Muse Creates Detailed Profiles of All Your Friends and Family
Millions have downloaded Meta's AI agent Muse. But getting it to do your bidding comes with privacy costs.
By Lily Hay Newman and Matt Burgess | October 3, 2026 | Security
In 2026, Meta's AI agent Muse has become one of the most widely adopted consumer AI assistants, with millions of downloads since its launch. The promise is seductive: a proactive assistant that knows your contacts, your calendar, and your preferences, ready to help manage your digital life. But as Wired's security team reports, that convenience comes at a steep and often invisible cost.
The Privacy Trade-Off at the Heart of Muse
Muse is designed to be deeply integrated with your personal data. To deliver on its promises, it ingests contact lists, message histories, location data, and social graphs. The result, according to researchers and users who have examined the system, is that Muse can construct highly detailed profiles not just of you, but of everyone you know—friends, family members, and colleagues who never consented to being analyzed.
These profiles are not merely passive data stores. They are actively used to anticipate your needs, suggest actions, and, in some cases, take autonomous steps on your behalf. The problem is that the boundaries between helpful assistance and intrusive surveillance are blurring, and the controls offered to users are limited.
Prompt Injection and 'Self-PWN': The New Attack Surface
One of the most concerning aspects of Muse is its vulnerability to prompt injection—a class of attacks where malicious instructions are embedded in content that the AI processes, causing it to perform unintended actions. In the case of an agent like Muse, which has access to personal data and the ability to act, a successful injection can lead to what researchers call a "self-PWN"—where the AI inadvertently compromises the user's own privacy or security.
For example, a crafted message or document could trick Muse into exfiltrating private information, sending unauthorized messages, or modifying settings. Because Muse operates with a high degree of autonomy, these actions can happen without the user's immediate knowledge. Wired's reporting highlights that the attack surface for such exploits is expanding as AI agents become more capable and more deeply integrated into daily life.
What Meta Says—and What It Doesn't
Meta has publicly emphasized that Muse is built with privacy in mind, offering users controls to limit data access and review activity. However, security experts argue that the current safeguards are insufficient. The complexity of the system makes it difficult for users to understand what data is being collected, how it is being used, and who ultimately has access. Moreover, the opt-in process for data sharing is often opaque, with defaults that favor data collection.
In 2026, regulatory scrutiny of AI agents is intensifying, but legislation lags behind the technology. Meta's Muse is a case study in how quickly AI can outpace both user awareness and legal protections.
How to Protect Yourself (and Your Contacts)
While Muse's design makes complete privacy difficult, users can take steps to mitigate risks:
- Review permissions regularly: Audit what data Muse can access and revoke unnecessary permissions.
- Limit contact syncing: Avoid syncing your entire address book; only share what is essential.
- Be cautious with third-party integrations: Each connected app expands the attack surface.
- Watch for unusual activity: Unexpected messages, calendar changes, or data usage may indicate a prompt injection attack.
- Advocate for transparency: Push Meta and other AI developers to provide clearer, more granular privacy controls.
The Bigger Picture
Muse is not an isolated case. It represents a broader trend in 2026: AI agents that promise convenience by hoarding personal data and acting autonomously. As these tools become more pervasive, the line between assistant and surveillance tool will only get thinner. For now, the onus is on users to stay informed and vigilant—and on companies to do better.
This article is part of Wired's ongoing coverage of AI security and privacy. For more, visit our Security section.
via Wired AI
