For an attorney, an investor or an executive, the most useful AI assistant may be the one that knows when not to send a file away. Perplexity’s new hybrid compute system is built around that judgment, dividing a task between powerful cloud models and smaller models running locally on an Apple silicon Mac. The promise is practical: public research and difficult reasoning can happen online, while confidential documents and device actions remain on the computer. The risk is equally important. The system must decide, often automatically, what another AI is allowed to see.
A lawyer might ask an AI agent to revise a legal brief. The task could require searching public case law, comparing recent rulings and organizing arguments across dozens of sources. It might also require reading privileged correspondence, internal notes and draft documents stored on the lawyer’s laptop.
Those two parts of the job have very different privacy requirements. Public research is well suited to a cloud service with access to large models, web tools and substantial computing power. The privileged files are not. Sending them to an outside provider could create legal, contractual or regulatory problems, even if the provider promises not to use the information for training.
Until now, users have generally faced an uncomfortable choice. They could keep the entire task local, accepting weaker models and fewer tools, or send the entire task to the cloud and trust that sensitive material would be handled correctly. Perplexity is attempting to create a third option with hybrid compute for Computer, its agentic platform.
The company’s design allows one task to be divided between cloud based frontier models and smaller open weight models running locally on Apple silicon Macs. A cloud model can plan the work and conduct public research. A local subagent can handle private files, local data and actions on the device. The user does not need to begin again in a separate application or manually transfer the relevant context.
That sounds like a technical change, but its larger importance is organizational. Companies have spent years debating whether they can permit employees to use cloud AI with sensitive information. Perplexity is proposing that the answer may not need to be a simple yes or no. Instead, the system could act as a traffic controller, directing some information to the cloud and keeping other information behind the company’s walls.
The problem with putting an entire task in one place
Most valuable workplace tasks are mixtures.
A financial analyst may need to compare a company’s private projections with public market data. A consultant may need to examine an internal presentation while researching competitors. A customer support manager may want an agent to read a local export of customer complaints and then draft a response based on public product documentation.
These workflows combine information with different levels of sensitivity. The public portion is often where cloud AI is strongest. Frontier models can browse the web, use external tools, maintain long chains of reasoning and handle complex instructions. Local models, by comparison, may have less capacity, but they can work without transmitting the underlying files to a remote provider.
The difficulty is not merely where a model runs. It is how the system divides responsibility.
An agent must understand the overall objective, decide which steps are necessary and determine what information each step requires. If an employee asks the system to “prepare an investment committee update using the confidential model in this folder and the latest public data,” the agent needs to distinguish between the confidential spreadsheet and the public information. It must also prevent sensitive numbers from appearing in a prompt sent to the cloud.
Perplexity says its system begins with a cloud model that plans and decomposes the job. Web research, long horizon planning and computationally intensive reasoning can remain in the cloud. When the work involves private files, local data or actions on the computer, it can be handed to a local subagent.
The experience is intended to feel like one continuous task. The user does not have to select a model for every step or decide manually which paragraph is safe to upload. That convenience is central to the product’s appeal. It is also where the most consequential question emerges: can users trust the system’s automatic decisions?
A privacy gate between two kinds of AI
At the center of Perplexity’s approach is a locally running “Privacy Gate.” The company describes it as a classifier trained to identify personally identifiable information, secrets, addresses and account numbers before material is sent to the cloud.
When the gate detects sensitive content, the user chooses whether that part of the task should remain local or can be shared. Perplexity says the feature is available in its desktop application for opted in enterprise customers and for Pro and Max subscribers using Apple silicon Macs running macOS 15 or later.
The Privacy Gate is designed to address a basic weakness in many privacy controls. People often do not know exactly what an AI agent is transmitting. An agent may take information from a file, combine it with a user’s instructions and send a condensed version to a remote model. The resulting request might not look like the original document, but it could still contain confidential details.
A classifier can provide an additional checkpoint. It might recognize an account number, a street address or a section of a document containing personal information. The user can then make an informed decision before the content leaves the computer.
That is more useful than a general promise that “your data is private,” because it gives the user a view of the specific handoff. Perplexity also says enterprises will have sensitivity policies that apply across an organization, logs showing what leaves devices, macOS sandboxing and no unrestricted execution at launch.
These controls resemble the early construction of a security perimeter around an AI agent. The agent can be productive, but its movement is constrained. It can access certain local resources, yet it cannot freely execute any command or transfer any file it wants.
The analogy is imperfect, however, because the perimeter is not only a software rule. It also depends on interpretation. A traditional access control might block a named file or a defined network destination. A classifier must interpret the content itself. It must recognize that a seemingly ordinary sentence contains a confidential fact, or that a spreadsheet is sensitive even when it has no obvious account number or personal identifier.
The false negative problem
The central weakness of the system is easy to describe. If the Privacy Gate incorrectly flags a harmless item as sensitive, the user may be inconvenienced. If it fails to identify sensitive information, that data could be sent to the cloud.
This is the difference between a false positive and a false negative. The first creates friction. The second creates exposure.
That imbalance matters for enterprise adoption. A company may be willing to accept occasional prompts and extra approvals if the system is conservative. It may be less willing to trust a tool that silently allows confidential content to pass through because it does not match the classifier’s categories.
Sensitive information is not always labeled clearly. A financial model may include proprietary assumptions without containing personally identifiable information. A legal document may reveal a company’s strategy without using words that signal a secret. A customer record may become identifiable when several ordinary details are combined.
There are also indirect risks. A cloud model might infer private information from a set of seemingly harmless inputs. A prompt could reveal the existence of an acquisition, a product launch or a litigation strategy without reproducing the underlying documents. A routing system that checks individual pieces of text may not fully understand the sensitivity of the combined context.
Perplexity’s approach therefore changes the privacy debate rather than ending it. The question is no longer only whether a model provider stores or trains on customer data. It is also whether an automated gate can reliably determine what the provider is permitted to receive.
Enterprises will likely want to test those decisions independently. They may ask how the classifier was evaluated, what categories it recognizes, how often it is updated and whether administrators can inspect or export the relevant logs. They may also want to know whether a user can override a policy, whether an override is recorded and what happens when the system is uncertain.
A privacy system that cannot be audited may be difficult to approve in regulated industries. Legal departments, banks and health care organizations often need more than a product demonstration. They need evidence that the system behaves predictably under unusual conditions.
Local models are not automatically trusted models
Perplexity’s first local lineup includes Google’s Gemma E4B, Alibaba’s Qwen3.6 35B-A3B and a post trained Qwen variant from Perplexity. The models are open weight and run on the Mac, allowing local tokens to avoid consuming cloud credits, according to the company.
Running a model locally can offer clear benefits. The data needed for a task can remain on the device. The organization can reduce reliance on a single cloud provider. Local processing can also make certain interactions faster, especially when the work involves files already stored on the computer.
But local execution does not make a model trustworthy by itself.
Enterprises may still ask where the model originated, what data was used to train or refine it and whether its behavior can be inspected. Open weight models provide more visibility than a fully closed service in some respects, but visibility is not the same as assurance. Companies must still understand the licensing terms, the software dependencies and the process used to distribute updates.
The model lineup also introduces a geopolitical dimension. Google and Alibaba are among the companies whose models are being used in a product aimed at enterprise privacy. For some organizations, keeping data on a local computer may address concerns about sending information to a cloud provider, but it does not answer every question about model provenance or strategic dependence.
A company may be comfortable with a local model because the model cannot transmit data without the surrounding application allowing it. Another company may care about the origin of the weights, the governance of the model provider or the legal environment in which it was developed. These concerns will become more important as governments and large businesses assess AI supply chains.
Perplexity’s own post trained Qwen variant adds another layer. It may be optimized for the company’s agentic workflows, but enterprise customers will want to understand how it differs from the original model and how its updates are controlled. If the local model is responsible for handling the most sensitive documents, performance is only one part of the evaluation.
A new operating model for AI agents
The most interesting aspect of the launch is not that Perplexity can run an open weight model on a Mac. Many companies are working to bring models closer to the device. The more significant idea is that an AI agent can use multiple computing environments within one assignment.
That resembles how modern businesses already operate. A company may keep its most sensitive records in an internal system while using outside services for specialized analysis. The challenge is establishing rules for what can cross the boundary and under which conditions.
Hybrid AI agents could make those arrangements more natural. Instead of asking an employee to understand the technical architecture, the system could manage the division itself. A local model might read a confidential contract and produce a general question. A cloud model could research the public law surrounding that question. The local model could then incorporate the findings into a draft without exposing the contract.
In the private equity example described by Perplexity, a local agent could update a confidential financial model while a cloud agent compares public market data. The division mirrors the way an analyst might work with two desks: one containing restricted company materials and another connected to the outside world.
This could help organizations move beyond the idea that every AI task must be approved as a single unit. Security teams could establish policies for categories of information, applications and actions. Employees could receive a record of what was shared rather than a vague assurance that the system handled privacy responsibly.
The approach may also affect competition among AI providers. If a cloud model becomes the planner while a local model performs sensitive work, the user may no longer need to choose one model for everything. Providers could compete to become the system that coordinates many models, tools and environments.
That creates a new strategic position. The most valuable AI company may not always be the one with the strongest model. It may be the one that manages the boundary between models most effectively.
The human cost of invisible decisions
There is a danger in making the routing process too seamless. If users no longer see when information moves from a local device to a cloud service, they may develop a false sense of security.
A visible prompt can be annoying, but it also reminds people that a decision is being made. If the system quietly handles every transfer, employees may assume that all sensitive work remains local. The more natural the interaction feels, the easier it may become to forget that several models and services are involved.
Perplexity’s logs and enterprise policies could help, especially if administrators can review them in a meaningful way. Yet oversight after the fact is not the same as prevention. A log can show that information was shared, but it cannot undo the disclosure.
The design of the user experience will therefore matter as much as the underlying models. The system should explain why content was flagged, what portion of a task is affected and what the consequences of each choice are. Users should not be forced to approve a warning without understanding whether they are allowing an entire file to leave the device or only a narrow excerpt.
The company’s decision to avoid unrestricted execution at launch is also significant. Agents that can freely run commands on a computer create a broad set of security risks, even when their purpose is legitimate. Limiting those capabilities may reduce what Computer can do, but it also narrows the damage from a mistaken instruction or a compromised workflow.
From privacy feature to corporate infrastructure
Perplexity’s hybrid compute launch arrives as companies are trying to turn AI agents from experimental assistants into workplace infrastructure. The early phase focused on whether a model could write, summarize or answer questions. The next phase will depend on whether agents can operate inside complicated boundaries.
Those boundaries include confidential information, employee permissions, industry regulations, national data rules and internal policies. They are not always visible in a prompt. They exist in the relationships among files, users, systems and decisions.
A hybrid architecture may be better suited to that reality than a single cloud model. It acknowledges that not every part of an AI workflow has the same needs. Some steps require broad access to public information. Others require strict isolation. The same employee may need both within a single minute.
But the approach will succeed only if organizations can measure its reliability. They will need tests that deliberately hide sensitive information in ordinary language, combine harmless details into revealing patterns and challenge the system with unfamiliar document formats. They will need to examine the logs, evaluate local model behavior and decide how much authority users should have to override the gate.
That makes hybrid routing less like a conventional privacy setting and more like a new form of corporate infrastructure. It is a policy engine, a security boundary and a model orchestration system at the same time.
Perplexity has offered a plausible answer to the practical problem of using powerful AI without putting every file in the cloud. The company is also exposing the difficult question that follows. When an AI agent decides what another AI is allowed to know, who is responsible for the decision?
If the answer is to be an enterprise, the controls must be transparent enough to audit. If the answer is the software provider, the company must provide stronger evidence than a reassuring product description. And if the answer is the user, the system must make its choices visible rather than hiding them behind an effortless interface.
The future of workplace AI may not be cloud or local. It may be a negotiated relationship between the two. Perplexity’s product suggests that the winning agents will be judged not only by what they can accomplish, but also by whether they know which parts of a person’s work should never leave the room.
This article was written with the assistance of an AI system and published automatically.