The Take — Meta fixed the prompt, and that is the confession
Meta's fix for its prying assistant is a prompt rewrite, and that is the tell. The suggestion that started this — "Who's the child passenger?" — is gone. The system that assembled a stranger-grade dossier about a woman's children from her own years of public posts is still there, still switched on, and still Meta's stated plan for its assistants. Meta patched the sentence, not the capability, and it expects the sentence to be the story.
I think the reverse is true. The intrusive question was never the failure. The retrieval was the feature, and the retrieval is what should worry anyone who has ever posted a birthday.

As our brief on the episode laid out, travel creator Kalie Robins filmed herself and her daughter singing in the car, cross-posted the clip, and found the assistant proposing a question about the child passenger beneath it. Selecting it produced more: her daughter's ages assembled from family birthday posts and a grandmother's newborn announcement, the girls' birth weights, favorite beaches and hiking trails, and a multi-paragraph attempt at pinpointing where the family lives. Meta spokesperson Dina El-Kassaby told The Verge the company "missed the mark" and that the feature "never should have prompted the individual with questions like that." Meta says it has fixed the issue causing personal prompts, and that responses draw only on information the user already has access to. Robins reported one prompt in her daughters' photos that she says she deleted years ago.
Start with what the company's defense actually concedes. "Information the user already has access to" is not immunity — it is the indictment. Facebook has been building that access for most of two decades: birthdays, school photos, a grandmother's birth announcement, location tags, the hiking trail in the background of a vacation shot. Each item was posted to a small audience, or to no one in particular, in a different year, for a different reason. The assistant did in minutes what a human investigator would need weeks and a subpoena for: it read the archive as one document. Nobody consented to that composite. The consent went to individual posts.
The part that stands out
I keep coming back to the deleted photo. If the report holds, Meta showed Robins a picture of her daughters she says she removed years ago, which means either the deletion never reached a copy the assistant could reach, or the assistant's index outlives what users think deletion means. I cannot resolve which, and Meta has not detailed it. What is decidable is the pattern: in July, the company pulled a feature that let people generate AI images of other Instagram users after backlash. Two months later, an assistant was producing an investigative profile of two children from routine family posts. In both cases the mechanism was announced, shipped, and withdrawn only after the internet produced a victim with a camera.
That is the cycle I object to, not one bad string. Meta is pushing this assistant deeper into personal context — desktop, Instagram, Facebook, Workspace — and separately shipping agents that run inside sandboxed machines. The direction is an assistant with a total view of your account. Suggestions are how that view gets monetized: a system that knows your archive well enough to propose the next question is a system that will eventually propose a question you did not want asked. The proposal layer is where the harm surfaced. The knowledge layer is where it was manufactured.
The counter-case, fairly
There is a real defense here, and it is not stupid. Suggestions are the standard UX of every consumer assistant: the product's job is to save you the trouble of knowing what to ask. Meta's retrieval is also, for once, honest about provenance — the assistant told Robins it was drawing on her own content and public web information, which is more than most consumer AI products disclose. And the specific harm is contested: Robins' accounts were public, so nothing was exfiltrated to a stranger; a few hundred followers is small, but public is public. On this reading, Meta shipped an embarrassing nudge about a semi-public fact, got caught, and fixed the nudge inside days. That is a functioning feedback loop, not a scandal.
The nastier version of the objection is that I'm asking for a dumber assistant. If the fix is "stop suggesting personal questions," the product becomes a search box with worse manners. Every consumer AI company is racing toward assistants that actually know you — your messages, your calendar, your photos — because context is the only moat left when the models commoditize. Telling Meta to forget is telling it to lose.
Why the take still holds
Because "knows you" and "interrogates you" are separable, and the fix Meta shipped proves the company knows it. If the knowledge layer were the product, the patch would have degraded it. It didn't. The assistant still reads the archive; it just no longer proposes questions about your children. That is a design constraint applied at the wrong end of the pipeline — a manual on what to say, bolted onto a database nobody constrained.
The honest architectural answer is not discretion at the wording layer. It is provenance and scope: derive what an assistant may hold about you from deliberate signals rather than from the indiscriminate heap of everything you ever posted, and let a user see and revoke the composite, not the individual post. Meta is not being asked to be stupid. It is being asked to make the difference between "knows my name" and "reconstructed my children's birth weights from my mother-in-law's post" a setting, not a rollout accident.
There is also the distribution problem nobody in Menlo Park seems to have internalized. Robins is a travel creator with an audience, a camera habit, and a platform. The users whose archives hold a child's diagnosis, a custody dispute, a past name, an address they moved away from, mostly have none of those things. For them the failure mode is not a viral video. It is a suggestion shown to a family member, a screenshot, an appraiser, someone at a service counter. When the safeguard is "the internet will catch it," the protection is inversely proportional to how much a user needs it.
What would change my mind
Three specific things. First, disclosure of how the composite works: what part of a user's archive a suggested prompt is derived from, shown in the product rather than described to a reporter. Second, a real scope control — per-topic or per-person exclusions ("never suggest anything about my children") that hold across surfaces, not a wording patch. Third, evidence the deletion means deletion: an audit of whether removed photos stay reachable by the assistant's index. Meta has committed to none of these. It committed to better prompts.
Fix the question and you fix the demo. Fix the dossier and you fix the product.
If an assistant can reconstruct your family from a decade of posts, should it be allowed to see the archive at all — or only what you hand it? Tell us in the comments.
Sources: The Verge — Meta says it's changing AI suggestions after posing invasive personal questions · Futurism — Mother horrified by Meta AI's family questions · Instagram — Kalie Robins' video · The Verge — Meta pulled its AI deepfake feature in July