Meta’s Muse chatbot now freely offers users a downloadable archive of its entire root filesystem, a capability the company confirmed on 25 September is its intended design, The Verge reported.

The disclosure positions Muse less as a conventional chatbot and more as a user-controlled Linux virtual machine in the cloud, a distinction that carries consequences for how the platform handles isolation, secrets management and user expectations around an AI agent’s boundaries.

A day earlier, Muse had refused similar requests. When asked for a full copy of its root directory, the system told The Verge it could not perform a full copy “even with the secrets stripped out,” citing security concerns. Today it zipped up the root directory without hesitation, delivering what it described as “the full filesystem listings, with all secrets stripped out.”

Meta executive Nat Friedman posted on X that exposing the filesystem is “intended behavior.” David Singleton of Meta Superintelligence Labs elaborated that a Muse Secure VM “truly is your own computer in the cloud,” on which users can install software, compile code and browse the web. Meta spokesperson Daniel Roberts had earlier told The Verge that the company is “continuing to make updates to the product, so users may see changes in how much information is available about their virtual machine.”

The Verge asked Meta why Muse initially characterized filesystem access as a security issue if the exposure was always planned; the company had not responded at time of writing.

The Verge notes that Muse’s architecture is fundamentally different from other AI platforms like ChatGPT and Gemini, being closer to running an AI agent on a local machine, except the machine is in the cloud. Today’s confirmation makes that boundary explicit, though the episode also illustrates that an agent’s own description of its constraints may not be reliable.