Skip to content
The Executives BriefThe Executives BriefBeta

Perplexity launches hybrid AI that keeps confidential data on your Mac, off the cloud

Perplexity's Computer routes confidential work to on-device Apple silicon models via a Privacy Gate, ending the cloud-versus-privacy tradeoff for enterprise AI.

ByKhalid Al-HarbiBusiness Desk, The Executives Brief
·4 min read
Perplexity launches hybrid AI that keeps confidential data on your Mac, off the cloud
Executive summary

Jon Staff, who leads Perplexity's macOS and iOS engineering teams, introduced hybrid compute for Computer, the company's agentic platform. It lets a single agent run cloud frontier models and local open-weight models together, keeping personally identifiable information off the cloud.

Perplexity today launched hybrid compute for its agentic platform, Computer, a system that lets a single AI agent split work between frontier models in the cloud and smaller open-weight models running locally on Apple silicon Macs. Sensitive data is routed to the local machine so it never leaves the device. The company says this is the first time an AI agent can begin a task in the cloud and dynamically hand off the confidential portions of that same task to a model running on the user's own hardware, without restarting the job or losing context. The feature is available today in Perplexity's desktop app for enterprise customers that opt in, plus Pro and Max subscribers, on any Apple silicon Mac running macOS 15 or later.

The architecture works like a dispatcher. A frontier model in the cloud breaks a task into subtasks and routes each one to the appropriate place. Web research, long-horizon planning, and heavy reasoning run remotely; anything touching private files, local data, or actions on the device gets delegated to a subagent running on the Mac itself. The linchpin is what Perplexity calls a Privacy Gate: a company-trained classifier that runs on the device and scans for personally identifiable information, such as names, addresses, account numbers, and secrets, before anything is transmitted to the cloud. When the gate flags sensitive content, the user chooses whether that portion of the task runs locally or gets shared. Jon Staff, who leads Perplexity's macOS and iOS engineering teams, explained the handoff: "The cloud orchestration will break down the task based on the prompt and figure out how to route it to different subagents... it's going to delegate that down to a sub-agent running on your Mac, and then that portion of the task is run entirely local. None of those tokens go to the cloud."

Hybrid also changes the unit economics. Tokens generated locally cost nothing, because the user pays for electricity and hardware; cloud credits only pay for orchestration and delegation. Staff is explicit: "You're paying for the electricity, you're paying for the hardware, so we're not charging you for that. The only thing the credits are used for is the orchestration and the delegation." That makes the system especially attractive for repetitive, long-running tasks in workplaces that handle confidential documents. In one briefing, a lawyer updated a draft brief against privileged case files stored on a Mac while a cloud agent pulled public case law from the open web. Perplexity says only anonymised legal questions were shared with the cloud. "At no point did their privileged information get shared to the cloud," Staff said. "It never left the Mac." In another, a private equity associate's agent reworked a financial model against confidential management projections, benchmarked the deal against public comparables, and produced a fifth iteration of an investment committee deck. That task ran for roughly 40 minutes in the background, with no human input, across little more than a lunch break.

The launch lineup includes Google's Gemma E4B, Alibaba's Qwen3.6 35B-A3B, and a Perplexity post-trained version of Qwen3.6 35B, which is the recommended option. Security questions quickly follow. All of these are open-weight models, and Qwen is Chinese-developed. Staff countered that local inference neutralizes the geopolitical risk: the data is not sent to some overseas cloud provider, all of Perplexity's models are U.S.-hosted, and the models can be evaluated internally. He pointed to the macOS sandboxing framework, Seatbelt, as a guardrail: "If local execution is trying to do something that it shouldn't, it'll just point blank stop it and it'll request permission from the user." Perplexity does not currently allow unrestricted "YOLO mode" execution, though Staff said, "I wouldn't be surprised at some point if we allow certain people to do this." For enterprises in regulated industries, administrators can set a single organization-wide sensitivity policy and audit exactly what leaves each device. Consumer questions remain: Staff cited Perplexity's incognito mode and an existing opt-out toggle, and a spokesperson said Perplexity is not using user input for post-training globally, with details promised for non-enterprise accounts.

Why this matters beyond Perplexity: the most valuable enterprise work involves the data companies are least willing to hand to someone else's servers. NIST's generative AI risk profile flags data privacy and information leakage as central risks. McKinsey's AI research consistently finds organizations struggle to move from experiments to production, with data governance among the chief obstacles. Gartner named hybrid computing among its top strategic technology trends for 2025. Perplexity is betting that the winning architecture is not a choice between cloud intelligence and local privacy, but an orchestration layer that arbitrates between them in real time. And its positioning is accordingly neutral: "Perplexity is like Switzerland in that we work with everyone," a company representative said, with "Anytime one of these gets better, Perplexity gets better" when local models, frontier models, and Apple's hardware improve.

Perplexity is making this bet from a fast-climbing position: from $520 million to a $20 billion agent platform in three years. For CIOs, GCs, and founders running anything confidential, the strategic takeaway is not just that hybrid compute exists. It is that the old either-or hardware question just got a new answer. The agents that can keep your data on the device will get the run at sensitive workflows. Hybrid, local-first privacy is going to be the default for any agent that wants to sit inside the legal, finance, and healthcare workflows that definition. Pay attention to data governance budgets, because with hybrid compute, privacy has become a timed performance.

Executive ActionsLocked

This story's Key Insights and Take-aways are locked.

Create a free account to unlock Executive Actions for one credit.

Register to Unlock

Always free for Executives Club members. Join the Club

More in Business