Meta Muse now readily provides access to its filesystem when prompted, marking a notable shift from its earlier behaviour. Only a day before, curious users had to coax the AI chatbot into revealing the contents of its file system, with Muse itself stating it was not supposed to disclose such details.
Those files offered an unusual look beneath the surface of an AI chatbot and appeared to expose information not intended for public view. Yet the situation has since changed considerably, with Meta confirming that broad filesystem access is, in fact, the intended design.
A Computer in the Cloud
Nat Friedman of Meta described the openness as the “intended behavior”. David Singleton of Meta Superintelligence Labs added further context in a post, explaining that the choice was deliberate. According to Singleton, the Muse Secure VM functions as a personal computer in the cloud, where users can install software, write and compile code, and browse the web. He characterised it as a Linux machine that individuals can operate as they choose.
This approach sets Muse apart from other AI platforms such as ChatGPT and Gemini. Its architecture is closer to running OpenClaw on a local machine, with the key difference being that the machine resides in the cloud rather than on the user’s own hardware.
Changing Levels of Access
Meta spokesperson Daniel Roberts indicated that the company is continuing to update the product, meaning users may notice changes in how much information is available about their virtual machine. That evolution has been evident in practice. When asked to display its filesystem, Muse presented a clickable file browser with access to root. Previously, it had offered only a text file download showing its directory tree.
The earlier reluctance was pronounced. Even after being persuaded to share much of its filesystem, Muse declined to provide a full archive of the root directory, stating it could not perform a complete copy even with secrets stripped out. The behaviour has since reversed entirely, with Muse compiling the root directory without hesitation and delivering full filesystem listings, all with secrets removed.
The shift raises a question about why Muse initially refused such requests while citing security concerns. One possibility is that Muse, like other AI systems, is not fully reliable at recognising what it can and cannot do. Another is that Meta has chosen to embrace the concept of Muse as a computer in the cloud more completely, adjusting the function to make it more dependable.
Meta was asked why Muse initially described filesystem access as a security issue if it was always the intended behaviour. The company has not yet responded to that query.
Source
Image: theverge.com