HomeIntelligenceBrief
BREACH BRIEF🟡 Medium ThreatIntel

Perplexity’s Agentic AI ‘Personal Computer’ Feature Automates Multi‑Step Tasks on macOS, Raising Access‑Control Concerns

Perplexity’s macOS app now includes a ‘Personal Computer’ agentic‑AI skill that can read files, launch apps, and change system settings without further user input. The capability expands the attack surface for privileged‑access abuse, making it a compliance focus for SOC 2 audit readiness.

LiveThreat™ Intelligence · 📅 July 23, 2026· 📰 zdnet.com
🟡
Severity
Medium
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
2 recommended
📰
Source
zdnet.com

Perplexity’s Agentic AI “Personal Computer” Feature Automates Multi‑Step Tasks on macOS, Raising Access‑Control Concerns

What Happened — Perplexity released a macOS app that includes a “Personal Computer” agentic‑AI skill. The AI can read local files, launch applications, adjust settings, and execute multi‑step workflows on the user’s machine without further human interaction. The feature is now available to Enterprise and Pro subscribers after an initial rollout to Max‑plan users.

Why It Matters for Compliance & Audit Readiness

  • The AI’s broad system access creates a de‑facto privileged service account; SOC 2 / CCPA programs must demonstrate that such accounts are provisioned, monitored, and limited to the principle of least privilege.
  • Continuous evidence of who (or what) performed actions on critical data is required for the Security and Confidentiality Trust Services Criteria; automated agents can obscure the audit trail if not logged.
  • Verisq’s SOC 2 Access Controls capability helps capture granular activity logs from agentic services and map them to audit‑ready evidence.

Who Is Affected — SaaS AI vendors, enterprise IT teams adopting AI‑assisted automation, regulated sectors (finance, health, education) that permit AI tools on corporate endpoints.

Recommended Actions

  • Inventory all AI‑driven agents on corporate devices and classify them as privileged services.
  • Enforce MFA and Just‑In‑Time (JIT) access for any AI that can manipulate files or system settings.
  • Enable detailed logging of AI‑initiated actions and integrate logs into your continuous‑compliance platform for SOC 2 evidence.

Technical Notes – The AI leverages three access tiers: local file read/write, application launch, and system‑level settings changes. No CVE or vulnerability is disclosed, but the breadth of permissions mirrors a “trusted‑execution” scenario that can be abused if the model is compromised or mis‑prompted. Source: ZDNet article

📰 Original Source
https://www.zdnet.com/article/perplexity-personal-computer-agentic-ai-complex-tasks-mac/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your SOC 2 posture defensible.

See where you'd stand with Verisq AI Trust Operations →