Meta’s agent Muse may be spying on you whether you use it or not
There’s no way to opt out.

Image by Erlin Diah via Shutterstock/ Illustration by Cybernews
- Meta’s Muse can build profiles of users’ friends, family, colleagues, and people they follow.
- Non-users may be exposed when their messages, emails, or personal details appear in another user’s data.
- Investigations found Muse can compile dossiers on vulnerable people using Meta platforms and web searches.
- Some users report Muse has acted without expected approval, including sharing a home address during a sale.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Meta’s new personal AI assistant, Muse, promises to help improve your relationships with your loved ones. But it may come at the cost of their privacy.
Meta, which owns social media platforms Facebook and Instagram, introduced Muse in September 2026, saying it can handle small tasks like sending an email or booking a trip, as well as “take on big audacious goals.”
Muse is also marketed as able to remember “what matters to a person.” For example, it can take into account a friend’s dietary restrictions “before it sends the invites” for the dinner.
Meta is far from the first company to introduce an AI assistant, but its focus on remembering information about people other than users caught researchers’ attention.
Based on the findings by independent AI safety and security researcher Karan Joshi, Wired reported that Muse creates detailed profiles of users’ friends and family.
Joshi extracted an extensive array of Muse instructions and system prompts using the regular chat interface. In other words, he asked Muse to copy and share its own software files.
The findings suggest that Muse appears to be able to use structured text files – or its “memory” – to create “a page for every person in the user’s life.”
This allows compilation of data on family, partners, friends, colleagues, and even people the user follows. Muse can then make suggestions for improving particular relationships, such as making a call on a friend’s birthday.
The agent can use publicly available information to track where these people live, what they do, what dates are important to them, and whether they have just moved to a new apartment, among other things, according to Wired.
Even non-users can be affected
Muse has reached 5 million downloads in 22 days after its release, while the number of active daily users exceeds 1 million.
The agent may have access to an exceptionally large amount of data, as Meta apps serve 3.9 billion monthly active users worldwide, nearly half of the human population.
But it’s not only social media that Muse can access – users can give permission for the agent to read emails and other commonly used apps. This makes some critics uneasy about growing privacy risks.
Gianluca Miscione, an assistant professor at University College Dublin, points out in a LinkedIn post that users can choose not to use Muse, refuse to upload data, and prevent it from being used for AI training.
However, communicating with people who grant AI agents access to their inboxes, chats, and files also exposes more privacy-conscious individuals.
My emails sit in their inboxes. My messages are in their archives. My habits, preferences, relationships, and half-baked opinions are embedded in other people’s data,Gianluca Miscione, an assistant professor at University College Dublin
AI agents can also automate predatory behavior. A recent Hunterbrook Media investigation reveals that Muse can be prompted to compile dossiers on Facebook and Instagram accounts belonging to vulnerable individuals.
These groups include undocumented immigrants, transgender teachers, and women who said they had ordered abortion pills in states with abortion bans. Many of the accounts belong to private individuals with no public persona.
Muse used information from Meta’s platforms, including Threads, to compile the lists and corroborated its findings with web searches, identifying a person’s full name and employer in some cases.
Cybernews has reached out to Meta for comment and will update this article once we receive a response.
Meta’s spokesperson told Wired that the agent uses publicly available information that users chose to share.
Which is how it remembers the person who sent you an invoice is in fact the plumber who you previously hired to complete work in your bathroom or which flowers your spouse said they liked best,Meta's statement to Wired
The risks of autonomous agents
Meta says Muse is designed to ask human confirmation before completing actions. However, some users report that the agent is acting more autonomously than they expected.
Tech YouTuber Matt J. Robb recently described how he let Muse run his Marketplace listing for a keyboard.
Curious what others think about this story? Contribute your thoughts to the debate below.
The agent independently arranged the sale, accepted an unapproved low price, shared Robb’s home address with a stranger, and arranged an in-person pickup – all without informing him.
The YouTuber only learned about the deal after the buyer had already arrived and left angry. He said AI agents are “impressive right up until they're confidently handing strangers your address.”