What Hybrid Compute Actually Does
Perplexity launched Hybrid Compute for its Mac app on September 1, 2026. A task still begins in the cloud, using Perplexity's frontier models for research and planning. If an on-device classifier detects potentially sensitive information partway through, the app alerts the user and offers a choice: keep that portion of the task on the Mac using a local model, mask the sensitive details, or send it to the cloud anyway. Perplexity says it built and trained the classifier itself, working with its own Secure Intelligence Institute, and has open-sourced the classifier code, though it has not published a specific repository name or link alongside the announcement.
The feature requires an Apple Silicon Mac running macOS 15 or later, with 24GB of unified memory as the stated minimum and 32GB recommended. At launch, the local models available are Gemma 4 E4B, Qwen3.6 35B-A3B, and a Perplexity-tuned version of Qwen3.6 35B-A3B. Perplexity's own examples of what the classifier flags are credentials, payment numbers, government IDs, confidential financial presentations, and private business pricing data. It is available to Pro, Max, and Enterprise subscribers.
Sensitive Is Not the Same Word as GDPR's Special Category
Perplexity's marketing language and the European Union's data protection law are using the word sensitive to mean two different things, and the gap matters for any business in the EU running client or employee data through this app. The examples Perplexity names, credentials, payment numbers, government IDs, and confidential pricing data, are commercially or security sensitive. Most of them are not what GDPR Article 9 calls special category personal data: health information, biometric or genetic data, political opinions, religious belief, trade union membership, or data about a person's sex life or sexual orientation.
That is not a criticism of the engineering. Keeping credentials and payment details off a third-party cloud server by default is a genuine architectural improvement over sending everything to the cloud, and it happens to reduce risk for ordinary business use too. The problem is the inference a compliance officer might draw from the feature's existence: that because Perplexity now keeps some things local, a task involving actual GDPR special category data, an HR file mentioning a medical condition, say, will automatically be treated as sensitive and kept off Perplexity's servers. Nothing in Perplexity's own announcement claims that mapping exists, and there is no public documentation showing the classifier was built against GDPR's Article 9 categories rather than against a general commercial-security sensitivity list.
What an EU Business Can Actually Rely On
| Situation | What actually happens |
|---|---|
| Ordinary task, nothing flagged | Processed in the cloud by Perplexity's frontier models, as before |
| Classifier flags credentials, payment data or an ID mid-task | User is asked to choose: local, masked, or cloud anyway |
| User picks send to cloud anyway | The flagged data is sent to the cloud despite the warning |
| Enterprise admin sets an organization-wide policy | A defined data category can be forced to stay local for every user, no per-task choice needed |
The enterprise policy control is the one piece of this feature that behaves like an actual compliance safeguard rather than a per-task nudge: it removes the individual employee's judgment call from the equation for a category the organization defines in advance. Everything else in Hybrid Compute is a default that a user, not a compliance policy, can override in either direction. A business handling genuine GDPR special category data through Perplexity still needs its own data processing agreement and its own definition of what must never leave the device, rather than assuming Perplexity's classifier already drew that line correctly.
Read next: A $2.5B Valuation With A Documented Risk List | Google Buys a Bankrupt Airline's Data for AI Training



