The task is split across two machines

Perplexity opened hybrid compute for its Computer agent platform. Cloud models handle web research, planning and heavier reasoning, while a subagent running an open-weight model on an Apple silicon Mac works on private files and local data. Perplexity says those tokens never leave the machine. The mode is available now in the desktop app to Pro and Max subscribers and to enterprise customers who opt in. What changes for a developer is the split of a single agent task across two runtimes: public research stays remote, private files stay local.[1]

The local options at launch are Google's Gemma E4B, Alibaba's Qwen3.6 35B-A3B and a Perplexity post-trained version of the same Qwen model, which the company recommends. The requirements are macOS 15 or later and a recommended 32 GB of unified memory. A classifier Perplexity trained, which it calls the Privacy Gate, checks content for personal identifiers before anything is sent to the cloud. The local model slot already has three candidates; the Mac and memory floor are the launch itself. The switching cost sits in that runtime boundary more than in the weight file.[1]

The routing signal comes from a 0.6 billion parameter encoder

Perplexity introduced the PII-TRACE benchmark and the on-device PII-Tracer detector the same day. PII-TRACE contains 13,148 synthetic user-assistant conversations across 13 languages and 10 writing systems, with 37,431 identifier mentions across 9 types. PII-Tracer is a 0.6 billion parameter bidirectional encoder adapted from a Qwen3 backbone; it replaces the causal mask with padding-aware bidirectional attention so every token can draw on earlier and later turns inside a 4,096-token window. Perplexity says it trained the model for 3 epochs on roughly 714,000 samples, and that a constrained Viterbi decoder maps the label sequence back to character spans. The announcement frames both as privacy infrastructure for Computer's hybrid architecture: a local gate keeps sensitive content on the Mac, redacts detected private information, or asks for approval before sending it to the cloud.[2]

The figures are Perplexity's own. The company reports that PII-Tracer reached the highest character F1 score, 0.629, among the 12 systems evaluated, and found every mention of 79.4 per cent of recurring identifiers. Length is a separate limit: single-window recall is 0.975 below 1,000 characters, 0.955 from 1,000 to 10,000, and 0.687 at 10,000 characters or more. Decoding the same checkpoint with 50 per cent overlap sliding windows raises overall character recall from 0.830 to 0.965 and multi-mention consistent detection from 0.794 to 0.954, without retraining. The conversations are synthetic reconstructions derived from the structure of production traffic; tool calls, inter-agent messages and multimodal inputs fall outside the benchmark's scope. No independent evaluation has been published.[2]

The inspectable unit sits at the gate

At Perplexity, I think the builder's real dependency collects in the control signal the Privacy Gate supplies. The Gemma E4B and Qwen3.6 35B-A3B slot already has three candidates; the claim that tokens never leave the Mac hangs on the spans the classifier marks. PII-Tracer offers a 0.6 billion parameter encoder for that signal, and on Perplexity's own PII-TRACE measurement it fully covers 79.4 per cent of recurring identifiers. A plain alternative remains open: the Privacy Gate may be a product name for a coarse user switch that keeps chosen files local, with span-level detection firing only rarely. Both readings point at the same layer. What locks the team is the policy that decides which tokens go to the cloud.[1], [2]

Perplexity says it plans to release the PII-TRACE set and the PII-Tracer detector under the MIT licence, and that it plans to release both soon. The weights and the benchmark set are not yet out. Sliding windows close the 10,000-character cliff on the company's own checkpoint, which shows that the default single window is not enough for a long session. Computer's hybrid promise is that private-file tokens stay on the machine. The testable form of that promise is published gate weights and a character F1 on the same 13,148 conversations from outside the company. The macOS 15 and 32 GB floor already narrows that test.[1], [2]