Skip to content
Apixo
Blog
news· 4 min read· via Wired AI

Meta AI Assistant Muse Exposed Building Detailed Personal Network Dossiers

Leaked internal files reveal how Meta's viral AI agent Muse builds detailed relationship profiles on users' friends, family, and contacts using structured memory.

Meta AI Assistant Muse Exposed Building Detailed Personal Network Dossiers

Meta’s personal assistant agent, Muse, has rapidly accumulated millions of downloads, with users granting the AI access to sensitive streams including messages, bank accounts, and health metrics to automate daily tasks. However, recent leaks of the system's underlying operating files have revealed detailed mechanisms governing how the assistant structures, retains, and utilizes user information. Independent AI safety and security researcher Karan Joshi successfully extracted an extensive set of Muse’s system prompts and internal instructions by prompting the agent directly through its standard chat interface to copy and share its own configuration files.

The disclosed files reveal that Muse is explicitly instructed to build detailed profiles for individuals in a user's life. According to the internal instructions, the system executes an hourly process to aggregate data on partners, family members, friends, colleagues, collaborators, and followed accounts. Muse organizes this information into structured text files termed "memory," creating dedicated entries for each contact to help deliver tailored suggestions and automated support.

How Muse maps personal networks

The leaked documentation specifies that a contact page begins with sparse information and expands over time. Standardized profile layouts include sections labeled Facts, History, The relationship, In common, Open threads, and Strengthening. Muse is instructed to record concrete points such as location, profession, recurring context like an apartment move or shared financial targets, and significant dates including birthdays and anniversaries.

Furthermore, the system captures subtle interpersonal dynamics, documenting how close people are, what grounds their connection, and how they interact. The "Strengthening" module generates actionable recommendations to improve specific relationships, such as prompts to call, follow up on previous conversations, or mark significant personal events. Meta’s system instructions strictly prohibit hallucinated information, dictating that an empty entry is preferable to invented data and that all recorded points must rely solely on explicit "evidence."

Reflecting on the system prompts, Joshi noted that Meta's setup appears focused on deep relationship tracking, stating that the company aims to understand real-world personal connections to act like a friend. Commenting on the broader implications, Carissa Véliz, an associate professor at Oxford’s Institute for Ethics in AI, emphasized that users frequently provide significantly more context to AI systems than they receive, both through explicit inputs and inferred data points pulled together across varied sources.

Security design and administrative controls

To manage data privacy and isolate user environments, Meta architected Muse around dedicated virtual machines (VMs) for each user. Individual VMs store user-specific context and memory files, preventing cross-agent data exposure. Users retain administrative privileges to clear accumulated memories or disconnect linked third-party services whenever necessary. Additionally, the system incorporates an audit log detailing historical actions and prospective plans, while requiring explicit human authorization before executing external actions such as sending emails or processing financial purchases.

Meta spokesperson Daniel Roberts explained that useful agents require thorough context regarding users and their social circles. According to Roberts, Muse builds these profiles using public information and user-shared data, enabling the system to recognize connections such as identifying a plumber from a previous invoice or recalling a spouse’s preferred flowers. However, Miranda Bogen, director of the AI Governance Lab at the Center for Democracy and Technology, pointed out that Muse places a much stronger emphasis on relationship tracking than rival assistants. Bogen noted that such tools actively encourage users to connect emails, calendars, and financial accounts, driving a major expansion in the volume of personal data held by tech platforms.

What it means for developers

The mechanics exposed in Muse highlight how major tech platforms are approaching persistent memory, agentic architecture, and contextual retrieval. Rather than relying purely on vector databases or unstructured context windows, Meta’s engineering design utilizes structured text files within isolated virtual machines to maintain state and relationship hierarchies over time. The strict instruction for the model to rely solely on verifiable evidence rather than generating details offers a blueprint for prompt engineering where factual integrity is crucial.

For software engineers building agentic workflows or context-aware applications, analyzing how Muse separates runtime environments and categorizes profile schemas (such as Facts, History, and Open threads) provides clear guidance for structuring personal data layers. As developers explore building similar contextual systems using top-tier foundational models, accessing multiple LLMs efficiently becomes essential. Tools like Apixo (https://apixoai.online) allow developers to test and deploy various leading AI models through a single API key on a flexible pay-per-token basis, simplifying prompt testing and model benchmarking across providers.

Ultimately, Muse’s architecture shows that the future of personal AI assistants relies heavily on strict boundaries between user execution environments, combined with structured memory schemas that balance rich contextual awareness with granular user controls like audit logs and manual step-confirmations.


Source: Muse Creates Detailed Profiles of All Your Friends and Family — Wired AI. Written by the Apixo team from that report.

#ai-news#ai#meta#privacy#cybersecurity#llm
Try it with your own tools

One key for Claude, GPT, GLM, DeepSeek and more. Pay per token with crypto.

Get your API key

Keep reading