Meta’s New “Muse Image” Feature Lets Anyone Generate AI Likeness from Public Instagram Profiles
What Happened — On July 7, Meta launched Muse Image, an AI model that can create photorealistic images using a public Instagram handle as a prompt. By default, the feature is enabled for all public accounts; anyone can tag a handle and receive a synthetic image without the account holder’s knowledge or consent. The setting can be turned off, but the option is buried deep in the app and only blocks future generations—not images already created.
Why It Matters for Compliance & Audit Readiness
- The automatic reuse of publicly posted media creates a de‑facto “data export” that falls under GDPR/CCPA consent and purpose‑limitation requirements.
- Lack of notification means organizations cannot demonstrate a lawful basis for processing or provide timely DSAR responses, jeopardizing audit evidence of privacy controls.
- The hidden opt‑out illustrates a control‑gap in user‑privacy settings; continuous monitoring of consent‑related configurations is a core SOC 2 CC‑5 (Privacy) control.
Who Is Affected – Social‑media platforms, digital‑marketing agencies, SaaS providers that embed Instagram content, and any organization that relies on user‑generated visual media for branding or analytics.
Recommended Actions
- Immediately audit Instagram (or similar) integrations for default‑on content‑reuse settings and document the configuration as part of your privacy control inventory.
- Disable the “Allow people to reuse your content on Instagram and with AI features at Meta” toggles for all corporate accounts; consider switching accounts to private where feasible.
- Conduct a privacy impact assessment (PIA) to map the new data flow to GDPR/CCPA obligations, update consent records, and ensure DSAR processes can address synthetic‑image requests.
- Capture evidence of the setting change and policy updates in your continuous‑compliance platform to satisfy SOC 2 CC‑5 audit requirements.
Technical Notes – Muse Image is a generative‑AI model integrated into Instagram’s backend; it pulls publicly available photos, videos, and metadata to synthesize new images. No CVE is disclosed, but the feature functions as an “implicit data export” triggered by a simple handle tag. Earlier this year Meta disclosed a “confused‑deputy” flaw in its AI chatbot that allowed account changes without proper verification, mitigated by MFA. Source: Malwarebytes Labs