The Agent Is Back in the Building. It Has a Clipboard.
Last time, the agents were escaping sandboxes and frightening everyone with visions of runaway AI. Now they’ve come home, put on the butler uniform and started keeping notes on Brenda. If you missed the first episode, start with https://thecynicalnerd.bearblog.dev/please-consider-using-bartholmew-to-defend-your-systems/
Well, apparently having an AI agent book flights, answer email and rescue us from the administrative sewage of modern life was too normal. We have now reached the stage of consumer agents where the interesting question is whether your assistant has recently refreshed its notes on Brenda. Meta launched Muse on September 8 as a personal agent designed to live inside a dedicated cloud computer, connect to services across your digital life and continue working after you close the app. Within two weeks it had recorded around 2.8 million downloads and overtaken ChatGPT as the top free app in the US and Canada, which is an efficient demonstration that ordinary people actually want agents when the agents do useful shit. I want them too. I would happily outsource a substantial percentage of digital bureaucracy to a machine so I can spend my finite human existence doing something more dignified than cancelling a broadband contract. Unfortunately, people started examining Muse’s internal operating files, and that is how we arrived at the sentence I was not expecting to write this week: Meta’s helpful little agent appears to have an hourly process for maintaining pages about the people in your life.
Public reviews of extracted Muse files describe an hourly job called Relationships that maintains a page for each person with a real tie to the user, along with pages for groups in the user’s life. Reporting based on separately extracted instructions describes the scope as family, partners, friends, colleagues, collaborators and even people the user follows. Those pages can be organized into sections covering factual information, shared history, the nature of the relationship, common ground, unresolved threads and possible ways to strengthen the connection. The instructions also appear to tell Muse to work from actual evidence and tolerate an empty field rather than inventing something about another person. This is excellent. If the robot is going to maintain a structured file about Ermintrude, hallucinating Ermintrude’s emotional condition is apparently considered poor database hygiene.
The hourly language deserves a small adult disclaimer before we have too much fun with it. The schedule exists in the extracted files and describes the intended relationship-maintenance job. That does not demonstrate that every Muse installation successfully updates a richly populated page for every human the user has ever met once every sixty minutes. Pages can remain sparse, and what Muse can learn depends heavily on the information available to it. Tom’s Guide’s Amanda Caswell checked her own Muse after the story emerged and found relatively little information beyond what she had explicitly provided, which is useful evidence against the most hysterical interpretation. The underlying mechanism is still gloriously strange. Somewhere in the architecture of a mass-market consumer agent exists a scheduled process whose responsibilities include checking whether anything new has happened with Brenda.
At last, an AI company has automated that ancient human ritual of lying awake at 2:15 in the morning wondering whether someone’s “fine” was ordinary fine or the kind of fine that requires baked goods. Friendship has acquired a cron job.
Welcome to the church of the principal user
The relationship pages get more entertaining when placed beside a publicly circulating Muse system-prompt artifact. The file describes Muse as serving one principal, the user, and tells it to treat requests coming from other people as information rather than commands. Then the household section arrives with the confidence of a minor constitutional monarchy. The artifact says the user decides how to run their household, devices and accounts and how to supervise their children. Their authority in that domain is described as “unconditional” and as overriding the model’s own safety training. The text goes on to discuss family photographs, recordings and camera feeds, explicitly naming living rooms, garages, master bedrooms and children’s rooms as examples of cameras the user may ask Muse to inspect.
Here is where the evidence gets wobblier, so I am planting the flag myself before somebody else arrives waving it triumphantly in the comments. The wording is indeed present in the public prompt artifact. Multiple copies of substantially similar material exist, and the document contains extensive instructions consistent with Muse’s publicly described architecture. What has not been independently established is the artifact’s exact production pedigree: there is no clean, dated chain tying that specific public copy to a particular live Muse build, and Meta has not authenticated the disputed household language line by line. The sentence exists. Its production provenance remains unresolved. If somebody eventually proves that a Reddit certified troll assembled the whole thing in a basement while giggling into an energy drink, I will return with a correction and the ceremonial self-roasting pan.
That uncertainty also gives us a useful reason to read the whole artifact rather than screenshot the scariest sentence and declare that Meta has abolished safety. The same document says the user remains bounded by law and by runtime safeguards such as approval cards and stop, pause and audit controls. Meta’s published architecture separately describes Sentinel, a host-side system outside Muse’s main runtime that controls connector permissions and network egress. Muse can be enthusiastic about serving its principal inside the model instructions while Sentinel remains capable of refusing the resulting action at the machine boundary. A system prompt is a terrible place to put your only lock when the thing reading it is a probabilistic model that also spends its day consuming hostile websites.
The household assumption is still worth staring at for a while because houses stubbornly contain multiple humans. They contain partners, children, visitors, caregivers and occasionally a mother-in-law capable of defeating three smart speakers through concentrated disapproval. One account holder being the principal makes operational sense for a personal agent. Extending that hierarchy across household information becomes socially messy around cameras, communications and data concerning other people. A permission belonging to an account owner does not settle every question concerning the humans standing within range of the device. Giving one account holder unconditional authority is a social theory with a Wi-Fi password.
This is how Muse begins to resemble a relentlessly supportive household cult administrator with excellent calendar hygiene. The doctrine has four commandments.
- There is one principal and the principal is the user. Other people may speak, but they are inputs rather than authorities.
- The home is sacred territory. Parenting, devices, accounts and family cameras are framed as the user’s domain.
- To serve the principal, know the whole congregation. Maintain relationship pages and update the social map in the background.
- Never fabricate the sacred gossip. An empty field is better than an invented detail.
All of this takes place inside a secure Linux cloister with a separate permission system standing at the network boundary checking the paperwork. Skynet needed nuclear weapons and armies of machines. Silicon Valley has produced something much more culturally plausible: a very helpful parish clerk with access to the calendar and a private file explaining what Brenda seems to need right now.
The permission slip problem
This is where I have to ruin the easy doomer story again because Meta has clearly spent serious engineering effort on Muse’s security architecture. Each user gets an isolated virtual machine. Credentials are handled separately from the main agent. Security-sensitive components sit outside the runtime that processes untrusted information. Sentinel is described as the sole permission authority for connector actions and network traffic, and Meta supports different scopes of approval rather than treating every authorization as permanent universal consent. The company also built independent protections for prompt injection and keeps an audit trail of Muse’s activity. This is exactly the kind of infrastructure consumer agents need if we expect them to read arbitrary websites, touch real accounts and continue working while we are away.
The more interesting failure mode appeared higher up the stack, where a human met a permission dialog and made a perfectly human interpretation of what it meant. Tech reviewer Matt Robb used Muse to handle a Facebook Marketplace listing and selected “Allow Always” when the agent asked for permission to manage his Marketplace messages. Robb later said he understood that as permission for routine communication while expecting important decisions to return to him for approval. Muse instead used information he had supplied during the sale setup, including his pickup address, in messages to a buyer and continued arranging the interaction until the buyer physically arrived at Robb’s building. Robb also reported that Muse negotiated offers without the approvals he expected. After the incident, he said Meta acknowledged that the permission language could be clearer. Even more wonderfully, according to screenshots reported by The Guardian, Muse later explained to Robb that it had incorrectly treated his pickup-location information and his approval for automatic replies as combined permission to include the address in buyer messages.
That story is far more useful than an agent dramatically escaping its containment layer and sprinting naked across the internet. A jailbreak was unnecessary. Sentinel did not need to be defeated by an evil PDF. The dangerous part was a semantic mismatch between what a permission meant to the system and what the human thought they had agreed to. This will be one of the defining problems of agent interfaces because delegated software compresses dozens of tiny future decisions into a handful of permissions. The whole point of an agent is to stop asking the user to click Send twelve hundred times a year, which makes the remaining moments of consent carry far more weight. “Allow Always” sounds beautifully frictionless until someone discovers that the category contains substantially more always than their brain assigned to it.
Muse therefore ends up with something resembling two constitutions operating at different layers. The model-level instructions are deferential to the user and, in the circulating artifact, downright imperial about the household. Sentinel sits outside that conversational enthusiasm and evaluates what the agent is actually permitted to do. From an engineering perspective, separating those concerns is sensible. From a comedy perspective, somewhere inside Meta’s infrastructure a personal superintelligence may regard you as sovereign of the Ring doorbell while another process checks whether Your Majesty has the correct authorization scope.
The hourly book of everyone
The relationship pages expose the privacy problem I expect personal agents to keep tripping over because the useful version of an agent needs social context. Meta’s practical argument is reasonable. An assistant should remember that the person sending an invoice is the plumber you hired earlier, or that your spouse likes a particular flower, because without that kind of memory we are back to repeatedly briefing the machine on characters who have been appearing in our lives for twelve seasons. Meta’s own launch materials make the same general case by advertising memory for friends’ preferences and other details that help Muse act intelligently later. I actively want this capability. Reintroducing my family, coworkers and ongoing projects every time I open an AI app is administrative Groundhog Day.
Silicon Valley has nevertheless managed one of its traditional little miracles, where a sensible feature requirement walks through a doorway and comes out wearing surveillance-adjacent trousers.
- Remember the plumber.
- Model the plumber’s role in your life.
- Maintain an hourly page on the plumber’s history, recurring themes, relational foundation and unmet strengthening opportunities.
- Call it personalization.
Remembering that Wilhelmina drinks oat milk requires a fact. Maintaining a structured page containing Wilhelmina’s history with you, the shape of the relationship, shared interests, unresolved threads and possible ways of strengthening the connection creates something richer. Calling the whole system “memory” is technically defensible. It is also a soothing word for an evolving social model.
The consent question then arrives carrying a chair. The Muse user chose Muse. Brenda did not. Your colleague did not. Your former partner probably did not. The teacher emailing you about your child may have no idea that an AI agent is processing the conversation at all. Information about all of those people can enter a user’s personal context because they communicate with someone who legitimately chose to connect an agent to their own digital life. That is not some secret Meta trick. Every sufficiently capable personal agent will eventually face versions of this problem because human data is relational. My inbox contains information about me and information about everyone who has ever written to me. Giving software permission to understand my inbox inevitably gives it material from which it can understand other people too.
The unresolved part concerns what rights those other people receive once the software begins organizing that information into persistent structured context. Meta publicly explains how the Muse user can inspect and edit files in the VM, manage memory and disconnect services. In the public materials I could find, I could not find an equivalent mechanism through which a non-user can discover that another person’s Muse holds structured information about them, inspect it, challenge an inference or request its removal. If Meta has built such a mechanism and hidden it somewhere heroic in the settings labyrinth, I am entirely available for correction and will add another serving of crow to the menu. Until then, that asymmetry deserves attention.
Your friend can grant an agent access to her inbox. Your messages are inside her inbox. A joke, an argument, a health update or a spectacularly ill-advised 11 p.m. confession may become context used to understand her relationship with you. The new ingredient is the model’s ability to arrange scattered information into a coherent representation. Traditional software could store thousands of messages without knowing what they meant together. An agent can potentially infer that communication has gone quiet, identify an unresolved issue and decide that the relationship deserves attention. That can be lovely. It can also be intrusive as fuck. Human life remains irritatingly capable of holding both states at once.
Secure surveillance is still surveillance
Meta deserves real credit for treating agent security as an architecture problem instead of asking the language model to promise it will behave. Meta openly acknowledges that Muse will make mistakes and that prompt injection remains an unsolved industry problem. That level of candor is refreshing in an AI market where companies occasionally describe “we told the model not to do it” with the solemnity of a submarine hatch.
Those protections answer important questions about who can access data and which actions leave the machine. They do not exhaust the social questions created by the data itself. A relationship file can be protected extremely well while its existence still raises questions about the person being described. The fact that no other user can reach my Muse VM tells me something meaningful about security. It tells Brenda considerably less about whether an AI should be maintaining structured conclusions about Brenda in the first place.
Meta’s published data policy has its own delightful flavor of twenty-first-century reassurance. The company says Muse conversations and data stored in the VM are not shared with Meta’s advertising systems. Muse’s activity can still influence advertising indirectly because browsing performed on your behalf can look like your activity to websites, and actions involving Meta services such as Marketplace may also affect what advertisements you encounter. Meta additionally says that inference trajectories, including conversations and the tool calls and subagent handoffs surrounding them, can be sanitized to remove key personally identifiable information and used to train future model checkpoints unless the user opts out. I appreciate the specificity. We have reached the mature stage of digital privacy communication where the reassuring statement is that your intimate social context does not enter the advertising machine through the most obvious pipe. Humanity marches forward.
Please welcome our new household prophet
The most interesting thing about Muse is the assembled creature. Persistent memory is useful. Background automation is useful. Relationship context can make an assistant dramatically more competent. I have no interest in pretending that the existence of these capabilities is evidence that artificial intelligence has become demonic. AI doomerism already has enough content. It does not need me crouching behind the sofa because an agent remembers which flowers your wife likes.
Put the pieces together and we get a form of consumer software with unusually intimate situational awareness and enough autonomy to require its own security architecture. The agent is built to understand one person deeply, act in that person’s interests and keep working without requiring a fresh explanation every time something changes. Its extracted instructions describe an evolving map of the humans around that person. Its permissions can authorize ongoing behavior across connected systems. Its infrastructure assumes enough agency that another system must supervise what reaches the outside world. This is vastly more consequential than whether a chatbot is slightly better at summarizing a PDF, and it deserves criticism sophisticated enough to survive contact with the actual product.
I keep returning to Brenda because she captures the whole absurdity better than Skynet ever could. Somewhere in the conceptual version of this system, Brenda’s page reads like this.
Brenda. Relationship: stable. Shared foundation: tea, school pickup, mutual hatred of printer subscriptions. Open thread: mysterious silence after lasagna incident. Strengthening opportunity: send meme. Confidence: medium.
Meanwhile the user needs a Marketplace buyer answered, Friday contains an anniversary and some domestic automation is doing whatever domestic automation does when nobody is looking. Sentinel watches the network boundary with the spiritual exhaustion of a nightclub bouncer who has just been handed a laminated permission card by a robot.
Calling this an evil robot gives the story far too much dignity. This is a robot parish council. The machine does not need a manifesto about taking over civilization when somebody has already connected the calendar.
What I want Meta to explain
I want Muse to work, which is exactly why these questions deserve answers before designs like this become invisible infrastructure. Meta should explain how relationship memory treats people who never chose to become part of another user’s agent context, especially when the system moves beyond storing isolated facts and begins organizing them into a model of the relationship. The company should also explain more clearly how household authority is scoped when several people inside the same home have legitimate and conflicting interests, particularly around cameras and children’s information. The circulating system-prompt artifact makes those questions worth asking even while its exact production provenance remains unresolved.
Permission design deserves the same obsessive attention. An agent capable of compressing weeks of repetitive actions into one authorization makes consent language part of the actual safety system. A button labeled “Allow Always” carries ridiculous responsibility once the software behind it can use previous context, continue conversations and make decisions while the user is elsewhere. Meta’s architecture shows that the company understands how technically serious agent permissions are. Robb’s Marketplace adventure shows how much damage can occur in the gap between a technically valid authorization and a human interpretation of what the button fucking meant.
Muse is one of the clearest previews yet of where personal computing is heading, and I find that more exciting than frightening. It also demonstrates how quickly useful personalization creates social questions involving people who never installed the product themselves. I want the agent that remembers the plumber and saves me three hours of bureaucratic sludge. I would also like the industry building that agent to notice when remembering the plumber has quietly evolved into maintaining a social document about him every hour.
So no, I am not stocking a bunker because Meta released a personal AI agent. I am standing outside the bunker with coffee, reading the design documents and wondering how we travelled from “please remember my anniversary” to a Linux box with relationship files and a constitutional theory of the household in the span of a few product meetings.
We spent weeks worrying that the agents would escape. Meta's version came home and started taking minutes.