Perplexity says its new product keeps sensitive data local by default. Security experts say the control that actually matters doesn't exist yet.
The company launched Portable Computer this week, an on-device AI system running on Nvidia's DGX Spark hardware. Work stays local unless a task is explicitly escalated to the cloud.
What Portable Computer Actually Does
The product runs its entire orchestration layer, including the planner, tool router and task queue, directly on device. Customers are only charged token costs when compute is explicitly sent to the cloud.
Aman Mahapatra, chief strategy officer at Tribeca Softtech, described the shift plainly. "Running the entire agentic control plane locally means the decision about whether a task needs the cloud is itself made on device," he said.
Hardware costs give some analysts pause. Flavio Villanustre is CISO at LexisNexis Risk Solutions Group. He said the setup needs at least 24GB of local GPU memory as a minimum. Gartner analyst Nader Henein said he couldn't get excited about the product without knowing its price.
The Real Question: Who Controls the Cloud Switch
The sharpest criticism targets enforcement, not hardware. Justin Greis, CEO of Acceligence, drew a specific distinction. "Local-first should not be confused with local-only," he said.
Mahapatra went further, arguing the product's cloud-escalation gate is consent, not control. "It depends on a probabilistic model correctly classifying sensitive content." He added: "It depends on a user judging a request they cannot fully inspect. Both fail adversarially."
He compared the risk directly to a known attack pattern. He compared the risk to a known attack pattern. The mix of file connectors and an authorized cloud path is "the same connector-plus-egress combination behind every Copilot exfiltration chain published this year," he said.
Mahapatra argued a real enterprise security review needs more. It requires a mandatory network-layer egress proxy with inspection on every escalation, not an application-level consent prompt.
"If escalation is governed by user consent and model judgment," he said, "this is a consumer product with a strong privacy story." Not an enterprise product with a compliance story, he added.
Perplexity's Response
Perplexity pushed back directly on that framing. Communications manager Beejoli Shah pushed back on that framing. Escalation requires explicit per-action approval, she said, and local data can't trigger it alone.
Users must manually enable a setting before any escalation is possible at all. "When that isn't toggled on, no work can proceed to the cloud," Shah said.
Shah added that escalation approval only applies once per request, not for the remainder of a task or in future sessions.
What This Means for Miami
This connects directly to the enterprise AI governance questions MAIN has already tracked. That includes workplace Slack visibility debates and the AI security testing standards multiple labs are now building together.
For Miami's financial firms, law offices and healthcare companies weighing on-device AI for compliance, that's the right question. Mahapatra's version of it works on any vendor.
Can an administrator define escalation policy the AI model can't override? Does a full audit trail exist for what actually left the device?
That's the difference between a real compliance product and a good privacy pitch.
Cisco and Supermicro Team Up to Build Neocloud Infrastructure