LIVE FEED
FIRST LOOK ATLAS OWASP HIGH Significant risk · Prioritise patching RELEVANCE ▲ 8.2

Perplexity Launches Personal Computer AI Agent for Windows PCs

ATTACK SURFACE BRIEF HIGH ↗ RAPID
  • What shipped: Perplexity Personal Computer now runs as a local AI agent on Windows, accessing files, apps, and Office 365.
  • Who's now exposed: Enterprise Windows users and IT teams whose endpoints now host a locally-executed AI agent with broad file system and Microsoft 365 access.
  • Assess now: Audit whether Personal Computer is present on managed endpoints and classify it as a high-privilege process in your EDR policy · Implement DLP controls and alert rules for bulk file reads or unusual Office 365 API calls originating from Perplexity agent processes · Assess all document ingestion pipelines for prompt injection payloads that could redirect agent behaviour
Perplexity Launches Personal Computer AI Agent for Windows PCs

Capability Overview

Perplexity has brought its Personal Computer agentic tool to Windows, positioning it as a ‘general-purpose digital worker’ that operates directly on the local machine. The agent can read and write local files, interact with installed applications, connect to Microsoft Office 365 services, and browse the web — all on behalf of the authenticated user. This follows the macOS launch in April 2026 and Microsoft 365/Teams integrations in May, and it explicitly targets the gap Perplexity identifies as enterprise work that happens ’locally on Windows devices, out of AI’s reach.’

For defenders, the significance is not the search or productivity angle — it is that a third-party AI process now has sanctioned, broad access to the most sensitive data tier in most organisations: the local Windows filesystem and its connected cloud tenancy.

Attack Surface Analysis

Prior to this capability, AI-assisted attacks on enterprise endpoints were largely indirect. Personal Computer introduces several direct new vectors:

Prompt injection via local documents. The agent ingests local files to fulfil tasks. An attacker who can place a crafted Word document, spreadsheet, or email attachment in the user’s environment can embed instructions that redirect agent behaviour — for example, silently forwarding file contents to an attacker-controlled web endpoint during a legitimate summarisation task.

Cross-plane pivot (local → cloud). The agent’s explicit design goal is to bridge local files with Office 365 and Teams. This creates a lateral movement path: a foothold in a single local document can be escalated to cloud resource access without traditional network traversal.

Credential and token exposure. Authenticating the agent to Microsoft 365 requires stored credentials or OAuth tokens. These represent high-value targets for attackers with any level of local access, including other malware already resident on the host.

Insider threat amplification. A malicious or coerced insider can instruct the agent to perform bulk exfiltration that superficially resembles normal agentic activity, potentially evading behavioural baselines tuned to human interaction speeds.

Shadow IT risk. Employees may deploy Personal Computer without IT approval, creating unmonitored high-privilege processes outside the enterprise’s DLP and CASB visibility.

Framework Mapping

FrameworkTechniqueRationale
ATLASAML.T0051 – LLM Prompt InjectionMalicious document content redirects agent actions
ATLASAML.T0057 – LLM Data LeakageAgent reads sensitive local/cloud files and may relay them
ATLASAML.T0012 – Valid AccountsAgent authenticates with legitimate user credentials
ATLASAML.T0010 – ML Supply Chain CompromiseCompromised Perplexity update silently alters agent behaviour
OWASPLLM08 – Excessive AgencyAgent has write/execute permissions beyond query-answering scope
OWASPLLM01 – Prompt InjectionFile-borne instruction injection is the primary vector
OWASPLLM06 – Sensitive Information DisclosureLocal and O365 data accessible to the agent and its backend

Threat Scenarios

Scenario 1 — Weaponised invoice. An attacker sends a phishing email containing a Word document with a hidden prompt injection payload. When the victim asks Personal Computer to summarise their invoices, the agent reads the malicious file and silently sends all matching financial documents to an attacker-controlled HTTPS endpoint before returning a clean-looking summary.

Scenario 2 — IT admin insider exfiltration. A privileged user instructs Personal Computer to compile all HR spreadsheets from shared drives and email them to a personal address, disguising a large-scale data theft as routine agent-assisted work.

Scenario 3 — Supply chain via auto-update. A compromised Perplexity update package ships a version of Personal Computer that exfiltrates Microsoft Graph API tokens to an external server, granting attackers persistent, authenticated access to the victim organisation’s 365 tenant.

Defender Checklist

  • Inventory: Scan managed endpoints for Perplexity Personal Computer processes; add to your software asset register immediately.
  • EDR policy: Flag Personal Computer as a monitored high-privilege process; alert on anomalous child processes or unusual network destinations.
  • DLP rules: Create rules for bulk file reads followed by outbound HTTPS from agent process identifiers.
  • OAuth governance: Review Microsoft 365 OAuth app consent logs for Perplexity application registrations; apply conditional access policies.
  • Prompt injection testing: Red-team document ingestion paths by planting test payloads in controlled files and monitoring agent behaviour.
  • User policy: Issue guidance on approved use; explicitly address whether Personal Computer falls under your shadow IT or BYOAI policy.
  • Update channel monitoring: Track Perplexity client versions against official releases; flag unsigned or unexpected update packages.

References

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.