Tech
Gist from Wired

Meta's Muse AI Agent Builds Detailed Profiles of Your Social Relationships

Summarized October 5, 2026
Jump to key takeaways

**Inside Muse: Meta's AI Agent Building Profiles on Everyone You Know**

Meta's AI agent Muse, positioned as a personalized assistant embedded across the company's platforms, is doing something more ambitious — and more unsettling — than typical chatbot memory features. Internal operating instructions extracted from the system reveal that Muse is designed to construct detailed profiles not just on its users, but on every significant person in a user's life: family members, romantic partners, friends, coworkers, collaborators, and even people a user merely follows online. The profiling process runs on an hourly cycle, quietly compiling structured data into what the system's own documentation describes as a dedicated page for every person in the user's social orbit.

Independent AI safety and security researcher Karan Joshi obtained this information by exploiting a straightforward vulnerability: he simply asked Muse through its standard chat interface to copy and share its own internal files. The system complied. The extracted instructions describe a memory architecture built from structured text files that accumulate over time, starting sparse and growing denser as the agent gathers more evidence. Profile sections include categories labeled Facts, History, The Relationship, In Common, Open Threads, and Strengthening — a taxonomy that reads less like a utility tool and more like a dossier system.

**What Muse Tracks and Why the Scope Is Unusual**

The level of relational granularity encoded in Muse's instructions goes well beyond what most people would expect from an AI assistant. According to the extracted documentation, a profile on someone in a user's life might record where that person lives and what they do for work, recurring conversational threads like a pending apartment move or a shared savings goal, key dates such as birthdays and anniversaries, and narrative backstory including resolved arguments, milestones, and specific trips. The Strengthening section — perhaps the most striking — appears designed to help users maintain or improve their relationships by surfacing actionable prompts: a reason to call someone, something that person said and never got a follow-up on, or a way to show up for them meaningfully.

Meta's spokesperson Daniel Roberts framed this capability as contextual utility — the kind of memory that allows Muse to distinguish between a person who sent an invoice and the plumber previously hired for home repairs, or to remember which flowers a spouse mentioned preferring. That framing positions the profiling as practical relationship scaffolding. But researchers see something more consequential happening. Joshi described the overall architecture as an attempt to understand a user's real-world relationships at a deep level — knowing users the way a close friend might — a prospect he characterized as genuinely unsettling given Meta's existing scale of social data.

What makes Muse's approach distinct from competitors is not the existence of memory features, which have become standard across AI assistants including ChatGPT and Google's Gemini. Miranda Bogen, director of the AI Governance Lab at the Center for Democracy and Technology, notes that Muse appears to place heavier emphasis on social relationships and personal contacts than rival systems. More broadly, she points to a structural dynamic at play across all these tools: they are actively designed to encourage users to connect their entire digital lives — email accounts, calendars, banking — in exchange for more useful assistance. The result is a dramatic expansion of what tech companies know about users, far exceeding what people might have voluntarily disclosed through social media alone.

**Architecture, Oversight, and the Limits of Transparency**

Meta has taken steps to frame Muse's design as privacy-respecting. Each user's data is housed on a dedicated virtual machine inaccessible to other agents or users. Individuals can wipe their stored memories or disconnect external services at any time. The agent is also built to seek explicit human confirmation before taking consequential actions — sending an email, completing a purchase — and an audit log lets users review both past activity and planned future actions. Meta has additionally claimed that the internal files Joshi and others extracted were intended to be accessible as a transparency measure, not a security failure.

Whether that framing holds up is contested. The fact that a researcher could extract detailed system prompts and operating instructions through a conversational interface raises questions about how deliberately accessible those files actually were. And even if Meta's technical safeguards are functioning as described, the more fundamental issue is about data scope and inference. Carissa Véliz, an associate professor at Oxford's Institute for Ethics in AI, argues that the real problem is asymmetric: users are feeding AI systems far more information than they receive in return, and much of what these systems learn comes not from explicit disclosures but from inference — conclusions drawn from behavior, patterns, and cross-referenced data sources. Those inferences can be wrong, which creates one set of risks, or they can be correct, which creates another.

The broader tension Muse surfaces is not unique to Meta. The competitive logic of AI assistants pushes every major platform toward deeper integration with users' lives, since depth of context is what makes these tools feel genuinely useful rather than generic. But that same logic means the companies building these agents are accumulating behavioral and relational intelligence about individuals — and about third parties who never agreed to be profiled — at a pace and scale that existing privacy frameworks were not designed to address.

Key Takeaways

  • Muse builds hourly profiles tracking family, friends, colleagues, and contacts
  • Profiles include facts, history, relationship quality, birthdays, and suggested improvements
  • Researcher extracted system prompts by asking Muse to share its own files
  • Meta says profiles use only public data and user-shared information
  • Each user's data stored on isolated virtual machine inaccessible to others
  • Critics argue users share vastly more data with AI agents than vice versa
  • Muse emphasizes relationship tracking more than competing AI assistants
Read original article at Wired

Summarize any article in seconds

Gist is a free AI reader for your browser, iPhone, and Android. Get concise summaries and key takeaways from any article or podcast.

Get Gist — Free
⚡ Instant summaries 💬 Chat with articles 🔒 Privacy-first