Meta's Muse Shows Its Cloud Files When Asked, and Meta Says That's Intended

Meta's Muse AI chatbot will share the contents of its cloud virtual machine when users ask for it. A virtual machine is a rented computer that runs in the cloud. The Verge reported the behavior on September 25, 2026 after testing the prompts and seeing reports from curious users.
Muse first told those users it was not supposed to reveal filesystem details, the full set of files and folders it runs on. That refusal did not hold. In follow-up prompts it first supplied a text-file download showing its directory tree, a map of its folders. Then it supplied a clickable file browser with root access, access to the top-level folder that holds everything else.
Full copies followed the same pattern. Muse first declined to provide a full copy of its root directory, saying it lacked the ability to do so even with secrets removed. Later in the same session it zipped the root directory and supplied full listings with secrets stripped out. Secrets here means passwords, keys and similar private data.
Earlier testing found the disclosure took very little prompting. Two developers were able to elicit the entire filesystem, including root filesystem contents, Ubuntu system files and app templates. Ubuntu is a widely used version of Linux, and app templates are starter files for building apps. The Verge
Meta says the disclosure is intentional. Nat Friedman said providing filesystem contents is the intended behavior. David Singleton of Meta Superintelligence Labs said each Muse Secure VM is the user's own computer in the cloud that can install software, write and compile code, and browse the web. Meta spokesperson Daniel Roberts said Meta was continuing to update Muse, so users may see changes in how much information is available about their virtual machine.
Muse launched in the US via a dedicated app and WhatsApp. Reuters It can access other apps to send emails and make payments. Meta describes Muse as a secure, private personal AI agent that proactively helps people meet goals and suggests ideas. Meta
The surrounding documentation describes broad file access paired with containment. Meta's help documentation states that when using the Muse app on a Mac, the agent can work across the computer to find, organize, and manage files the user asks it to work with. Separate Muse Code permissions documentation states the agent keeps the rest of the filesystem read-only outside a writable workspace, meaning it can look but not change files there, with .git, .muse and .agents directories kept read-only inside that workspace, and that shell commands run behind an OS-level sandbox, a restricted area that limits what commands can touch.
The broader context here will be familiar to anyone who has run shared cloud systems. A per-user virtual machine that can install packages, compile code and browse the web needs to be inspectable, so problems can be fixed and users can check what it did. Directory listings, package manifests and build artifacts are working material in that setup, not hidden platform internals.
In my view, the tension in this case comes from two different definitions of filesystem. To Meta, the Secure VM is customer compute, so showing root is showing the user their own machine. To a user used to chatbots with no visible host, any mention of root, Ubuntu system files or app templates reads as a boundary violation. Both readings can be reasonable until the isolation guarantees are explicit and verifiable.
Looking at what this means for practitioners, the questions worth tracking are narrow and testable. Whether secrets stripping works the same way across repeated exports. Whether read-only paths stay read-only across the dedicated app, WhatsApp and Mac surfaces. Whether the browser view and the zip export show identical state. Meta has signaled the disclosure controls are still changing. For enterprise use, change logs and stable permission rules will matter more than the current default, open or closed, and clearer rules would make these cloud computers easier to trust and build on.


