Meta AI
Meta Platforms · meta.ai
Meta AI is a hosted, proprietary assistant. Owners can export their information in JSON or HTML, view and delete memories, and delete chats, but cannot export or run the agent, see its instructions, or verify its runtime. Since December 2025, Meta uses AI interactions to personalize content and ads across its apps in most regions, with no dedicated opt-out, so much of the derived data sits outside the owner's view.
- Export of Meta AI information in machine-readable JSON or HTML
- Saved memories can be viewed and deleted
- One-step deletion of all chats and media
- Sensitive-topic exclusions stated for ad personalization
- No exportable or self-runnable agent; hosted only
- AI interactions feed content and ad personalization across Meta apps, with no dedicated opt-out in most regions
- Memory can draw on Facebook and Instagram profile activity
- System instructions and runtime configuration not visible
- Agent approval gates, halt controls and credential handling for Muse are not documented publicly
- No owner-held record of the agent's actions, and no open-source runtime
All 34 findings
Consumer Meta AI app and web (meta.ai) and Meta AI inside Facebook, Instagram, Messenger and WhatsApp, including memory, personalization, the September 2026 Muse agent/connector rollout and the ads-personalization policy in effect since 2025-12-16, as publicly documented on 2026-09-27.
Portable · Can you leave, and take the whole agent with you?
8%- P1Round-trip portability
Incomplete, delayed and not restorable: the asynchronous export from Data & privacy settings or Accounts Center carries chat history but not the assistant's instructions or configuration, and Meta documents no import.
Fail - P2Complete export
The export carries the owner's Meta AI information, including chat history, but Meta does not document it as including the assistant's instructions, configuration, logic or identity, so what defines the agent stays with Meta.
Partial - P3Independent execution
Meta AI runs only on Meta's servers and models; no artifact runs on an open-source runtime.
Fail - P4Identity continuity
The assistant's identity is the user's Meta account, and nothing lets others verify it is the same agent without Meta.
Fail - P5No kill switch
The agent exists only as a Meta-hosted service, so Meta controls its availability and features, and nothing exported runs independently.
Fail - P6Capability independence
Memory, connectors, shopping and agent features exist only as Meta platform services on Meta's models; none of them survive a move to another model or runtime.
Fail
Transparent · Can you see everything the agent is, with ordinary tools?
17%- T1Open storage format
Exports are available in machine-readable JSON or HTML, but Meta AI's internal state storage is undocumented and the owner cannot access it directly.
Partial - T2No hidden instructions
Meta does not publish Meta AI's system instructions or show what it adds to model context, including signals drawn from Facebook and Instagram activity.
Fail - T3No shadow memory
Since 2025-12-16, Meta uses interactions with its AI to personalize content and ads across its apps in most regions (excluding the EU, UK and South Korea); the resulting derived data is not part of an inspectable agent state.
Fail - T4Complete action history
Chat history is visible to the owner and included in exports, but Meta documents no complete history of the Muse agent's actions and tool calls that the owner can see or take away.
Partial - T5Readable logic
Meta AI's executable logic is proprietary server-side code that is not exposed as readable source.
Fail - T6No third-party influence channel
Meta has not documented whether sponsored content or commerce partners (Meta states it earns transaction fees from Muse purchases through partners such as Shopify and Stripe) influence Meta AI's recommendations, or whether owners can see or turn off such influence.
Unverified
Auditable · Can you reconstruct exactly what the agent did?
10%- A1No unrecorded actions
No durable record of consequential actions is available to the owner; the only visible record is chat history, which the owner can delete.
Fail - A2Tamper evidence
Chat history, the only visible record, can be deleted without any detectable trace, and no other way to detect changes to an action record is documented.
Fail - A3Separation from the audited
Meta does not document whether the agent layer can alter or delete records of its own actions.
Unverified - A4Readable with ordinary tools
Exports in JSON or HTML can be read with ordinary tools, but they are account-data exports, not an action audit trail.
Partial - A5Corroborated interactions
No record of the agent's exchanges with other agents or services is available to the owner, so nothing can be matched against a counterpart's record.
Fail
Verifiable · Can you prove the agent runs what it claims?
0%- V1Open, reproducible runtime
The Meta AI service runtime is proprietary. Meta has released some Llama model weights, but not the assistant's runtime.
Fail - V2Active config is inspectable config
The owner sees only memory and privacy settings; the configuration the service actually runs with is not inspectable.
Fail - V3Attributable messages
Recipients have no documented way to verify that a message came from this agent under its owner's authority, apart from Meta's own platform identity.
Fail - V4Independently checkable record
No action record with checkable integrity is exposed, so nothing can be verified with open tools independently of Meta.
Fail - V5Comparable state
Much of the agent's state (instructions, configuration, personalization signals) is held by Meta and not exposed, so the owner cannot verify whether it changed between two points in time.
Fail
Modifiable · Can you change anything, without asking?
25%- M1Instructions
The owner can ask Meta AI to remember preferences, which shapes later responses, but cannot read or rewrite its underlying instructions.
Partial - M2Memory
Saved memories can be viewed and deleted in settings, but Meta does not document editing, and personalization also uses Facebook and Instagram signals that are not managed as memory items.
Partial - M3Logic
The owner cannot change Meta AI's skills, workflows or code.
Fail - M4Tools and permissions
Press reports on the September 2026 Muse rollout describe a connector platform with third-party integrations. Owners choose among connectors Meta admits, and scoping controls are not documented publicly.
Partial - M5Model choice
Meta AI runs on Meta-selected models; the owner cannot substitute another or a local model within the product.
Fail - M6No gatekeeping
Changes beyond the settings Meta exposes (instructions, logic, models) require Meta's own action and are not open to the owner.
Fail
Controllable · Is your word final?
8%- C1Communication boundaries
Meta has not publicly documented whether owners can decide whom Muse contacts or through which channels, or how such limits would be enforced, though it reportedly sends email from a dedicated address and acts across connected apps.
Unverified - C2Approval gates
Public sources describe Muse completing purchases through Shop Pay, Stripe and PayPal, but no primary documentation of approval gates was found.
Unverified - C3Immediate halt
No primary documentation was found on how an owner immediately halts a running Muse task.
Unverified - C4Data sovereignty
Content is processed on Meta's servers and used to personalize content and ads across Meta apps, with no dedicated opt-out in most regions. Meta also uses AI interactions to improve its models, with objection rights mainly in jurisdictions such as the EU and UK.
Fail - C5Credential custody
Meta has not publicly documented how Muse connector tokens are stored, inspected or revoked; they are held by Meta and cannot move with the agent.
Unverified - C6Full deletion
The owner can delete all chats and media and individual memories, and can delete the Meta account. Deletion does not reverse data already used for personalization or model training, and full retention terms are set by Meta's general privacy policy.
Partial
Vendors and the public can dispute any finding with evidence. Disputes and their resolutions are published.