There's a conversation we have constantly with NGOs, small law firms, and accounting practices: "We'd love to use AI for this, but our clients' files can never leave our systems."
That's been a real objection. Not bureaucratic cover, not technophobia. An actual compliance concern. Cloud AI is useful. Cloud AI that processes your donors' personal information, your clients' privileged legal files, or your patients' health records is a harder sell, internally and legally.
On September 1, Perplexity shipped something that starts to answer it. Hybrid Compute is a new mode in their Mac app that splits each AI agent task in two: the cloud handles research, web search, and reasoning; a local model running on your Mac handles anything it classifies as sensitive.
Here is the actual flow. You ask Perplexity's Computer agent to find recent case law on non-compete agreements and compare it against your client's employment contract. The agent pulls from the web in the cloud. Your client's contract stays on your machine, processed by a model running locally. The outputs get merged. Nothing from that contract file hit an external API.
The local classifier runs first, before anything gets sent anywhere. When it catches something that looks sensitive — names, account numbers, emails, file types it recognizes as privileged — you get a prompt: keep it on-device, mask the details, or send it to the cloud anyway. That last option means you stay in control; the system does not override your judgment.
Perplexity open-sourced the PII classifier. That matters more than it sounds. If your IT team or legal counsel wants to audit what gets flagged as sensitive before trusting the system, they can look at the rules directly and customize them. That's a more honest approach than the black-box data handling most cloud-only tools ship with.
What is actually running locally
The local models are real: Google's Gemma 4 E4B, Alibaba's Qwen3.6 35B-A3B, and a version of that Qwen model that Perplexity itself fine-tuned for its agent workflows. These are not throwaway small models. The 35-billion-parameter variants handle document analysis, summarization, and comparison tasks competently. The app installs them itself — no terminal, no configuration files, no sysadmin help needed.
The app also surfaces live CPU, GPU, memory, and token counters while queries run, so you can see in real time which model is handling which part of the task. That kind of transparency is not standard, and for compliance purposes it matters.
The hardware floor is real
This requires an Apple Silicon Mac running macOS 15 with at least 24GB of unified memory. That means an M2 Pro, M3, or M4 machine at minimum. Base-model MacBook Airs with 16GB are out. If your office runs a mix of older hardware, this will not cover everyone.
For the machines that do qualify — and a lot of 2024 and 2025 professional laptops do — this is the first production AI agent that handles the cloud-versus-local routing automatically, without requiring your staff to manage two separate tools or manually decide what goes where.
It is also Mac-only right now. Windows support is not on the announced roadmap.
Subscription is required: Pro, Max, or Enterprise. The Enterprise tier is where organizational controls and audit logging live. For a five-person NGO, the Pro plan is probably enough to pilot this. For an office with compliance requirements, Enterprise is where you would want to start.
The use cases that actually matter here
Three specific workflows where this changes the conversation:
An eight-person NGO with donor data under privacy regulations can now run AI research tasks that touch their donor database without that data hitting a cloud API. The agent handles the research side in the cloud; the personally identifiable information stays on the device.
A small law firm can have the associate run a research brief from the web, cross-referenced against a privileged client file, with the privileged content processed locally. This is what every lawyer has wanted and what compliance teams have blocked. The routing happens automatically.
An HR team at a 50-person company wants to analyze market compensation data against their actual payroll. The benchmarking data comes from the cloud. The payroll file stays on the Mac.
These are not edge cases. They are exactly the workflows that have been sitting in the "we cannot do this with AI" pile.
What this is not
This is a first version, and it is worth being clear about what it does not solve.
The local classifier will miss things. It will also flag things it does not need to. You are routing sensitive data to a model that is still, ultimately, running on hardware Perplexity's app controls. This is a meaningful step up from sending everything to the cloud, but it is not the same as running a fully self-hosted, air-gapped system.
The system is not offline. Cloud reasoning and web search are still part of the workflow. If your organization's security posture requires fully disconnected operation, this is not that.
And Perplexity is a VC-backed company. Open-sourcing the PII classifier is a good sign, but the business could change direction. Vendor dependency is still vendor dependency.
What we would do with this right now
If you have been putting off an AI workflow because of data governance concerns, pick one use case and pilot it in the next two weeks. The goal is not to migrate everything — it is to find out whether the classifier's routing matches your risk tolerance before deciding whether to expand.
Run something low-stakes first: a research task that references internal but non-critical documents. Check what the classifier routes locally and what it lets through. That gives you a baseline for the more sensitive workflows.
If it holds up, the conversation with your compliance team changes. Instead of "we cannot use AI for this," the question becomes "does this routing pass our threshold." That's a much more tractable problem.
This is the pattern we think wins: local intelligence for sensitive data, cloud intelligence for everything else. If Perplexity's implementation works at scale, it will push other platforms to follow. The orgs that figure out their hybrid compute workflow now will have a head start when that shift happens.
CivSafe helps small organizations set up AI workflows that fit their compliance requirements. If your org has been blocked by the "we can't send our data to the cloud" problem, let's talk.