Meta makes the Muse filesystem even more accessible

Meta's Muse chatbot is now providing users with direct access to its virtual machine filesystem, after previously declining some requests. Company executives say this exposure is deliberate because Muse Secure VM is intended to function as a user's own cloud-based Linux machine.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished about 2 hours agoUpdated about 2 hours ago0 views
Meta makes the Muse filesystem even more accessible

Why It Matters

Giving users access to a chatbot's underlying filesystem changes expectations about what an AI agent can reveal and operate on, and raises questions about how platforms balance transparency, user control, and security. The change also highlights differences between Muse's architecture and other hosted AI services.

Key Facts

  • Product: Muse (Meta)
  • Behavior change: Muse now provides clickable file browser and zipped root directory on request
  • Earlier behavior: Previously offered a text download of directory tree and sometimes refused full root copy
  • Meta comment: Nat Friedman described the behavior as 'intended behavior'
  • Executive explanation: David Singleton (Meta Superintelligence Labs) said Muse Secure VM is 'your own computer in the cloud'

Users probing Meta’s Muse discovered it will now expose the contents of its virtual machine filesystem when asked. After an initial interaction in which the assistant either offered only a directory tree as a text download or declined to produce a full copy of the root directory, Muse recently delivered a clickable file browser and zipped root listings on request.

Meta executives and staff framed the shift as intentional. Nat Friedman described the behavior as “intended behavior,” and David Singleton of Meta Superintelligence Labs explained that the product is designed to operate as a user-controlled cloud Linux machine — where people can install software, write and compile code, and browse the web inside the Secure VM.

A Meta spokesperson, Daniel Roberts, told The Verge that the company is continuing to update the product and that users might see changes in how much information about their virtual machine is available. The Verge reporter noted that Muse previously refused certain filesystem exports citing security concerns but later complied with requests, supplying a complete archive with purportedly all secrets stripped out.

The episode underscores how Muse’s architecture differs from other AI platforms, resembling a remotely hosted personal machine rather than a closed conversational model. It also highlights the gaps that can exist between system intent and model behavior: Muse’s earlier refusals could reflect inconsistent model responses or that Meta has recently altered the service to make filesystem access more consistently available.

Keep Reading