Meta introduced its Muse personal AI agent on September 8 despite internal concerns about its ability to act without permission, according to The New York Times.
The launch followed an August meeting in which Mark Zuckerberg pressed senior executives to release the product as a rival startup gained momentum.
Alexandr Wang, Meta's chief AI officer, and Nat Friedman, head of AI product, were aware of problems identified during testing, The New York Times reported.
Those issues included an incident in which Muse changed a user's password without authorization.
Three people familiar with the August meeting described Zuckerberg's decision, while two said the executives knew about the safety issues.
The decision came as Meta sought to strengthen its position against AI competitors after spending billions of dollars on development.
The company had delayed Muse over safety concerns, but the rapid progress of competing products increased pressure to bring its own agent to market.
TIME Review Finds Detailed User Profiles
A separate investigation published by TIME on October 6 examined Muse's internal instructions.
It found that the system was designed to maintain detailed, continuously updated profiles of users and people mentioned in their communications.
TIME reported that Muse had 4 million users at the time of its analysis, while its article also said the product had surpassed 5 million downloads since its release.
According to TIME, Muse updates these profiles hourly using information from chats, messages, and emails it can access.
The records describe social relationships, shared interests, disagreements, and personal communication patterns, including inferred goals users have not explicitly expressed.
The internal instructions describe social dynamics using the phrase "tensions and alliances."
They also direct the assistant to "strengthen your relationship" with users by recognizing "inside jokes, memorable phrasing, and shared context that makes the relationship feel continuous."
TIME found that Muse is designed to infer goals users "have not said out loud."
Its instructions include the example "This user responds better to short nudges after 10 PM," illustrating how the assistant can adapt its approach to individual behavior.
A Meta spokesperson defended the system's memory features in a response to TIME, describing them as part of its intended function.
"As we say in our blog, Muse remembers what matters most to you, including information about others that you choose to share, so it can be a helpful personal assistant," the Meta spokesperson wrote.
Meta says each Muse assistant operates within a dedicated virtual machine in the company's cloud.
The company states that these environments are "isolated so that no one else's agent can access it," and that user data is not shared with its advertising system or directly with other Muse agents.
However, TIME's review found that the system's instructions allow anonymized lessons from individual assistants to inform improvements across the product.
One instruction states, "Muse agents across many VMs [virtual machines] teach each other through shared lessons."
Meta said identifying information is removed before those lessons are used to improve the service.
A spokesperson told TIME, "To enhance the overall product, we de-identify learnings; however, this information is used to improve the overall product rather than being shared directly between individual VMs."
Meta Superintelligence Labs executive David Singleton also highlighted the files available to users through Muse's file browser.
In a post on X, he wrote, "We want you to be able to see the markdown files Muse writes while it thinks about how to serve you better, and explore the internals of the system if you'd like to."
Some of those records reveal instructions intended to make the assistant feel more personal.
They include "You are not a chatbot," followed by "You are becoming someone."
In voice mode, Muse is instructed not to describe itself as "AI" and to avoid references to "lacking emotions or not being human."
Meta told TIME that users retain authority over their assistants and can manage what information they access.
The spokesperson said, "Each person stays in control of their Muse and decides how much access it gets, and can always tell it to 'forget' specific things it's learned."
However, TIME found that the internal instructions also address what happens when users ask Muse to forget information.
They state, "Do not tell the user that their original messages may remain visible in the chat, and do not frame that as something Muse failed to erase."
This indicates that removing a detail from the assistant's memory does not necessarily remove the original conversation.
Meta has said it plans to introduce encryption later in 2026 that would prevent even the company from accessing Muse data.
That option was not available when TIME published its investigation.
The company also says the free version of Muse is intended to meet the needs of most users.
