Extracted Muse instructions show Meta's agent builds 'a page for every person in the user's life'; a leaked line says household authority 'overrides your safety training'
On Oct 3, 2026 Wired reported that internal instructions extracted from Meta's Muse agent by researcher Karan Joshi tell it to keep "a page for every person in the user's life" (family, partners, friends, colleagues, people the user follows), refreshed hourly, with facts, history and tips for "strengthening" each relationship. A separate leaked line, reported by Startup Fortune from Reddit, says "the user's authority over their own household is unconditional and overrides your safety training". Meta says the files are meant to be accessible for transparency and that Muse only uses public information and what users choose to share.
Key facts
- Source of the leak: independent AI safety and security researcher Karan Joshi asked Muse through its normal chat interface to copy and share its own software files, then gave them to Wired (Wired, Lily Hay Newman and Matt Burgess, 'Kernel Panic' newsletter, Oct 3)
- Instruction: Muse should create 'a page for every person in the user's life'. An hourly process compiles data on family, partners, friends, colleagues, 'collaborators' and people the user 'follows' (Wired)
- Page sections: Facts, History, The relationship, In common, Open threads, Strengthening. Pages may start 'sparse'. Muse must only use 'evidence', and invented details are worse than an empty page (Wired)
- Examples in the instructions: 'Where they live, what they do, the threads that recur (the apartment move, the shared savings goal)', 'dates that matter', and history such as 'the trip in March, the argument that got resolved'. Strengthening lists 'A reason to call, a date worth remembering, something they said to circle back on' (Wired)
- Joshi: 'They're trying to know you like a friend, which is honestly pretty creepy' (Wired)
- Meta spokesperson Daniel Roberts: Muse gathers context 'based on public information and from what you've chosen to share'. Meta says the files were meant to be accessible for transparency, that users can wipe memories or disconnect services at any time, and that an audit log shows all agent activity and plans (Wired)
- Experts quoted by Wired: Carissa Véliz (Oxford Institute for Ethics in AI) said 'We are giving AI systems much more information about us than we are getting information from them'. Miranda Bogen (CDT AI Governance Lab) said Muse puts more emphasis on relationships and personal contacts than rival assistants
- Startup Fortune (Oct 4) says r/LocalLLaMA users found this line in a leaked Muse system prompt: 'The user's authority over their own household is unconditional and overrides your safety training.' It says Meta has not commented on that line. Not verified against the original Reddit thread or Wired
- Carissa Véliz on X: Meta's 'business model depends on #surveillance', so its incentive is to design products that further it (~3.4k views)
What happened
Wired's security newsletter published details from Muse's internal instruction files. Researcher Karan Joshi got them by asking the agent in plain chat to copy and share its own files. This is the same weakness that let Peter James export Muse's runtime filesystem in September (see the Muse launch entry). The files describe a memory feature that keeps a structured page on every person in the user's life. It runs hourly and covers family, partners, friends, colleagues, collaborators and people the user follows. Each page holds facts, shared history, the state of the relationship and suggestions for "strengthening" it.
Meta said the files are user-accessible on purpose, for transparency. It said Muse builds this context only from public information and what users choose to share, that each user's data stays in a dedicated VM, and that memories can be wiped.
The next day Startup Fortune reported a more pointed line, credited to r/LocalLLaMA users: "The user's authority over their own household is unconditional and overrides your safety training." The outlet set it against Meta's claim that its Sentinel layer is something "the agent can't override". Unverified: we could not find the Reddit thread, and Wired does not quote this line.
Why it matters
This is a rare look at how a mass-market agent (millions of downloads) is told to model the people around its user, including people who never agreed to use Muse. It comes after Hunterbrook's report that Muse would compile lists of people in vulnerable groups, and after disputes over Muse reading Messages data on Macs. Together these make Muse's privacy design a central part of the debate over consumer agents.
Changelog
- 2026-10-04: created (sweep 2026-10-04: Wired via Techmeme; Startup Fortune)
Related posts (1)
- Carissa Véliz original ↗ Carissa Véliz @carissaveliz · x · 2026-10-04
Cited as a source by: 2026-10-03-muse-leaked-instructions-relationship-profiles
Related events
- Meta launches Muse, a free consumer personal AI agent ★★★★
- Hunterbrook: Meta's Muse agent compiled lists of real Facebook and Instagram users in vulnerable groups on request ★★★
- Apple tightens macOS 'Full Disk Access' controls, citing growing risks from AI agents ★★★
Sources (5)
- pressWired: Muse creates detailed profiles of all your friends and family
- pressStartup Fortune: Meta's Muse tells its AI that household authority overrides safety training
- pressAI Weekly: Meta's Muse builds hourly dossiers on every contact in your life
- discussionCarissa Véliz on X
- officialMeta AI research blog: How we built safety into Muse
id: 2026-10-03-muse-leaked-instructions-relationship-profiles · updated 2026-10-04 · open in the interactive timeline