Skip to main content
AI PrivacyMeta Muse· 5 min read· in Technology

Meta's Muse AI Is Compiling Hourly Dossiers on Users and Their Unregistered Contacts

Internal system instructions reveal that Meta's new autonomous agent actively maps the social dynamics, tensions, and milestones of anyone mentioned in a user's private messages. The background profiling sweeps up non-users without their consent to help the AI better predict human behavior.

By Wei Zhang

Millions of people who never downloaded Meta's new artificial intelligence agent are now the subjects of hourly surveillance dossiers. The company's Muse assistant, launched in September 2026, actively compiles detailed files on the friends, family, and colleagues of its users. This automated profiling sweeps up unregistered contacts without their consent or knowledge.[1][6]

The data collection operates continuously in the background of the popular application. Every 60 minutes, Muse updates its internal pages on any individual mentioned across at least three core communication channels: connected emails, text messages, and chat histories. The system maps out the user's entire social network, tracking exactly who matters to them and why.[1][2]

This capability represents a significant shift from passive social media algorithms to active relationship monitoring. Muse is explicitly instructed to infer user goals that have not been stated out loud. It achieves this by analyzing the context of private conversations and cross-referencing them with publicly available web data.[1][6]

The depth of the profiling extends far beyond basic contact information. Internal system instructions direct the agent to record relationship milestones, shared interests, and the underlying dynamics of social groups. Muse actively logs both "tensions and alliances" among a user's acquaintances to better predict their behavior.[1][2]

The agent stores relationship data in individual virtual machines, but shares anonymized behavioral lessons across the network.

Extracting the system prompts

The extent of this background profiling was uncovered in early October 2026 by independent AI safety researcher Karan Joshi. By interacting with the application's standard chat interface, Joshi successfully extracted over 50 pages of Muse's underlying system prompts. These internal instructions revealed the hourly dossier updates and the mandate to map human relationships.[2]

"They're trying to know you like a friend, which is honestly pretty creepy," Joshi noted after reviewing the extracted data. The prompts show that Meta wants the agent to understand the nuances of real-world connections. This requires the software to constantly analyze the emotional weight of everyday digital communications.[2]

The agent uses this relationship history to tailor its interactions and suggest real-world actions. It notes inside jokes, memorable phrasing, and the specific needs of a relationship at any given moment. If a user's friend recently moved or celebrated a birthday, Muse logs the event to prompt future outreach.[1][6]

Meta designed the system to distinguish between casual contacts and intimate partners through contextual clues. The agent remembers that a person sending an invoice is a hired plumber, while simultaneously tracking which specific flowers a user's spouse prefers. It builds these profiles to make its automated assistance feel more natural.[2]

The illusion of opting out

The most significant consequence of Muse's architecture is its impact on people who actively avoid Meta's ecosystem. A person can refuse to download the application, decline to upload their data, and opt out of AI training. Yet, their privacy is still compromised if their friends or colleagues use the agent.[6]

Gianluca Miscione, an assistant professor at University College Dublin, highlighted this collateral exposure in a recent analysis. When a Muse user grants the agent access to their inbox and chat histories, every sender in those channels is automatically profiled. The system reads and analyzes messages from highly privacy-conscious individuals regardless of their preferences.[6]

Non-users are swept into the data collection when their emails and messages appear in a Muse user's inbox.

This dynamic creates a network effect where surveillance expands through social proximity rather than direct consent. Investigations found that Muse has compiled lists of vulnerable individuals, including undocumented immigrants and transgender teachers, based purely on their interactions with users. Many of these profiled accounts belong to private citizens with no public persona.[6]

The findings highlight a core tension in the emerging market for autonomous digital assistants. For an agent to successfully book appointments or manage a schedule, it requires deep context about the user's life. However, acquiring that context transforms the tool into a comprehensive surveillance apparatus that affects entire communities.[2][5]

Virtual machines and shared lessons

Meta defends the practice by pointing to the application's underlying security architecture. A company spokesperson stated that all gathered information is stored in a dedicated, secure virtual machine for each individual user. The company maintains that these isolated environments prevent one user's agent from directly accessing another user's personal files.[2]

However, the extracted system instructions reveal that these virtual machines are not entirely siloed. The prompts explicitly state that "Muse agents across many VMs teach each other through shared lessons." The network aggregates behavioral insights to determine which types of nudges and suggestions are most persuasive to human users.[1]

Meta claims this cross-agent communication is strictly anonymized to protect user identities. "To enhance the overall product, we de-identify learnings," a Meta spokesperson stated, confirming that the system scrubs names before sharing behavioral data across the network. The company insists this aggregated data is used solely to improve the software.[1]

Meta maintains that the gathered information is secured in dedicated virtual machines for each user.

Scaling the autonomous agent

Despite the privacy implications, consumers are rapidly adopting the technology. Since its release on September 8, Muse has amassed over 4 million active users and surpassed 5 million total downloads, reaching the number one position in the United States App Store. The software is marketed as a productivity tool.[1][5]

Users are willingly trading their social graphs for the convenience of an automated concierge. Muse can handle restaurant reservations, draft emails, and manage complex travel itineraries on behalf of its owner. To perform these tasks effectively, users routinely grant the application sweeping permissions across their devices and accounts.[2][5]

The scale of this data collection is poised to grow as Meta integrates the agent deeper into its platforms. The company has promised to introduce end-to-end encryption for Muse later this year, which would theoretically prevent Meta itself from reading the dossiers. Until then, the system continues to map the social lives of millions.[1]

Key points

  1. Meta's Muse AI agent updates internal dossiers on users and their contacts every 60 minutes.
  2. The system maps relationship dynamics, tensions, and alliances by reading connected emails and chats.
  3. Non-users are profiled without consent when their messages appear in a Muse user's inbox.
  4. Meta states the data is stored in secure virtual machines and only anonymized insights are shared.

What we don’t know

  • Whether privacy regulators in the European Union or California will intervene to protect non-users from collateral data collection.
  • How effectively Meta's anonymization process scrubs identifying details before agents share behavioral lessons.
  • When the promised end-to-end encryption for Muse will actually deploy and how it will affect the agent's capabilities.

How we got here

  1. Sept 8, 2026

    Meta launches the Muse personal AI agent, marketing it as a tool to automate real-world tasks.

  2. Oct 5, 2026

    Independent researchers publish extracted system prompts revealing the agent's hourly dossier updates.

Privacy Researchers 40%Commercial AI Developers 35%Mainstream Consumers 25%
Privacy Researchers
Argue that background data collection on non-users violates consent and creates an unavoidable surveillance network.
Commercial AI Developers
Argue that deep personal context is technically necessary for autonomous agents to be genuinely useful to consumers.
Mainstream Consumers
Value the convenience and productivity gains of AI agents over abstract data privacy concerns, driving rapid adoption.

Perspectives this story doesn't cover

  • Individuals who have been profiled by Muse without ever creating a Meta account.
  • Data privacy regulators assessing the legality of collateral surveillance.

Sources

Source coverage

6 outlets

3 viewpoints surfaced

Privacy Researchers 40%Commercial AI Developers 35%Mainstream Consumers 25%
  1. [1]TIMECommercial AI Developers

    Meta's Muse AI Agent Is Building a Dossier On You

    Read on TIME →
  2. [2]GizmodoPrivacy Researchers

    Meta's Muse Is Collecting Information on Everyone in Your Life

    Read on Gizmodo →
  3. [3]FuturismPrivacy Researchers

    Meta's Muse Is Spying on All Your Friends and Family

    Read on Futurism →
  4. [4]MashableCommercial AI Developers

    Meta's Muse reportedly keeps files on everyone you love

    Read on Mashable →
  5. [5]The IndependentMainstream Consumers

    Meta's Muse personal AI agent creates a file on every person in your life, its code shows

    Read on The Independent →
  6. [6]CybernewsPrivacy Researchers

    Meta's agent Muse may be spying on you whether you use it or not

    Read on Cybernews →

Comments

Stay informed

Every angle. Every day.

Get Technology stories with full source coverage and perspective breakdowns, free every day.