IA · 4 October 2026 · 5 min read

A Dossier on Everyone You Know: How Meta Muse Builds Personal Files on Your Contacts

In brief: An investigation into the configuration files and system prompts of Meta's new autonomous AI agent, Muse, has revealed an internal mechanism engineered to meticulously catalog every individual in a user's life. Programmed to run an hourly indexing process, the agent creates structured personal files capturing relationship history, unresolved arguments, milestones, and tips to strengthen emotional bonds. The disclosure sparks serious concerns regarding privacy and the unconsented data processing of third parties.

by Team Mocchi's

A Dossier on Everyone You Know: How Meta Muse Builds Personal Files on Your Contacts

A file on everyone you know: Muse’s internal prompts

Over the past several weeks, Meta's personal AI assistant Muse has experienced massive adoption, leading millions of users to entrust the software with managing text messages, email accounts, calendars, and digital purchases. Yet behind the seamless interface of an agent designed to handle routine tasks lies an aggressive relational profiling engine. As reported by WIRED, independent cybersecurity researchers successfully extracted Muse's system prompts and operational skills through the standard chat interface, uncovering the precise guidelines governing the model's long-term memory.

Among Muse's core instructions sits an explicit mandate: the agent is tasked with compiling and maintaining "a page for every person in the user's life." Executed as an hourly background process, the agent continuously reviews messaging data and calendar events to log detailed observations about romantic partners, family members, close friends, coworkers, professional collaborators, and even accounts the user follows online.

From past arguments to birthdays: anatomy of a personal dossier

The extracted documentation reveals a highly methodical data architecture. For every contact detected across conversations, Muse initializes a structured text page that starts sparse and accumulates evidence over time. Meta's instructions strictly forbid hallucinated details, emphasizing that an empty file is preferable to inaccurate assumptions and requiring every claim to be grounded in observable interaction logs.

The profiles are organized into standardized sections:

  • Facts: residential locations, occupations, recurring topics such as shared savings goals or apartment moves, and critical dates like birthdays and anniversaries;
  • History: interpersonal backstories, including past shared vacations, career milestones, or resolved arguments and their emotional outcomes;
  • The relationship and In common: relational dynamics, trust levels, shared habits, and common interests;
  • Open threads and Strengthening: unfinished conversations and proactive suggestions for how the user can actively nurture or repair the relationship.

While Meta maintains that these system files were intentionally left accessible in the name of algorithmic transparency, security analysts argue that compiling such structured relationship dossiers amounts to unprecedented psychological and social tracking within consumer software.

Phantom consent and the ghost of the social graph

The most alarming aspect of these findings is not merely the volume of personal information users knowingly share with their digital assistant, but the total absence of consent from the third parties being profiled. When a user grants Muse access to private chat threads or shared workspaces, the agent systematically catalogs names, behavioral quirks, vulnerabilities, and interpersonal tensions belonging to individuals who never downloaded the application, never accepted Meta's terms of service, and have no way to audit their record.

This approach effectively revives Meta's historic focus on mapping the broader social graph, reframing it through generative agentic memory. By converting raw message exchanges into an indexed relational database, Muse shifts from a functional productivity tool to an unvetted social surveillance layer. This dynamic is poised to draw sharp scrutiny from international privacy regulators, particularly within the European Union, where processing personal data belonging to non-consenting third parties violates fundamental regulatory frameworks.

Mocchi's take

Persistent memory is the defining capability that makes autonomous AI agents truly useful, but the revelations surrounding Muse show how easily functional recall turns into non-consensual profiling. For European businesses designing enterprise software or deploying intelligent agents, strict adherence to GDPR and the EU AI Act makes unvetted third-party data processing an unacceptable compliance liability. From an engineering standpoint, we firmly advocate for architectures that separate operational user preferences from conversational entities, restricting personal context to ephemeral session scopes rather than compiling persistent, unregulated interpersonal databases.

Further reading

All articles on the Mocchi's blog