On October 3, 2026, WIRED's Lily Hay Newman and Matt Burgess reported on the operating instructions inside Muse, Meta's personal AI agent. Independent AI safety researcher Karan Joshi extracted them "by using the regular chat interface to essentially ask Muse to copy and share its own software files," and shared them with WIRED. Meta has said it intended the files to be accessible in the interest of transparency.
The headline instruction: Muse can create "a page for every person in the user's life." According to WIRED, this is an hourly process that compiles data on family, partners, friends, colleagues, "collaborators" and people the user "follows," stored in the agent's memory as structured text files. The instructions describe sections such as Facts, History, The relationship, In common, Open threads and Strengthening -- recording "where they live, what they do," "dates that matter," and history like "the argument that got resolved." The Strengthening section proposes "a reason to call, a date worth remembering." The instructions also say Muse should use only the evidence it has, and that invented details are worse than an empty page.
"They're trying to know you like a friend, which is honestly pretty creepy," Joshi told WIRED.
Meta's response. Spokesperson Daniel Roberts said an agent "needs to have context about you and those you interact with," and that "Muse gathers that based on public information and from what you've chosen to share." Meta says each user has a dedicated virtual machine inaccessible to other agents, that users can wipe memories or disconnect services, that Muse asks for confirmation before sending email or buying something, and that an audit log shows its activity and plans.
Separately, Startup Fortune reports a line from a leaked Muse prompt circulating on Reddit: "The user's authority over their own household is unconditional and overrides your safety training." WIRED's report does not quote that line, and Startup Fortune says Meta had not commented on it; treat it as unconfirmed.
The adoption constraint is consent, and not only the user's. The people being profiled -- a user's colleagues, partners, friends -- never connected anything to Muse. Miranda Bogen of the Center for Democracy and Technology told WIRED that assistants like this are "actively soliciting users to plug their whole lives in." Oxford's Carissa Véliz pointed out that the risk includes what such systems can infer, correctly or not.
Analysis: Meta's controls -- per-user VM, confirmations, audit log, memory wipes -- protect the user from the agent. None of them address the third parties in the relationship pages, who cannot see, correct or delete what has been written about them. For companies, the immediate implication is simpler: an employee who connects a work mailbox or calendar to a personal agent like this is feeding colleague and customer information into hourly profiles outside any corporate data policy. That is a reason to block or govern personal-agent connectors on work accounts now, before a regulator decides what a "relationship page" about a non-user is.
WIRED's October 3 report shows Meta's Muse instructed to keep hourly 'relationship pages' on everyone in a user's life; Meta's safeguards protect the user, not the profiled contacts, and companies should treat personal-agent access to work mail and calendars as a data-governance problem.