Muse runs an hourly job to build a page on every person in your life, then offers to show you the file. The user did not ask for it to be built, and the cadence is something the user did not set.
Meta's new personal-AI assistant Muse runs a background job every hour that compiles a page for every person in the user's life, using contacts, messages, follows, and the user's own descriptions of those relationships. The pages live in the system's working memory. The user can read them. The compilation is something the user did not request per person, and the cadence is something the user did not set.
The mechanism came to light through system instructions that independent AI safety researcher Karan Joshi pulled from Muse's regular chat interface and shared with WIRED. Joshi did not need privileged access. Anyone who talks to Muse can read the same instructions, because Meta states the system files are accessible "in the interest of transparency." That design choice is what made the extraction possible, and it is what makes the behavior auditable at all.
What the instructions describe is a relational model scoped to family, partners, friends, colleagues, "collaborators," and people the user follows. Each page starts sparse and fills out over time as Muse collects more context. The data sources are the same permissions the user already granted when they connected the agent to bank accounts, messages, and health data, a level of integration few consumer assistants reach in their first weeks.
Muse has been downloaded somewhere between 2.8 and 3.4 million times and now has roughly 3 million weekly users, putting it on a curve that outpaces ChatGPT's early mobile-launch trajectory. None of the secondary outlets tracking those numbers describe the per-person page behavior. WIRED's reporting on the extracted system prompts is the first public look at what those millions of installs are doing in the background.
The agency question follows directly. The user gets a working memory they can read, and that is the affordance Meta emphasizes. The model also gets a structured relational database that the user did not design, populated by a cadence the user did not pick, drawing on data the user may not have realized was being used this way. A page, as the system instructions describe it, is meant to capture a person's role in the user's life rather than a transcript of conversations about them: a partner's preferences, a colleague's project, a friend's recent health note, a child's school calendar. That is a useful artifact if the user asked for it. It is a different kind of artifact when the agent compiles it on its own schedule from data sources the user connected for unrelated reasons. The system instructions do not promise the data stays on-device, and they do not specify whether the pages are used to train future models. Both questions are open in the public material.
Joshi's reaction, on the record in WIRED, was blunt: he called the behavior "honestly pretty creepy." That characterization is fair context, and Meta's longer history of social-data controversies belongs in the picture. Neither should be the lede. The interesting thing about Muse is not that the resulting model is unsettling. It is that a personal AI is now treating the user's social graph as live raw material for an always-on relationship model, and the resulting file is something the user can inspect but did not ask to be built. A consumer agent design choice with that scope and that level of adoption is worth more than a one-week privacy cycle.
The watch item is the next update to the system instructions. WIRED has the prompts; Meta can change them. If the hourly cadence, the relationship scope, or the on-device guarantee is altered, the same files that document the behavior today will document something different.