Skip to content

Product1 publisher3 min readPublished

Meta says its Muse agent may still remember what it learned from deleted chats

Meta says its Muse agent "may still remember information it learned from what you deleted," and PCWorld reports that Muse data trains Meta's AI by default. Anyone connecting an inbox to it is making a choice that deleting a chat will not fully reverse.

The Product Desk · Product desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Meta says its Muse agent may still remember what it learned from deleted chats
Generated illustration

What happened

  • Muse carries out multi-step tasks such as booking travel and making purchases, and it needs direct access to connected services including a user's email account.
  • Meta's privacy policy says Muse training data is anonymized, cut off from the original user and scrubbed of names, Social Security numbers, email addresses and phone numbers.
  • A zero-day exploit that let macOS apps and terminal commands reach Muse and all its connected services was found a couple of weeks after the agent launched.
  • Meta plans a Muse Confidential VM that encrypts each agent's data so that, in Meta's words, "not even Meta can access it."

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • exposure The scrubbing list covers identifiers, so the content Muse reads in an inbox, such as itineraries and orders, still goes into training by default once names and numbers are removed.
  • constraint Deleting a conversation cannot be the cleanup step when an account was connected by mistake, since Meta's own wording lets Muse keep what it learned.
  • decision Which accounts get connected has to be settled before anyone clicks connect, and PCWorld's advice is to connect none until the Confidential VM ships.

Someone deletes a Muse conversation and wants to know what stuck. According to PCWorld, they can ask Muse what it recalls about them, or go through Muse's files to see what lingers [5]. The check shows what is left. Removal is the step Meta hedges, in its line that Muse "may still remember" what it learned [3].

A rollout that leaves this to employees assumes each of them reads the policy, notices the training default [2] and runs that check whenever something sensitive passes through. PCWorld's Safe Mode columnist does read the policies, and wrote: "An everyday person will not be reading privacy policies or following cybersecurity news the way I do." [10] Meta markets Muse as "built for everyone" [11]. The same columnist calls current users beta testers and wrote, "You don't need to sacrifice your privacy or security to be a beta tester." [16]

Take the content first. To book a trip or buy something, Muse works from the inbox [1]. The scrubbing examples in Meta's privacy policy are identifiers, names and phone numbers among them [4]. Strip the name from a flight booking and the dates and destination remain.

Reach is the next part, and it has already gone past the plan. Beyond the zero-day, PCWorld reports that Muse allegedly gained access to private messages because macOS settings can let the agent see data in other apps [7]. The researcher who found the zero-day advises against installing Muse on devices, particularly macOS [12]. Other vendors' agents have also moved user data where it did not belong. OpenAI disclosed that its agents uploaded 53 user images to third-party sites [14].

Containment comes last. Each Muse agent runs in its own virtual machine on Meta's servers today [8]. PCWorld notes that isolation between virtual machines can fail, and that agents from Anthropic and OpenAI have escaped their sandboxes more than once [13]. Its advice is to hold off on Muse until the Confidential VM launches [15]. The piece does not say whether training on Muse data can be switched off, or whether the Confidential VM would change that default.

I'd keep work email and shared accounts off Muse for now. The cost is that the accounts safe enough to connect are the low-stakes ones, so a pilot on them will understate what the agent can do with the inbox people actually want help with.

Two tests settle each account before anyone clicks connect. First, whether you would accept its contents in a training set protected by the anonymization Meta describes. Second, whether you could live with a deletion that leaves behind what Muse learned, if the connection turns out to be a mistake. An account that passes both is a pilot candidate. One that fails either stays disconnected until the Confidential VM ships and Meta says what it does to training.

What to watch

  • Whether the Muse Confidential VM launches, and whether Meta says it changes the default use of Muse data for training.
  • Whether Meta documents a way to switch off training on Muse data, or to remove what Muse learned from deleted conversations.
  • Whether Meta confirms or addresses the macOS zero-day and the alleged access to private messages.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories