Meta's Muse instructions point to a page on every person in your life

Meta's Muse instructions point to a page on every person in your life

WIRED's Kernel Panic! newsletter, written by Lily Hay Newman and Matt Burgess, reports on what is inside Meta's new personal assistant, Muse. The newsletter describes Muse as a viral hit: millions have downloaded the AI agent, connected it to bank accounts, messages or health data, and let it complete tasks for them.

In recent days, multiple researchers have extracted Muse's internal files and dumped the agent's operating instructions. Meta has maintained that it intended these files to be accessible in the interest of transparency. Independent AI safety and security researcher Karan Joshi pulled an extensive set of instructions and system prompts by using the regular chat interface to essentially ask Muse to copy and share its own software files, then shared the results with WIRED.

One instruction appears to give Muse the ability to create "a page for every person in the user's life." According to the instructions, this hourly process compiles data on family, partners, friends, colleagues, "collaborators," and people the user "follows." Muse uses its "memory" (structured text files) to gather information about those relationships, then makes suggestions, such as pointers on improving a particular relationship or where to take a coffee-loving friend for breakfast.

Muse's documentation says a page may start "sparse" and fill out over time, potentially with sections called Facts, History, The relationship, In common, Open threads, and Strengthening. Facts can hold where a person lives, what they do and recurring threads such as an apartment move or a shared savings goal, plus "dates that matter" like birthdays or anniversaries. History can hold backstory such as a trip in March or an argument that got resolved. The instructions also call for recording "how close they are, what it is built on, how they act with each other, and what it seems to need right now." The Strengthening section suggests things like a reason to call, a date worth remembering, or a way to be there for someone. Meta's instructions say Muse should only use the evidence it has, and that invented details are worse than an empty page.

Joshi reads the design as an attempt to understand the user's relationships with real people: "They're trying to know you like a friend, which is honestly pretty creepy." The newsletter notes that AI chatbots tracking social information is not unusual, since people have long asked ChatGPT for relationship advice, but finds it interesting given Meta's history and vast access to social network data.

Carissa Véliz, an associate professor at Oxford's Institute for Ethics in AI, says people give AI systems much more information about themselves than they get back. She adds that it is not only what users tell the systems but what the systems can infer, correctly or incorrectly, and piece together from other data sources.

Meta describes safeguards. Each user gets a dedicated virtual machine that stores their data and context; it is inaccessible to other agents and users, and users can wipe memories or disconnect external services at any time. Meta says Muse is designed to seek human confirmation before actions such as sending an email or making a purchase, and keeps an audit log where users can see all of the agent's activity and future plans. Meta spokesperson Daniel Roberts told WIRED that for an agent to be useful it needs context about the user and the people they interact with, and that Muse gathers it from public information and what users have chosen to share. His examples: remembering that the person who sent an invoice is the plumber the user hired earlier, or which flowers a spouse liked best.

Miranda Bogen, director of the Center for Democracy and Technology's AI Governance Lab, says memory features are now common in AI assistants, and that Muse appears to put more emphasis on relationships and personal contacts than rivals' systems. Such tools generally offer some transparency and editing, and Muse does too. But she notes that agents and assistants encourage people to share more data rather than focusing on culling it, and that this breadth of access will lead to a ballooning of what they know about users.

Key facts

  • Researchers, including independent security researcher Karan Joshi, extracted Muse's operating instructions and system prompts by asking it through the regular chat interface to copy its own software files.
  • One instruction appears to have Muse create "a page for every person in the user's life," through an hourly process covering family, partners, friends, colleagues, collaborators and people the user follows.
  • Pages may include sections named Facts, History, The relationship, In common, Open threads and Strengthening; the instructions say invented details are worse than an empty page.
  • Meta says it intended the files to be accessible for transparency, and cites a dedicated virtual machine per user, memory wiping, human confirmation for actions like purchases, and an audit log.
  • Oxford's Carissa Véliz and the Center for Democracy and Technology's Miranda Bogen raise concerns about the volume of personal data these assistants collect and infer.

Why it matters

Personal assistants that remember things about you are now common, but the extracted instructions show how far Muse is meant to go: a running page on each person around the user, with notes on closeness, shared history and what the relationship needs. Bogen says Muse appears to emphasise relationships and personal contacts more than rivals' systems. The newsletter also points to Meta's history and vast access to social network data as context for why the design draws attention.

Who it affects

Mainly people using Muse, which the newsletter says millions have downloaded and connected to bank accounts, messages or health data. The pages also describe other people: family, partners, friends, colleagues, collaborators and people the user follows. Those people are the subject of the notes, not the ones who set the assistant up.

How to use it

Meta says the controls sit with the user. Users can wipe Muse's memories or disconnect external services at any time. Muse is designed to ask for human confirmation before actions like sending an email or making a purchase, and an audit log shows all of the agent's activity and future plans. Roberts says Muse draws on public information and what the user has chosen to share. Bogen notes that Muse, like similar tools, offers some transparency and editing capabilities.

How solid is it

The reporting rests on instructions extracted by Joshi and shared with WIRED, and the newsletter says multiple researchers have extracted Muse's internal files. Meta has maintained that it intended the files to be accessible in the interest of transparency. The page-per-person instruction is hedged in the source as something that "appears to be" there, and it is the newsletter's reading of the prompts. The "creepy" verdict is Joshi's own opinion.

Risks and caveats

Véliz warns that what AI systems infer about users, correctly or incorrectly, is concerning for different reasons, and that they can piece together information from other sources. Bogen says the push to plug in emails, calendars and financial institutions will lead to a ballooning of what the tools know. The source does not report any data breach or misuse; the concern is about what the instructions describe. It also does not say Meta uses Muse's relationship data for advertising or shares it with social-network products.

“We are giving AI systems much more information about us than we are getting information from them”

— Carissa Véliz, associate professor at Oxford's Institute for Ethics in AI