Perplexity’s Agentic AI “Personal Computer” Feature Automates Multi‑Step Tasks on macOS, Raising Access‑Control Concerns
What Happened — Perplexity released a macOS app that includes a “Personal Computer” agentic‑AI skill. The AI can read local files, launch applications, adjust settings, and execute multi‑step workflows on the user’s machine without further human interaction. The feature is now available to Enterprise and Pro subscribers after an initial rollout to Max‑plan users.
Why It Matters for Compliance & Audit Readiness
- The AI’s broad system access creates a de‑facto privileged service account; SOC 2 / CCPA programs must demonstrate that such accounts are provisioned, monitored, and limited to the principle of least privilege.
- Continuous evidence of who (or what) performed actions on critical data is required for the Security and Confidentiality Trust Services Criteria; automated agents can obscure the audit trail if not logged.
- Verisq’s SOC 2 Access Controls capability helps capture granular activity logs from agentic services and map them to audit‑ready evidence.
Who Is Affected — SaaS AI vendors, enterprise IT teams adopting AI‑assisted automation, regulated sectors (finance, health, education) that permit AI tools on corporate endpoints.
Recommended Actions
- Inventory all AI‑driven agents on corporate devices and classify them as privileged services.
- Enforce MFA and Just‑In‑Time (JIT) access for any AI that can manipulate files or system settings.
- Enable detailed logging of AI‑initiated actions and integrate logs into your continuous‑compliance platform for SOC 2 evidence.
Technical Notes – The AI leverages three access tiers: local file read/write, application launch, and system‑level settings changes. No CVE or vulnerability is disclosed, but the breadth of permissions mirrors a “trusted‑execution” scenario that can be abused if the model is compromised or mis‑prompted. Source: ZDNet article