machine learning in spreadsheet applications

Keep data local while AI agents work across cloud and device

Your files stay put.

4 min readVentureBeat
Keep data local while AI agents work across cloud and device

The hybrid model Perplexity is rolling out today is the first credible answer we have seen to the question that has dogged every AI assistant since ChatGPT entered the workplace: how do you give an agent access to the data that matters most without handing that data to a third party? The mechanics are worth sitting with, because they invert the usual trade-off. A frontier model in the cloud plans the work, breaks it into subtasks, and then hands the sensitive pieces to a smaller open-weight model running on your Mac. The cloud never sees the privileged case files or the confidential financial projections. The local model does. And the Privacy Gate, a classifier Perplexity trained itself, decides what stays and what goes. That is a genuinely different architecture from the "just don't send us your secrets" posture most vendors have adopted, and it is why this launch feels like a turning point rather than another incremental feature drop. We would tell any reader who has been holding back on agentic tools because of confidentiality concerns to look closely at how the gate actually behaves. You can expand and review exactly what it flags before anything is transmitted, and enterprises get device-level audit logs. That is not a trust-me promise; it is a transparency mechanism baked into the product. The practical stakes for lawyers, bankers, and analysts are immediate. Perplexity's demos show an associate reworking a financial model against confidential management projections for 40 minutes with no human input, while a cloud agent simultaneously benchmarks the deal against public comparables. That work would have taken hours of manual stitching between local spreadsheets and cloud research. The founder in the Uber example is the one that should resonate, though. She starts a marketing analysis on her iPhone, and the agent asks permission to reach her Mac at the studio, spins up the local subagent to process her customer interviews, and combines that with public competitor pricing. The context survives the handoff. The confidentiality holds. The task gets done. That is the promise of agentic computing finally matching the reality of how professionals actually work, which is to say, not from a single locked-down machine. Perplexity's bet is that the fix was never to build a higher wall around sensitive data. It was to build a smarter gate. The company is positioning itself as the neutral broker, the Switzerland sitting above whichever frontier model happens to lead at any given moment, and its recent trajectory, from a $520 million valuation in early 2024 to a $20 billion round last September, suggests that arbitration layer is where the value is accruing. But there is a hard question buried in the architecture that no amount of clever routing can fully answer. The Privacy Gate is itself a machine learning classifier, and classifiers miss things. A false negative means sensitive data reaches the cloud anyway, no matter how well the orchestration works. Perplexity's answer is transparency, letting users expand and review what the gate flagged, and that is a reasonable response. It is not a complete one. The gate is making a judgment call about what constitutes personally identifiable information, and that judgment is being trained, evaluated, and tuned by the same company asking you to trust it. The open-weight models running locally, including the Chinese-developed Qwen models, are a separate point of tension. Perplexity argues that local inference neutralizes geopolitical risk, and that is true in the narrow sense that your tokens are not leaving your device. But the model itself is a piece of software running on your machine, and software has been a vector for exfiltration before. The mac sandbox constrains what the agent can do, and enterprise admins can set organization-wide policies and audit what leaves each device. That is real. It is also a lot of trust being placed in a stack that is only as safe as its least-examined dependency. The concrete detail to watch is the smallest local model option, which Perplexity admits significantly underperforms the larger Qwen models.

From VentureBeat

Perplexity today launched hybrid compute for its agentic platform, Computer, a system that lets a single AI agent split its work between frontier models running in the cloud and smaller open-weight models running locally on Apple silicon Macs — routing sensitive data to the local machine so it never leaves the device.

Read the original at VentureBeat