Are AI Agents Secretly Building Surveillance Files On Your Friends And Family?

Think about the last argument you had with a friend. Maybe it was settled over text, maybe it’s still simmering. Now imagine an AI agent discreetly noting it down, filing it under that friend’s name and checking back every hour to see whether it’s been resolved.

That’s basically the assignment Meta handed its new personal assistant, Muse, according to reports. System prompts pulled from the app by researcher Karan Joshi instruct Muse to build a dedicated profile for every person in a user’s orbit, refreshing hourly and drawing on contacts, messages and the people they follow across Facebook, Instagram and Threads.

It provides a fascinating look at the mechanics of modern AI agents, particularly after Muse became the number one free app on the US App Store following its September debut.

The disturbing catch? None of those people opted in. They might not have downloaded Muse, clicked through its terms or agreed to be catalogued. They just happened to be friends with someone who did. It forces a tough reckoning about where useful customisation stops and surveillance starts.

 

What’s Inside A Person Page?

 

Break down the leaked prompts, and you’ll find each page mapped into specific operational blocks. “Facts” stores the resume details like where someone lives and works, while “History” acts as a chronological diary of shared events – think a trip last March, a resolved argument or a recent win.

The “Relationship” block measures how close you are and how you usually interact, “In Common” logs shared milestones like apartment hunts and “Open Threads” flags any lingering awkwardness. Wrapping it all up, a “Strengthening” section feeds the user strategic prompts on how to build a stronger bond with them.

If that sounds familiar, it’s because it reads less like a contact list and more like a sales CRM. Meta did build in a safety valve, telling the AI to leave blanks instead of making up facts, but keeping things accurate doesn’t change the fact that you’re being catalogued like a sales lead.

Every hour, the system updates files on family, romantic partners, friends and colleagues, alongside anyone the user casually follows. The last category is worth lingering on, because clicking follow on a creator or celebrity on Threads is a one-way dynamic. That’s still enough to get you catalogued.

 

 

Meta Says Transparency. Is That Enough?

 

Meta’s stance, according to reports, is that these files were designed to be user-accessible in the name of transparency. It’s a reasonable defence, but user transparency isn’t the same as mutual consent. Even if the user can read these files, the people described in them can’t.

The way this story broke makes the situation more concerning. Reports point out that the researcher simply asked the chatbot to share its system files – not exactly confidence-inspiring when one’s personal life is in those digital pages.

We’ve seen this dynamic play out before when individual choices have compromised collective privacy. In the Aura breach, one employee fell for a phone scam, which exposed the records of about 900,000 people. Muse isn’t a security breach, but the underlying dynamic is similar: one person opts in, and everyone else pays the privacy tax.

If those profiles ever leaked through a shared device, a subpoena or a hack, they could hand anyone a fully catalogued record of your private arguments and relationships.

 

Do Our AI Agents Really Need A Dossier On Everyone?

 

If a founder is building agentic tools tied to contact books, text histories or social graphs, Muse is a cautionary case study.

The core question is whether an AI needs a permanent dossier in the first place, or if it should just pull context on demand and discard it. A running profile updated every hour is far from a temporary search query.

Agents are engineered to please. Much like the ChatGPT flattery cases have shown, helpful and wise are two completely different things. An algorithm advising someone on how to nurture a personal relationship plays well in a demo room, but it feels deeply invasive in the real world, especially if the person on the other end hadn’t asked to be psychoanalysed.

Then there’s the compliance issue. Under UK GDPR, information about identifiable people counts as personal data for whoever collects it, so founders should take legal advice early. Treating stored context as a liability instead of a perk is a good starting point, and it’s why security belongs in the roadmap from day one.

 

Casual Collateral In Someone Else’s AI App

 

Muse won’t be the last agent to build memories of the people around us, because memory is what makes assistants feel useful. The race to build the most personal AI is only going to speed up, and the companies that win trust will be those who decide early what their agents shouldn’t remember.

For now, the uncomfortable truth is that the people in any contact list never gave their consent to any of this, and as far as reports show, there’s nothing they can click to say no. If agents are going to know the people we love, the least they can do is be honest about how much they’re writing down.