Perplexity's new hybrid AI keeps your sensitive files on your Mac while still using cloud intelligence
A built-in privacy filter decides in real time which parts of a task stay local and which go to the cloud. Lawyers, finance teams and healthcare workers are the target audience.

Key points
- Perplexity launched hybrid compute for its Computer agent platform on 22 July 2025, available to Pro, Max and enterprise subscribers on Apple silicon Macs running macOS 15 or later.
- A on-device classifier scans for personally identifiable information before any data leaves the machine, giving the user final say over what gets shared.
- Local processing costs no credits; users only spend credits on the cloud orchestration portion of a task.
- Three local models are available at launch: Google's Gemma E4B, Alibaba's Qwen3.6 35B-A3B, and a Perplexity-tuned version of Qwen3.6 35B.
- Perplexity says it is not using this data for model training globally, though it has not yet published specifics for non-enterprise accounts.
Most AI agents work like a postal service that opens your letters. You hand over everything, the cloud reads it, and the answer comes back. Perplexity wants to change that.
The company launched what it calls hybrid compute on Tuesday, a system where a single AI agent, software that can carry out multi-step tasks on its own, splits its workload between powerful cloud servers and a smaller model running entirely on the user's own Mac. The sensitive parts never leave the device.
How does the privacy filter actually work?
A piece of software Perplexity calls the Privacy Gate sits on the Mac and scans everything before it goes anywhere. It is a classifier, a trained program that reads text and decides what category it belongs to, and its job is to spot personally identifiable information: names, addresses, account numbers, anything confidential.
When it finds something sensitive, it stops and asks the user. You decide whether that portion of the task runs locally or gets sent out. If you choose local, those words never touch a cloud server.
The cloud side handles the bigger-picture thinking: web research, long-range planning, heavy reasoning. The local model handles whatever touches private files or actions on the machine itself.
"The cloud orchestration will break down the task based on the prompt and figure out how to route it to different subagents," Jon Staff, who leads Perplexity's macOS and iOS engineering, said at a press briefing first reported by VentureBeat. "That portion of the task is run entirely local. None of those tokens go to the cloud."
What models run on your Mac?
At launch, users can pick from three local models.
| Model | Developer | Notes |
|---|---|---|
| Gemma E4B | Smaller, faster option | |
| Qwen3.6 35B-A3B | Alibaba | Larger, more capable |
| Qwen3.6 35B (Perplexity-tuned) | Perplexity / Alibaba | Recommended by Perplexity |
Two of the three are based on Qwen, a model family developed by Chinese tech company Alibaba. Asked whether enterprise customers had raised concerns about running a Chinese-developed model on company machines, Staff argued the risk is neutralised when the model runs locally: the data never leaves your computer, and open-weight models, meaning models whose underlying code is publicly available for inspection, can be examined by anyone. MacOS also constrains what the agent can do through its built-in security framework.
That argument is reasonable for data privacy. Whether government or regulated-industry customers accept it remains to be seen.
What does this mean in practice?
Perplexity showed three demos. A lawyer updated a confidential draft brief while a cloud agent pulled public case law. A finance analyst ran a 40-minute background task combining confidential projections with public market data, no manual work needed. A small-business owner kicked off a marketing analysis from her phone while the agent reached her Mac at the office to process local customer data.
All three are jobs people currently either do manually or refuse to give to an AI because the data is too sensitive.
On cost: tokens processed locally use no credits. You pay credits only for the cloud orchestration piece.
One open question is consumer data use. Perplexity says it is not using this data for training, globally, but has not yet published the detail for non-enterprise accounts. Enterprise contracts can include zero-data-retention terms. If you are a Pro or Max subscriber with privacy concerns, Perplexity's incognito mode and its existing opt-out toggle are your best tools for now, until the company publishes clearer terms.
Common questions
Does this work on Windows or older Macs?
No. At launch, hybrid compute requires an Apple silicon Mac, the chip design Apple introduced in late 2020, running macOS 15 or later. Windows and Intel-based Macs are not supported.
Who can use it right now?
Perplexity's Pro subscribers, Max subscribers and enterprise customers can opt in through the desktop app today. A free-tier rollout has not been announced.
Is the Alibaba-made model a security risk?
Perplexity's position is no: the model runs entirely on your device, its code is publicly available for inspection, and macOS limits what it can access. Independent security researchers have not yet published assessments of this specific setup.



