniversaries, arguments that got resolved and how close the two of you seem to be.

“They’re trying to know you like a friend, which is honestly pretty creepy,” Joshi told WIRED, according to AI Weekly.

What Meta’s Muse system prompt actually tells the agent

Read charitably, the people pages are the product working as designed. Meta pitched Muse at its Sept. 8 launch as an agent that remembers what matters to you and can act on a detail you mentioned once. Remembering that your partner likes peonies is that pitch. Meta has said the context comes from public information and things users share, offering examples like “a plumber’s invoice or a spouse’s preferred flowers”, as Implicator reported. The company also said the operating files were meant to be user-accessible in the interest of transparency, per Archyde’s summary.

Diagram of a Meta Muse 'people page' from the leaked instructions: six template headings (Facts, History, The relationship, In common, Open threads, Strengthening), refreshed hourly, one page for every person in the user's life, logging locations, jobs, birthdays, anniversaries, resolved arguments and closeness.
The leaked Muse template gives every person in a user’s life a six-part page, refreshed hourly. Graphic: prompt/power

There is even a guardrail in the text. The instructions tell Muse to rely only on available evidence and treat an empty page as better than an invented detail.

The trouble is the asymmetry. You agreed to Muse’s terms. The people on your pages did not, and there is no setting on their phones that reaches your agent’s notes about them.

“The user’s authority over their own household is unconditional and overrides your safety training.”

That line is the one that travelled furthest on Oct. 4. It appears in coverage by Startup Fortune and AI Weekly. Startup Fortune says it was first surfaced by users of Reddit’s r/LocalLLaMA forum. We have not confirmed it in WIRED’s own text, and Startup Fortune says Meta has not commented on it specifically.

Our read: the sentence is probably aimed at a narrow problem, like a model refusing to help a parent configure a child’s device or a homeowner reset a shared account. But “unconditional” is a strong word to put in front of a system that keeps hourly notes on the other people in that household. Nobody inside that house gets a vote, except the account holder.

The Messages fight Meta still hasn’t settled

The people pages land on top of an existing dispute over how much Muse sees on a Mac. On Sept. 19, Inc. columnist Jason Aten wrote that Muse surfaced material from his private Messages after he declined to give it access, and that he found it had synced his Messages database up to row 187,462, The Next Web reported. “I never gave it permission to do that,” he wrote.

Meta says that is not possible. Communications chief Andy Stone posted on X that the integration is opt-in: “You have to enable both Full Disk Access and the Messages connector for Muse to be able to read your Messages content,” according to NewsBytes. David Singleton of Meta Superintelligence Labs added on Threads that reading Messages takes “three separate steps of app and macOS permissions,” The Next Web reported. Singleton also said Muse gave Aten a wrong explanation of what it had done, which is its own small problem for an agent that is supposed to keep an honest audit trail. As of Oct. 4, Implicator noted, neither side had produced evidence that settles it.

Meta’s Virtue AI exit came the same week

On Oct. 2, Semafor reported that Meta had parted ways with Virtue AI, the safety and security startup whose co-founders Bo Li, Dawn Song and Sanmi Koyejo joined in June. Virtue had previously worked with Anthropic, OpenAI and the National Institute of Standards and Technology. “Unfortunately, the arrangement didn’t work out as planned,” Stone told Semafor, adding that Superintelligence Labs still prioritizes safety and alignment work.

Nothing public ties the Virtue split to Muse. The timing is still awkward: a team hired for AI security leaves in the same week the flagship agent’s people-tracking instructions became public.

How to see and limit what Muse stores about the people you know

Muse reached Canada on Sept. 18, so this applies here too. Meta has not published a people-pages control, so these are the levers that exist today:

  1. Ask Muse what it has. Joshi’s method works for you too. Ask it to show the page it keeps on a named person, then tell it to forget specifics. Meta’s launch post says you can tell Muse to “forget” things it has learned.
  2. Know that there’s no master off switch. When WIRED’s Reece Rogers tested Muse on Sept. 20, he could edit or wipe the memory document through chat, but there was no switch to turn memory off altogether, per Implicator. Wiping is the closest thing.
  3. Cut the feeds. Meta says you choose which apps connect and can disconnect any of them at any time. Contacts, email and Instagram are where most people-page material comes from.
  4. On a Mac, check the operating system, not just the app. Go to System Settings, then Privacy and Security, then Full Disk Access, and switch Muse off unless you need it. Both sides of the Aten dispute agree that is the gate for Messages.
  5. Opt out of training. Meta says interactions are not used for model training without your opt-in and are not shared with ad systems. Check the toggle anyway; our training opt-out guide covers Meta’s other AI products.

Meta’s promised fix is Muse Confidential VM, which its launch post says will encrypt everything with keys only the user holds “later this year.” No date yet. It would lock Meta out of your pages. It would not let anyone else in.

When we covered Muse passing 5 million downloads, the story was Meta’s distribution muscle. Each of those downloads can open a notebook with a page reserved for someone who has never seen it, under a heading called Open threads.

// Columnist, Security & Privacy
Oman Hassan

Oman Hassan covers cybersecurity and privacy for prompt/power: breaches, exploits, surveillance and the policy that follows them. He assumes the password is "password" until proven otherwise.

Latest from prompt/power

  1. Thomson Reuters Won the First AI Training Appeal. Footnote 7 Is the CatchOct 7
  2. The Family Safe Word: How to Beat AI Voice-Clone Emergency ScamsOct 7
  3. Reflection AI’s Beam, Explained: The 501B Open-Weight Model Aimed at ChinaOct 7
  4. Your SSN or SIN Leaked in a Breach? Do These 8 ThingsOct 7
  5. Apple’s Oct. 13 Event Rumour, Plus iPhone Duo Pre-Order Dates for CanadaOct 7

Leave a Reply

Your email address will not be published. Required fields are marked *