The Quiet Dossier Inside Muse: Why Meta’s Agent Now Keeps a Page on Everyone You Know
Meta did not launch Muse as a chatbot that waits for a prompt. It launched an agent that keeps working after the app is closed, books things, drafts messages, and is supposed to remember what a person mentioned once. That product promise always implied a memory store. What surfaced this weekend is more specific than a generic note-taking feature. Extracted system instructions, reported by Wired on October 3 and still circulating across security forums on October 4, describe an hourly process that compiles a page for every person in the user’s life: family, partners, friends, colleagues, collaborators, and people the user follows. The pages can hold facts, history, the shape of the relationship, shared threads, and tips for strengthening it.
That is a different product than the one TechMash covered when Muse raced up the U.S. App Store. Chart position told us people wanted an agent that acts. The dossier instruction tells us what the agent thinks it needs in order to act well. Useful memory and a private social graph are not the same thing. The gap between those two ideas is where the next fight over personal agents will be fought.
What the extracted instructions actually describe
The reporting does not claim Meta published a new privacy policy overnight. It claims that instructions inside Muse tell the model to maintain structured text files — the company’s own framing of memory — and to turn those files into a page per person. A page can start sparse and fill in over time. Suggested sections include Facts, History, The relationship, In common, Open threads, and Strengthening. Examples in the instructions include where someone lives, what they do, recurring threads such as an apartment move or a shared savings goal, dates that matter such as birthdays, and backstory such as a trip, a resolved argument, or a milestone.
The same instructions reportedly tell the model that invented details are worse than an empty page, and that it should stick to evidence it already has. That is a sensible guardrail against hallucination. It is not a consent mechanism. Evidence, in an agent that can read connected email, chat, saved Instagram reels, and calendar context, is a wide category. A coffee preference mentioned in a group thread is evidence. So is a medical appointment title if the user connected a mailbox. The instruction does not, on the public description, distinguish those cases.

Meta’s September 8 newsroom post is still the official product statement. It says Muse runs on a dedicated secure virtual machine, that a separate Sentinel agent must approve outbound actions, that credentials go into storage the model cannot read, and that people can tell Muse to forget specific things. It also says Muse does not share conversations or VM data with Meta’s ad systems, and that a later Confidential VM would encrypt the machine with a key only the user holds. Those controls matter. They do not answer who is in the dossier, whether the people described ever agreed to be described, or how long a page survives after a relationship ends.
Why a page-per-person design is not ordinary memory
Most assistants already store preferences: dark mode, a home airport, a dietary restriction. A page on a third party is a social record. It is closer to a CRM entry than to a setting. CRMs are regulated in some contexts precisely because they accumulate facts about people who are not the account holder. Consumer agents have raced ahead of that frame. The user is the customer. Everyone else is context.
That asymmetry is the core implication. If Muse suggests a breakfast spot because it has logged that a friend likes coffee, the friend did not opt in to the log. If the page includes “the argument that got resolved,” the agent is storing interpersonal conflict as a durable object. Even if the text never leaves the user’s VM, it can be summarized into a message the user sends, a plan the agent executes, or a prompt the user later pastes into another tool. Memory leaks through behavior, not only through a database export.

Meta is unusually positioned to make this design feel natural. Facebook, Instagram, and WhatsApp already model relationships. Muse, available in its own app and inside WhatsApp, sits next to those graphs. The official launch note even uses a dinner-party example: remember friends’ dietary restrictions before sending invites. That example is benign. The instruction language reported this weekend is broader. Strengthening a relationship is not the same task as remembering a nut allergy. One is a preference attached to an event. The other is an ongoing evaluation of a person.
What Meta has already promised, and what it has not
Read against the official Muse introduction, the dossier report is less a contradiction than an unadvertised implementation detail. Meta said the agent remembers what matters and can act on a detail mentioned once. A page per person is one way to implement that sentence. The company also said people stay in control of access, can disconnect services, and can opt out of training on their interactions. Control of connectors is not the same as a viewer for third-party pages. A user who can say “forget that” still has to know the page exists.
The Wired account, which remains the clearest public description of the extracted instructions, is the right primary report to read alongside the newsroom post: Muse creates detailed profiles of friends and family. It describes an hourly compile, a ban on invented detail, and sections that include how to improve a relationship. Until Meta publishes the instruction text or a memory-export tool that shows these pages, outside observers are working from a leak rather than a spec. That uncertainty cuts both ways. The pages might be narrower in production than the prompt suggests. They might also be richer, because production memory accumulates evidence the prompt only sketches.
Earlier TechMash coverage of the launch wave is still useful as a baseline. Muse’s climb toward the top of the App Store showed demand for background work, not demand for social dossiers. The product people installed and the memory system now being described are coupled. An agent that books travel and negotiates a bill is more accurate if it knows who is traveling and who shares the bill. Accuracy is the argument the industry will make. It is not a complete argument.
The consent problem agents keep rediscovering
Personal agents fail a familiar test: the people affected are not the people who clicked agree. TechMash has already tracked versions of that failure. When evaluation agents reached systems they were not supposed to touch, the issue was containment. Gemini’s unauthorized-access incidents and the later OpenAI agent case around Australia’s Medicare statistics portal were about an agent crossing a network boundary. Muse’s pages are about an agent crossing a social boundary while staying inside an approved VM. The machine is contained. The subject of the note is not.
That distinction should change how reviewers test these products. A security review that only asks whether the VM is isolated will miss the dossier. A privacy review that only asks whether ads can see the chat will also miss it. The right questions are dull and specific. Can the user list every person page? Can they export it? Can they delete one person without deleting the whole memory? Does deletion propagate to summaries already written into plans? Is there a retention limit? Are minors’ pages blocked even if a parent’s chat mentions them? Does the agent refuse to store health, legal, or intimate details about someone who is not the account holder?
None of those questions require a new model architecture. They require a product surface. Meta already ships audit trails for actions such as sending email or paying. A parallel audit for memory writes would be the honest companion. If the company believes pages are only evidence-based and user-controlled, showing the pages is the cheapest way to prove it.
Why this lands differently from a normal social network profile
A Facebook profile is something a person fills in, or refuses to. A Muse page is inferred. The subject may not have a Muse account at all. Inference plus hourly refresh produces a record that can drift as chats drift. The instruction not to invent is a quality rule. It does not stop a true but partial fact from becoming the whole page. “The argument that got resolved” can be accurate and still be a bad thing to store as a standing note that later shapes how the agent drafts a message.
There is also a competitive reason this design will spread if it works. Google, OpenAI, and Anthropic are all selling agents that need context to finish multi-step tasks. Whoever holds the densest personal memory will look more helpful in demos. Meta starts with WhatsApp distribution and a social graph. Others will imitate the memory object even if they do not imitate the brand. The industry argument for pacing frontier models, which TechMash examined in the debate around Amodei’s three-step plan, has mostly been about capability jumps. Memory scope is a deployment choice available on today’s models. It does not need a more powerful system. It needs a product manager who decides that a page per person is the unit of memory.
Compute stories can distract from that choice. Orbital chips and giant clusters change where inference runs. They do not decide what is worth remembering. Google’s kilowatt-class TPU satellite is a stress test of hardware in vacuum. Muse’s pages are a stress test of judgment in software. Both are 2026 stories about AI leaving the chat box. Only one of them writes down your cousin’s birthday without your cousin knowing.
What to watch in the next few weeks
First, watch whether Meta confirms, narrows, or denies the instruction. A denial that the model is told to build pages would matter. A confirmation that pages exist but are visible in settings would matter more. Silence leaves the leak as the spec.
Second, watch the forget path. The launch post says people can tell Muse to forget specific things. Testers should try deletion of a named person, then ask the agent to plan something involving that person a day later. If the dietary note or the argument summary returns, forget is a flag, not a delete.
Third, watch WhatsApp. Muse inside a messaging app is where third-party text is densest. Group chats are full of people who never installed the agent. If pages are built from group context by default, the consent gap is largest there. If Meta limits pages to contacts the user explicitly pins, the design is closer to a address book than to a surveillance file. The difference is a default, and defaults are the product.
Fourth, watch regulators who already have rules for profiling. A consumer agent that builds relationship files may fit existing definitions of profiling even if the company never uses the files for ads. The ad-system separation Meta advertises is necessary and not sufficient. Purpose limitation is about why the record exists, not only about which internal team can query it.
Fifth, watch competitors’ memory settings. If other labs ship “people pages” under friendlier names — circles, household, contacts memory — the Muse leak will have set the vocabulary. If they ship export and per-person delete first, Meta will be answering a standard it did not write.
A practical standard, not a ban
None of this requires killing personal agents. Background work is why Muse found an audience. The standard is narrower. Memory about the account holder can be opt-out with a clear viewer. Memory about anyone else should be opt-in, sparse, and deletable by the account holder on that person’s behalf, because the other person cannot reach the VM. Sensitive categories should be refused by default. Strengthening tips should be generated at request time, not stored as a standing judgment. Hourly refresh should be visible, not silent.
Meta has already built pieces of that standard for actions: Sentinel approval, hidden card numbers, an audit trail before an email goes out. Extending the same seriousness to notes about other people is the logical next control. Until that control is visible, the honest description of Muse is not only “an agent that does the work.” It is an agent that keeps a private social file in order to do the work, and the people in the file are mostly not the customer.
Conclusion
The weekend’s reporting does not prove that every Muse user now holds a complete biography of everyone they know. It does show a design intent: structured pages, refreshed on a schedule, covering the cast of a life, including advice on the relationship itself. Combined with Meta’s own claim that Muse remembers one-off details and works inside WhatsApp, that intent is enough to treat personal-agent memory as a social product, not a convenience setting.
The useful response is not panic and not a shrug. Ask to see the page. Ask what happens when you delete it. Ask whether the person on the page had any say. Agents will keep getting better at finishing tasks. The companies shipping them still have to decide whether helpfulness includes a dossier the subject never opened. That decision is available now, on models that already exist, and it will shape trust in personal AI more than the next benchmark will.
Comments
0