FR
live
AI

Perplexity launches its local agent on Windows, gated behind 24 GB of VRAM

Perplexity has brought Portable Computer, the local edition of its Computer agent, to Windows after Linux and macOS — but only for NVIDIA RTX cards with at least 24 GB of VRAM. Simple tasks run on-device, the model hands off to the cloud when it needs more reasoning, and sensitive files can stay on the machine.

A desktop graphics card seated in a dark PC tower, a single amber status LED lit on its edge.

August 25, 2026. Perplexity ships Portable Computer, the local edition of its Computer agent, on Linux and the NVIDIA DGX Spark workstation. Early September. A hybrid variant lands on Apple silicon, splitting work between on-device and cloud models. September 14, 2026. The Windows build arrives in the Perplexity app for NVIDIA GeForce RTX and RTX PRO GPUs. Why it matters: a consumer-grade agent with real multi-step autonomy now runs on a desktop PC — with one requirement that changes everything, a minimum of 24 GB of VRAM.

What Portable Computer actually does

Portable Computer is not a model launcher. Tools like LM Studio and Ollama make running a model locally painless, but they stop well short of handing it autonomous multi-step work. Perplexity bundles the whole agent stack instead: a post-trained model, a built-in browser, tool calling, and its proprietary SPACE sandbox.

On Windows, the app ships two models tuned for RTX GPUs: PPLX 27B, Perplexity’s own post-trained model, and Qwen 3.8 27B. The agent can open files, browse, invoke tools, and chain steps without supervision — as long as the GPU holds up.

The hardware bar is unforgiving. You need an NVIDIA card with at least 24 GB of VRAM, which rules out most consumer cards and reserves the local edition for the RTX 3090, RTX 4090, RTX PRO parts, and workstations. On an 8 GB RTX 4060, Portable Computer simply will not run.

Underneath, SPACE is the trust boundary that makes the whole thing safe enough to ship. It is Perplexity’s sandbox: the agent’s tools — the browser, the file access, the connectors — run inside it, so a bad tool call degrades into a contained failure rather than a compromised machine. The sandbox is what separates an autonomous agent you supervise from a shell script executing model-generated commands. That distinction is easy to miss in a demo, but it is the difference between a curiosity and a tool you can let near real data.

Three platforms in under three weeks

The pace of the rollout is worth pausing on. In less than twenty days, Perplexity covered three very different targets:

  • Linux + DGX Spark, on August 25, aimed at developers and dedicated stations;
  • Apple silicon, a week later, using a hybrid mode that splits tasks between the local engine and cloud models on Macs;
  • Windows, on September 14, the largest consumer audience of all.

Each port took more than a recompile. Perplexity had to adapt the inference runtime, orchestration, security, and hardware integration for every platform while keeping the experience identical. Pulling that off in three weeks signals that agent infrastructure is now the real battleground — a point underscored by DeepSeek, which is hiring roughly 150 roles, almost all of them focused on agent infrastructure rather than the model itself.

“Local” does not mean “isolated”

“Local” is a misleading word if you read it wrong. Portable Computer is not air-gapped. The agent can reach external services because it ships connectors for Microsoft Outlook, OneDrive, Word, Google Drive, Gmail, Slack, and GitHub. A task completed locally can process files without sending documents to a cloud model, but once an agent has access to both local files and remote APIs on the same machine, the boundary gets blurry.

That is where the hybrid architecture steps in. Perplexity is not claiming that a 27-billion-parameter model on a desktop GPU can handle everything. When the agent decides a task needs more reasoning than the local model can deliver, it escalates to Perplexity’s cloud models. According to NVIDIA, the agent flags when cloud help would be useful and asks the user for permission before sending any data off the machine.

For an organization handling sensitive or regulated data, that split matters. The agent can grind through source code or financial records without uploading them to a hosted model for basic processing. There is a cost angle too: tasks completed locally do not burn Perplexity Computer credits.

The pricing and what comes next

Portable Computer is included in Perplexity Pro at $20 per month and Max at $200 per month, across individual and enterprise plans, with NVIDIA DGX Station support promised later. The hard part is not technical — it is turning local agents from developer passion projects into enterprise-ready tools, and by baking the agent into Windows, Perplexity puts it in front of the scale of users needed to make that happen.

The signal goes beyond Perplexity. DeepSeek is hiring heavily for agent infrastructure, OpenAI is pushing its Agents API, and now an autonomous local agent has arrived on the world’s most widely used desktop operating system. The race is no longer about model size — it is about the layer that gives models the means to act.

A contested field between launchers and orchestrators

Portable Computer’s positioning is clearest when placed between two tool families. On one side, model launchers — LM Studio, Ollama — run an LLM locally but never hand it autonomy. On the other, cloud agent platforms — OpenAI’s Agents API, Anthropic’s Claude agents — offer multi-step autonomy but keep execution and data on the server. Portable Computer tries to take the best of both: chaining tasks without sending file contents off the machine.

DeepSeek’s hiring confirms the hard part is no longer the model. The roughly 150 open roles target agent infrastructure — orchestration, memory, tools, sandboxing — not the LLM itself. That is a strong signal: value is shifting from model size to the layer that gives models the means to act.

An example makes the promise concrete. Consider a data analysis on a confidential spreadsheet. Locally, the agent opens the file, cleans the columns, and computes aggregates — the document never leaves the machine. If a step needs heavier reasoning, the agent flags that it wants to escalate to the cloud and asks permission. The user can decline and keep the task local, at the cost of a more limited answer.

None of this removes the operator’s judgment. A local agent that can reach cloud APIs is only as safe as the permissions you grant it, and the SPACE sandbox is a mitigation, not a proof. For teams, the governance question is the same as with any agent: which tools, which connectors, and which data the agent may touch — decided before the agent runs, not discovered after.

Verdict

Portable Computer on Windows is a serious demonstration of what a local agent becomes, but its 24 GB of VRAM floor makes it, for now, a product for workstations and high-end rigs.

If you run an RTX 3090, 4090, or a PRO card, the local edition is worth trying: simple tasks stay on your machine and burn no credits, with an explicit handoff to the cloud when needed. If your fleet is 8 GB or 12 GB machines, do not expect it to run — the door is shut, and your options are the Mac hybrid mode or waiting for a smaller model. If you handle regulated data, the deciding factor is not compute but the permission rule: verify that cloud escalation is blocked by default before you let an agent touch your files.

References

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

Qwen3.8-Max ships open weights, but not under Apache 2.0

On August 12, 2026, Alibaba published the weights of Qwen3.8-Max, a 2.4-trillion-parameter MoE model, under a custom license with revenue thresholds rather than Apache 2.0. Before you deploy, read the clauses: the checkpoint is text-only and resale above a threshold becomes paid.

← Back to the feed

Type at least two characters.

navigate open esc dismiss