Skip to content
Agents for Humanity
Public draft. All results are preliminary desk assessments against criteria v1.0, updated 27 Sept 2026. No agent has been certified yet. How we assess
AssistanthostedProprietary

Meta AI

Meta Platforms · meta.ai

Meta AI is a hosted, proprietary assistant. Owners can export their information in JSON or HTML, view and delete memories, and delete chats, but cannot export or run the agent, see its instructions, or verify its runtime. Since December 2025, Meta uses AI interactions to personalize content and ads across its apps in most regions, with no dedicated opt-out, so much of the derived data sits outside the owner's view.

Strengths
  • Export of Meta AI information in machine-readable JSON or HTML
  • Saved memories can be viewed and deleted
  • One-step deletion of all chats and media
  • Sensitive-topic exclusions stated for ad personalization
Gaps
  • No exportable or self-runnable agent; hosted only
  • AI interactions feed content and ad personalization across Meta apps, with no dedicated opt-out in most regions
  • Memory can draw on Facebook and Instagram profile activity
  • System instructions and runtime configuration not visible
  • Agent approval gates, halt controls and credential handling for Muse are not documented publicly
  • No owner-held record of the agent's actions, and no open-source runtime
Evidence

All 34 findings

Consumer Meta AI app and web (meta.ai) and Meta AI inside Facebook, Instagram, Messenger and WhatsApp, including memory, personalization, the September 2026 Muse agent/connector rollout and the ads-personalization policy in effect since 2025-12-16, as publicly documented on 2026-09-27.

Portable · Can you leave, and take the whole agent with you?

8%
  • P1
    Round-trip portability

    Incomplete, delayed and not restorable: the asynchronous export from Data & privacy settings or Accounts Center carries chat history but not the assistant's instructions or configuration, and Meta documents no import.

    Fail
  • P2
    Complete export

    The export carries the owner's Meta AI information, including chat history, but Meta does not document it as including the assistant's instructions, configuration, logic or identity, so what defines the agent stays with Meta.

    Partial
  • P3
    Independent execution

    Meta AI runs only on Meta's servers and models; no artifact runs on an open-source runtime.

    Fail
  • P4
    Identity continuity

    The assistant's identity is the user's Meta account, and nothing lets others verify it is the same agent without Meta.

    Fail
  • P5
    No kill switch

    The agent exists only as a Meta-hosted service, so Meta controls its availability and features, and nothing exported runs independently.

    Fail
  • P6
    Capability independence

    Memory, connectors, shopping and agent features exist only as Meta platform services on Meta's models; none of them survive a move to another model or runtime.

    Fail

Transparent · Can you see everything the agent is, with ordinary tools?

17%
  • T1
    Open storage format

    Exports are available in machine-readable JSON or HTML, but Meta AI's internal state storage is undocumented and the owner cannot access it directly.

    Partial
  • T2
    No hidden instructions

    Meta does not publish Meta AI's system instructions or show what it adds to model context, including signals drawn from Facebook and Instagram activity.

    Fail
  • T3
    No shadow memory

    Since 2025-12-16, Meta uses interactions with its AI to personalize content and ads across its apps in most regions (excluding the EU, UK and South Korea); the resulting derived data is not part of an inspectable agent state.

    Fail
  • T4
    Complete action history

    Chat history is visible to the owner and included in exports, but Meta documents no complete history of the Muse agent's actions and tool calls that the owner can see or take away.

    Partial
  • T5
    Readable logic

    Meta AI's executable logic is proprietary server-side code that is not exposed as readable source.

    Fail
  • T6
    No third-party influence channel

    Meta has not documented whether sponsored content or commerce partners (Meta states it earns transaction fees from Muse purchases through partners such as Shopify and Stripe) influence Meta AI's recommendations, or whether owners can see or turn off such influence.

    Unverified

Auditable · Can you reconstruct exactly what the agent did?

10%
  • A1
    No unrecorded actions

    No durable record of consequential actions is available to the owner; the only visible record is chat history, which the owner can delete.

    Fail
  • A2
    Tamper evidence

    Chat history, the only visible record, can be deleted without any detectable trace, and no other way to detect changes to an action record is documented.

    Fail
  • A3
    Separation from the audited

    Meta does not document whether the agent layer can alter or delete records of its own actions.

    Unverified
  • A4
    Readable with ordinary tools

    Exports in JSON or HTML can be read with ordinary tools, but they are account-data exports, not an action audit trail.

    Partial
  • A5
    Corroborated interactions

    No record of the agent's exchanges with other agents or services is available to the owner, so nothing can be matched against a counterpart's record.

    Fail

Verifiable · Can you prove the agent runs what it claims?

0%
  • V1
    Open, reproducible runtime

    The Meta AI service runtime is proprietary. Meta has released some Llama model weights, but not the assistant's runtime.

    Fail
  • V2
    Active config is inspectable config

    The owner sees only memory and privacy settings; the configuration the service actually runs with is not inspectable.

    Fail
  • V3
    Attributable messages

    Recipients have no documented way to verify that a message came from this agent under its owner's authority, apart from Meta's own platform identity.

    Fail
  • V4
    Independently checkable record

    No action record with checkable integrity is exposed, so nothing can be verified with open tools independently of Meta.

    Fail
  • V5
    Comparable state

    Much of the agent's state (instructions, configuration, personalization signals) is held by Meta and not exposed, so the owner cannot verify whether it changed between two points in time.

    Fail

Modifiable · Can you change anything, without asking?

25%

Controllable · Is your word final?

8%
Something wrong or out of date?

Vendors and the public can dispute any finding with evidence. Disputes and their resolutions are published.

Dispute a finding