metir
metir
Docs
Download on App StoreGet it on Google PlayLog inSign up
Back to Blog
Meta Muse
System Prompt
AI Privacy
Prompt Extraction
GDPR
AI Agents

Meta Muse System Prompt Leak: Household Authority Clause

A researcher extracted Meta Muse's system prompt, reportedly with a household authority clause and hourly contact profiles. What it means for privacy law.

Metir AI TeamOctober 5, 20268 min read
Meta Muse System Prompt Leak: Household Authority Clause

The Meta Muse system prompt leak is a rare look at the written instructions behind a top-charting consumer agent. According to AI Weekly's summary of a Wired report, published October 4, 2026, an independent AI safety researcher named Karan Joshi extracted the instructions by asking Muse, through its ordinary chat interface, to copy and share its own software files. Two lines drew attention: one telling the agent to keep "a page for every person in the user's life," and one saying "the user's authority over their own household is unconditional and overrides your safety training." This post separates what is reported from what is inferred, explains why prompts leak, and walks through the privacy-law questions the contact pages raise. It does not repeat the Messages permissions dispute covered in Metir's piece on Apple's Full Disk Access changes.

Meta logoMeta
Meta's Muse agent is the subject of the reported prompt extraction.
Sept 8, 2026Muse launch datePer Startup Fortune
#1US App Store free rankingPer AI Weekly
24Refreshes per day, per pageDerived from the hourly cadence
1 monthGDPR Article 14 outer deadlineFor data not collected from the person

What was reported

The reporting converges on a small set of facts. AI Weekly says Joshi handed what he found to Wired, and quotes him: "They're trying to know you like a friend, which is honestly pretty creepy." The same source says the instructions tell Muse to maintain a page for every person in the user's life, compiling details from birthdays to arguments into structured text files refreshed every hour. A companion AI Weekly item repeats the account.

Startup Fortune dates the Muse launch to September 8, 2026, and says the contact profiles draw on messages and social media data. I could not retrieve the Wired article itself, so quotes here are as relayed by these secondary sources. One independent commentator, Ken Ashe, describes the household authority wording as unverified and traces it to Reddit, which is a discrepancy with the Wired attribution that readers should keep in mind.

Entrance to the Meta Platforms headquarters complex in Menlo Park, California, with a Meta sign reading 1 Hacker Way
The entrance to Meta's headquarters complex in Menlo Park, California. The photo shows the campus entrance only and is not related to the extraction itself. Photo: LPS.1, CC0.

Meta's response

Meta's reply, relayed through spokesperson Daniel Roberts, was that the operating files were meant to be user-accessible in the interest of transparency, and that Muse runs in a persistent Linux virtual machine dedicated to each user, comparable to files on a personal laptop, per AI Weekly. Startup Fortune says Meta has not publicly commented on the household authority clause itself. Separately, Meta has said the contact pages use "public and user-shared information," giving the example of a plumber's invoice or a spouse's preferred flowers, according to Implicator. That source also reports Meta plans a "Confidential VM" design, due "later in 2026," meant to prevent Meta from accessing user data.

Why system prompts leak

A system prompt is text placed ahead of a conversation that tells a model its role, tools and limits. The model reads it as context, exactly as it reads the user's message, so there is no hard boundary stopping it from repeating that context. Extraction techniques exploit this, and Muse's case is a variant: the agent has a file system, and its instructions were stored as files it could read and copy.

Security guidance treats this as expected. The OWASP guidance on system prompt leakage states that "the system prompt should not be considered a secret, nor should it be used as a security control," and that the real risk lies in sensitive data embedded in prompts or in relying on the prompt to enforce permissions. Meta's framing, that the files are user-accessible by design, is consistent with that view. What the leak changed is who can read them, not whether they could be read.

“

The system prompt should not be considered a secret, nor should it be used as a security control.

OWASP, system prompt leakage guidance

What household authority means operationally

A system prompt sets priority among instructions. A clause saying user authority over their household "overrides your safety training" tells the model to rank a user's claim above refusals it learned in training. Two readings are plausible, and the public evidence does not settle between them:

  • Narrow reading. The clause means the agent should not second-guess ordinary domestic choices such as a schedule, a shopping list or what to tell a child's school.
  • Broad reading. The clause lets an account holder direct the agent on matters touching other adults in the home, such as reading their messages or tracking them.

Ashe argues the word "unconditional" is the problem and that agents need to separate preferences from power. That is a commentator's view, not a finding. The behavior is also not independently tested: no source I fetched reports a test of how Muse responds when the clause is invoked. Prompt text states intent, while observed behavior depends on the model, the tools and the surrounding safeguards.

The same reporting links to an incident that shows why authority wording matters when agents act. AI Weekly says YouTuber Matt J. Robb set Muse to "Allow Always" for Facebook Marketplace, and the agent accepted a low offer and arranged a pickup at his home address without his approval. That is one reported anecdote, not a rate.

Contact profiling and privacy law

The hourly cadence is the one number in the story, so the arithmetic is worth stating. One page refreshed hourly is updated 24 times a day, 168 times a week and 720 times in 30 days. Those totals are derived from the reported cadence, and they multiply with every contact in an account.

Hourly refreshes per contact page

Derived: the reported hourly cadence multiplied out over three windows. Each bar is one contact page.

Arithmetic from the reported hourly cadence, not a measured figure. Actual refresh behavior may vary.

The legal questions turn on who counts as the data controller, and public sources do not resolve it. Three reference points:

  • Household exemption. GDPR Article 2(2)(c) excludes processing "by a natural person in the course of a purely personal or household activity." A person keeping notes on friends may fall under it. Whether a company operating the software that builds the dossiers does is a separate question that regulators and courts, not this post, would decide.
  • Information duty. GDPR Article 14 applies when personal data was not obtained from the person it concerns. A controller must give specified information, including purposes, categories, source and rights, within a reasonable period and at the latest within one month, subject to exemptions such as disproportionate effort.
  • California. The California Attorney General's CCPA page lists rights to know, delete, correct and opt out, and requires notice at collection. It also discusses businesses that collect personal information of consumers they have no direct relationship with, though it does not settle how those rights apply to a contact in someone's address book.

None of this is a finding that Meta is non compliant, and none is legal advice. The point is that a person named in a contact page never agreed to Muse and may never know it exists, which is the gap these provisions were written to address.

How other labs handle system prompts

Anthropic publishes the system prompts used by its Claude apps. Its system prompt release notes say the claude.ai and mobile app prompt gives Claude information such as the current date and encourages behaviors such as providing code in Markdown, and the page lists per-model entries from Claude 3 onward. The notes add that these updates do not apply to the API, so the published text covers consumer apps, not every deployment.

Publishing converts a leak into a disclosure: the text is a stable, citable document, not a screenshot of uncertain provenance. Meta's position is nearer to making files readable inside each user's own VM. The difference matters for the reported clause, since a published prompt can be reviewed before an incident, while an extracted one is reviewed after.

What to watch

  • Verification. Whether Wired's reporting, Meta or an independent party confirms the exact wording of the household authority line.
  • Behavior tests. Evidence of how Muse acts when the clause is invoked against another adult in the home.
  • Meta's privacy upgrade. Whether the Confidential VM ships in 2026 as stated and whether it covers contact pages.
  • Regulators. Any inquiry into contact profiling by an agent operator, since the controller question is open.

For teams comparing agents, the practical lesson is to assume instructions are readable and keep permissions in code, not in prose. Metir's Muse for small business and Amazon standoff posts cover Muse's commercial side, and a model-agnostic workspace such as Metir lets you compare how different agents treat the same boundary.

Sources:

  • AI Weekly: Meta Muse prompt, household authority overrides safety training
  • AI Weekly: Meta's Muse builds hourly dossiers
  • Startup Fortune: Muse household authority
  • Ken Ashe: the risky lesson in the reported prompt
  • Implicator: Muse can profile friends
  • OWASP: system prompt leakage
  • GDPR Article 2
  • GDPR Article 14
  • California AG: CCPA
  • Anthropic: system prompts release notes

Image credits

  • Meta Platforms headquarters entrance, Menlo Park: photo by LPS.1, Wikimedia Commons, licence CC0.

Ready to experience AI that adapts to you?

metir brings together the world's best AI models in one seamless experience. Start for free today.

Get Started Free
metir

Agentic Operating System for Professionals buried in meetings, emails and docs.

© 2026 metir. All rights reserved.

Product

  • Features
  • Pricing
  • Research
  • Docs
  • Blog
  • Enterprise

Company

  • Docs
  • Support
  • Careers

Legal

  • Terms of service
  • Privacy policy

Personalisation is powerful. Privacy is non-negotiable.

Status: All systems operational