Executive Summary: Perplexity (API Platform + Enterprise + Comet + Computer)

Perplexity sells judgment, not infrastructure, and it prices that judgment per call. The row reads gap at Layer 0, 1A, 1C, 2A and 2C, moderate at 1B, and strong at 2B and Layer 3. That shape puts it in the same cohort as OpenAI and Anthropic, with one difference that matters. Those two sell intelligence and let you assemble around it. This one sells an assembled opinion about how the work should go. Presets that decide how much effort a run deserves. A classifier that decides how much searching a question needs. A ranking that decides what counts as an answer. The mechanisms underneath are largely other people's, from the frontier models it brokers to the open weights it hosts to the web itself.

The two customer-facing surfaces point in opposite directions, and the row turns on that. Where Perplexity is the served component, at retrieval and inference, an enterprise can build on it. The Search API returns raw ranked results for your own pipeline, the Agent API answers an OpenAI client with a base-URL change, and Computer takes work from an external agent over the Model Context Protocol. Where Perplexity is the client, at data movement, there is nothing to build on. Its 400 connectors exist so the agent can reach into systems that already hold the data, and a run ends with a person reading an answer or the same agent writing back through another connector. No stage another system consumes, no destination, no artifact that outlives the run. The data never moves. The decision does.

Layer 1B is the cell that explains the rest. Perplexity exposes its own production web index as a generally available API, past 300 billion pages by its own account, with content extraction, domain and language filters, and a published evaluation framework beside it. On its own terms that capability is strong. It scores moderate because of where the surface sits. There is no index the customer administers, no vector store, and no hybrid retrieval over the enterprise's own corpus, so an architect cannot build what peers building on AWS, Databricks, Palantir or VAST can build. Nothing here is deficient. The primitive is exposed above the altitude where the building happens, and the instrument grades capability against the market rather than against the vendor's own ambitions.

At 2C the row ships more first-party agent control than either peer and still lands on gap. Comet Enterprise governs what the assistant may do, mobile device management pushes it silently, CrowdStrike Falcon watches the data movement, custom roles and SCIM carry identity, and audit logs claim capture across agent steps. All of it governs Perplexity's agents inside Perplexity's clients. None of it is a plane the enterprise points at its own agent estate, and a log of what an agent did is never a control over what it may do. Live per-request placement is absent here as it is nearly everywhere, and the routing that does exist distributes traffic across deployments of a model the caller already named.

The capture is decoupled and the doors are all on one side. You can bring your model, your client, your agent, your own protocol server, and Perplexity documents every one of those paths. What has no door is the value: the index, the ranking, the embedding space, the answer. The browser is the sharpest version. An assistant living in Comet inherits every session the user is already signed into, with no connector, no authorization grant, and no line in anyone's integration inventory. The local product inverts the usual reading and is worth understanding precisely. The weights are portable, and the lab that tested it reproduced the local stack standalone with no vendor application present. The harness around them is not portable, and it exposes nothing that would let another system drive it.

The buyer's trade: the best web retrieval sold anywhere, a genuine agent runtime hosted and local, four vendors' frontier models on one invoice, and an application estate that reaches into the browser. In exchange, the data plane stays entirely the enterprise's problem, the reasoning plane stays the enterprise's problem, capacity arrives as a function of lifetime spend with no way to reserve it or cap it, and the judgment the buyer accumulates has no exit. The exits that do exist are real, and they are all day-one architecture decisions. Keep the application logic in deterministic code outside the model. Drive Computer over the protocol rather than living inside it. Hold your skills in your own repository. Take the default path instead and what compounds is somebody else's opinion, arriving as an answer, with the reasoning behind it unavailable for review.

Layer-by-layer status: Layer 0 (Serving Fleet, Not a Customer Surface), Layer 1A (Permission Consumer, Thin Trust Shell), Layer 1B (Web-Scale Retrieval Primitive, No Customer Estate), Layer 1C (Agentic Movement, No Pipeline), Layer 2A (Spend-Earned Tiers, No Customer Plane), Layer 2B (Brokered Serving, Hosted and Local Runtimes), Layer 2C (Product Controls, Not a Reasoning Plane), Layer 3 (+1) (First-Party Value Plane: Answers, Browser, Agent).

Assessment framework: 4+1 Layer AI Infrastructure Model. Scoring model: Decision Authority Placement Model (DAPM) — Retained, Delegated, or Ceded. Published by The Advisor Bench LLC. Author: Keith Townsend. Date assessed: August 27, 2026. Version: v1.1 - Peer-Review Reconciliation.

Perplexity (API Platform + Enterprise + Comet + Computer)

Mapped to the 4+1 Layer AI Infrastructure Model

v1.1 - Peer-Review Reconciliation·Assessed August 27, 2026·Source: docs.perplexity.ai (Agent API, Search API, Embeddings API, Router API, Sonar deprecation and migration, tools, connectors, skills, admin rate limits and usage tiers, analytics API, privacy and security, MCP server integrations), Perplexity Help Center (Enterprise roles and permissions, SCIM, audit logs, data retention and privacy, file connectors, internal knowledge search, Comet for Enterprise, Computer, scheduled tasks), Perplexity hub blog and changelog (Search API introduction, Comet Enterprise, Portable Computer, March 2026 platform launch), CrowdStrike newsroom (Falcon for Comet Enterprise), github.com/perplexityai/pplx-garden (TransferEngine, MIT), trade coverage of the NVIDIA partnership and Portable Computer launch (August 25, 2026). Published 4+1 methodology applied: the exposure test and substrate-surface rule at Layer 0 (ratified CoreWeave 1C vs. Supermicro 1C, extended on OpenAI v1.0); the whose-paper rule at 2B (ratified Supermicro v1.0, Cisco v1.5); the inference-interface standards rule, 'the S3 of inference' (ratified OpenAI v1.0, Anthropic v1.0), applied here to the OpenAI-compatible Responses interface; 'routing is not reasoning' and 'you cannot prompt your way to deterministic output' (ratified Salesforce v1.0) at 2C; the GA-gate applied to the Router API (private preview), Agent API Connectors (preview), and the CrowdStrike Falcon integration (announced opt-in, no GA date). v1.1 (peer-review reconciliation, August 27, 2026): adversarial review by an independent reviewer under the Layer2C Labs peer-review harness, six claims, one upheld and five rejected with evidence recorded in labs/reviews/perplexity-row.json. Upheld: the Portable Computer component bundled the portable open weights with the proprietary harness, under-reporting a genuine exit; split into a Ceded harness component and a Retained locally-served weights component on the gpt-oss precedent. Rejected with evidence: 2C to moderate (the estate distinction is the peers' ratified calibration language), 2B to moderate (AWS Bedrock is the published precedent for brokered models scoring as the broker's capability), the Responses interface to Ceded (enumeration returned vLLM, Azure OpenAI and the Open Responses specification as independent implementers), 1B to gap (the real-dependence guardrail and the OpenAI 1B precedent), and Layer 3 to moderate (four published rows hold Layer 3 strong with no first-party coding agent).
ACTIVE ASSESSMENT
Strength
Moderate
Gap
Partner
Layer 0 · ComputeCompute & Network FabricServing Fleet, Not a Customer Surface

Raw compute, networking, and acceleration fabric

Vendor-Provided

NVIDIA-Provided

No Customer-Facing NVIDIA Surface, and a Fabric Built to Be Portable

Nothing at this layer transmits NVIDIA exposure to the customer, because nothing at this layer is sold. The fabric finding sits on the other side of the ledger. TransferEngine, the point-to-point communication library Perplexity published under MIT and runs in its own production serving, reaches 400Gbps on NVIDIA ConnectX-7 and on AWS Elastic Fabric Adapter alike, by design. Its stated purpose is running trillion-parameter models on H100 and H200 clusters an operator already owns rather than buying the next generation. The peers hedge their NVIDIA dependency in the supply chain. This one published the hedge.

Gap Analysis

There is nothing to buy here and that is the whole shape of the company. The buyer purchases answers, seats, or tokens. Perplexity operates a large serving fleet on capacity it rents, and none of it appears on the architect's menu: no instance types, no accelerator selection, no fabric, no cluster topology, no placement, and no dedicated-capacity product in the documentation. The exposure test governs (ratified CoreWeave 1C vs. Supermicro 1C), and the substrate-surface rule from the OpenAI row makes the boundary decidable. Layer 0 credit requires the substrate itself to be the purchasable thing, meaning silicon choice, instance types, fabric, and placement. Compute administered through an abstraction that hides the substrate is a runtime product and scores at the runtime layers. This row adds a wrinkle neither peer has, and it does not move the cell. Portable Computer runs on hardware the customer already owns, from a GeForce RTX card to a DGX Spark, and the customer buys, powers, and supports every part of it. Perplexity provides none of that and supports none of it. This is packaged software arriving on somebody else's machine, which cedes no compute authority and confers no compute capability on the vendor. The open-source fabric work is real Layer 0 engineering given away rather than sold, and a free library is not a purchasable compute substrate. It is scored where it performs its function, at 2B, on the precedent that put OpenAI's open-weight models at the runtime layer rather than here.

Borrowed Judgment

Total at this layer and structurally invisible, with a second layer of opacity the peers do not have. The enterprise inherits the silicon, fabric, and placement judgment of whichever owner's capacity served the request, and cannot audit which one that was. Because the Agent API also brokers models from OpenAI, Anthropic, Google and xAI, a single Perplexity request can be served on a third party's fleet that Perplexity does not own either.

Working Notes

Ruling recorded: Portable Computer does not create a Layer 0 surface. The vendor ships packaged software onto hardware the customer bought and supports none of it, so the compute stays substitutable and the authority never moves. Fact question, read of docs is no: does Perplexity sell any dedicated or single-tenant inference deployment an enterprise administers, including through the AWS Marketplace listing, where the customer selects capacity rather than tokens? The Marketplace listing reads as a procurement path for the same API.

Layer 1A · StorageData Storage & GovernancePermission Consumer, Thin Trust Shell

Durable, governed data foundation — the Governance Catalog that Layer 2C queries

Vendor-Provided

NVIDIA-Provided

No NVIDIA Layer 1A Dependency

There is no storage product for NVIDIA to accelerate. The near-empty column continues.

Gap Analysis

What exists is a trust shell around data the enterprise brings in. No training on customer data, a zero-data-retention policy on the chat completions API, SOC 2 Type II, a HIPAA gap assessment, and CAIQlite. On the application side: SCIM at fifty or more seats or one Enterprise Max seat, custom roles on sales-assisted plans, audit logs delivered in real time to a webhook, configurable retention and enforced incognito mode, and an organization-level setting governing which model providers are permitted. Connectors reach Google Drive, OneDrive, SharePoint, Box and Dropbox, and they honor the source system's permissions live, including immediate revocation when access changes at the source. None of it is a data foundation. The layer's purpose is the governed foundation a reasoning plane would query, and there is no storage product, no catalog, no classification authority, no lineage, and no authorization authority beyond the workspace wall. Perplexity honors SharePoint's catalog rather than being one, which is well-designed behavior and the opposite of capability at this layer. The Salesforce and Qlik boundary decides it the same way it decided Anthropic: this does not reach the curation rung, because there is no catalog to curate. Calibration, and it is not a tie. Both peers ship a thicker apparatus. OpenAI has residency across ten regions, customer-managed encryption keys, a tenant admin console and a Compliance API. Anthropic has zero-data-retention arrangements, workspace inference-geography controls, customer-managed keys and a Compliance API with dozens of security integrations. This row's documentation shows no residency control, no customer-managed keys, and audit delivery by webhook rather than a queryable compliance surface. All three land on gap because the function is absent in all three. This apparatus is the thinnest of the cohort and the cell says so. One number settles the architectural question. An organization administrator can upload up to five hundred files to the org repository, and a user gets fifty files per Space. That is a workspace, not a data foundation.

Borrowed Judgment

None to borrow at this layer. The enterprise's authoritative data, classifications, lineage and access policies stay in the source systems, governed by those vendors' catalogs and the enterprise's own controls. Adopting Perplexity transfers no data-governance authority. It adds one more consumer that honors the existing authorities.

Working Notes

The trust apparatus is named here as sub-threshold platform administration, not scored capability, matching the treatment the metering apparatus receives at 2A. Connector indexing of enterprise content is scored at 1B where it performs its function, not double-counted here. Fact question, read of docs is no: does an Enterprise Max agreement add data residency, regional inference, or customer-managed encryption keys? A yes softens the prose and moves nothing, since none of those is the layer's function. The Trust Center renders client-side and could not be read directly, so the absence rests on doc inference.

Layer 1B · RetrievalContext Management & RetrievalWeb-Scale Retrieval Primitive, No Customer Estate

Low-latency retrieval for RAG — vector/hybrid search, context windows

Vendor-Provided

Search APICeded

Generally available. Ranked results over Perplexity's own index as structured data, with content extraction under a caller-set token budget, domain, country and language filters, and multi-query requests. Callers process and store results in their own pipelines. The interface is single-vendor: no independent vendor implements it, and the ranking behind it is proprietary. The residual switching cost is the lowest of any Ceded component on this row, because what you accumulate against it is a query and what you keep when you leave is the retrieved content.

Embeddings API (Standard and Contextualized)Ceded

Generally available, 1024 and 2560 dimensions, 32K context, with Matryoshka representation learning and INT8 or binary quantization. Vectors are returned to the caller rather than stored by the vendor, which looks like portability and is not. The embeddings carve-out ratified on the OpenAI row governs: vectors are useless without the same model at query time and no second vendor serves the same embedding space, so an embedded corpus does not lift out.

Internal Knowledge Search and File ConnectorsCeded

Generally available on Enterprise plans. Indexes content connected from Google Drive, OneDrive, SharePoint, Box and Dropbox, honoring the source system's permissions in real time including immediate revocation. A permission-honoring index that lives inside Perplexity's product and answers only there. The enterprise cannot query it from anywhere else and cannot take the index with it.

NVIDIA-Provided

No NVIDIA Layer 1B Dependency

The index, the ranking models and the embedding models are Perplexity's own, served on rented capacity. NVIDIA supplies nothing the customer touches at this layer.

Gap Analysis

This is the one thing no other vendor on the instrument sells: a production web index, exposed raw. The Search API is generally available and returns ranked results as structured data with titles, links, snippets, and publication and update timestamps, plus full page-content extraction under a token budget the caller sets. Filters cover domain allowlists and denylists, country, up to ten languages, and up to five related queries in one request. Perplexity states the index runs past 300 billion pages, refreshed continuously, ranked in 358 milliseconds. A software development kit and a published evaluation framework ship alongside it. Beside it sits a generally available embeddings line the enterprise runs against its own corpus, in standard and contextualized forms, from a 1024-dimension model at less than a cent per million tokens to a 2560-dimension model, both with 32K context and quantization options. Contextualized embeddings chunk with document-level awareness rather than treating each chunk as an island. Vectors return to the caller and Perplexity stores nothing. On the application side, Internal Knowledge Search indexes connected corpora and honors the source system's permissions. The case for strong is real and the cell rejects it. This is a general primitive rather than a fixed-function one: the caller gets raw results for their own pipeline and can send them anywhere, which is the test that separated VAST's arbitrary event-driven functions from NetApp's captive ingest pipeline. The grade turns instead on the altitude at which the primitive is exposed. There is no index the customer administers, no vector store, no hybrid retrieval surface over customer data, and no reranker in the documentation. The frontier at this layer is set by AWS, Azure, Google, Databricks, OCI, Palantir, VAST and Salesforce, each of which hands the enterprise a governed retrieval estate it operates. This hands over two ends, retrieve-the-web and embed-your-text, and leaves out the middle, so the enterprise cannot build what its peers build. Strong is frontier-pegged and moderate is absolute. The capability is not deficient. It is exposed above where the building happens, and the grade is a statement about the market rather than about the engineering. It lands with OpenAI's hosted retrieval primitive and Anthropic's federated search, and it is the strongest web-retrieval capability of the three by a wide margin.

Borrowed Judgment

High, and it accumulates in two distinct places. The embedding space is model-captive by the instrument's own carve-out: vectors are useless without the same model at query time and no second vendor serves that space, so an embedded corpus is a standing commitment. The ranking is the subtler one. What the Search API returns is not the web, it is Perplexity's opinion about the web, and an application tuned against that ranking inherits a judgment it cannot audit or reproduce elsewhere. You are renting the garden's judgment by the query. The retrieved content itself is yours and always was, which is the part that looks like an exit and is not the part where dependence accumulates.

Working Notes

Watch-list, August 2026: Agent API Connectors, covering GitHub, Slack, Google Drive and Datadog, carry an explicit preview notice in the documentation and are not scored. The Agent API's web_search and fetch_url tools are the Search API wearing a runtime hat and are scored once, here. Index size and the 358 millisecond figure are vendor-stated. The absence of a reranker rests on absence from the documentation. Fact question: is there any customer-administered index or vector store in an Enterprise agreement, or is Internal Knowledge Search the only place enterprise content is indexed?

Layer 1C · PipelinesData Movement & PipelinesAgentic Movement, No Pipeline

Move/transform data — ETL/ELT, lineage, cost-aware movement, KV cache tiering

Vendor-Provided

NVIDIA-Provided

No NVIDIA Layer 1C Dependency

No movement product exists for NVIDIA to accelerate. The near-empty column continues.

Gap Analysis

This cell is genuinely contested and the reasoning matters more than the grade. Perplexity Computer reaches more than four hundred services through authorized connectors with real read and write access, including Gmail, Outlook, Slack, GitHub, Notion, Linear, Salesforce and Snowflake, with a bring-your-own path over the Model Context Protocol for internal systems. Scheduled Tasks sit on top of that and run unattended on a cadence, using the same tools, connectors and subagents an interactive run would use. An enterprise can absolutely stand up recurring movement between two systems of record without writing a pipeline. That is more than either peer productized, and the Anthropic row's standing question, whether any generally available service synchronizes data between enterprise systems independently of a query, gets a yes here where it got a no there. What ships is still agent labor rather than a movement product. At run time the agent performs all three motions: it reads through a connector, transforms in a sandbox or in the model, and writes back through another connector. What it never produces is the artifact. There is no pipeline authoring surface, no schema mapping, no declared source-to-target contract, no lineage, no dependency management, no backfill or idempotency semantics, no change data capture, no cost-aware movement, and no administrable cache tier. The transform is also not a transform in the pipeline sense. A deterministic mapping turns input into output the same way every time, and what returns from a run is a new artifact generated from the input, different next week from the same source. Nothing accumulates that an operations team could inherit. Tasks are real objects with identifiers and their own addresses, and there is a management view, but what the object carries is the instruction plus the cadence, with no declared scope over which tools or connectors a run may touch. Rebuild cost is retyping the sentence. The layer asks for pipelines and what ships is movement performed by an agent. The topology is the cleaner reason. At this layer Perplexity is the client. Its agent calls into the enterprise's systems, and the path has no downstream edge: no stage another system consumes, no destination it lands in, no artifact that outlives the run. A run ends with a person reading an answer or the same agent writing back through another connector. The API platform inverts that relationship and is scored where it performs its function, at 1B and 2B. This is not a vendor missing a pipeline product. It is a surface with no place for a pipeline to attach. The real-dependence guardrail does not trigger, and OpenAI is the direct precedent: scheduled tasks and connector sync did not lift that row off gap either.

Borrowed Judgment

None at the layer's architectural function. Pipeline definitions, transformations, scheduling semantics, lineage and destination choices remain in the enterprise's integration stack. What the enterprise does inherit, per run, is the model's decision about what to move, which is judgment rather than pipeline authority and cannot be stated in advance.

Working Notes

Watch-list, August 2026: Agent API Connectors are in preview, covering GitHub, Slack, Google Drive and Datadog, with live per-request access and no synchronization. At general availability the API side gains a live access path, still not movement. Computer's runtime, sandbox, subagents and scheduling are scored at 2B, the connector estate at Layer 3, and file-connector sync into the index at 1B. Unresolved detail, carried rather than asserted: help-center material states that stopping a scheduled task deletes it permanently with no paused state, while release-note material describes pausing. Fact question: does a scheduled task carry any declared, inspectable scope over the tools and connectors a run may touch, or only the instruction and the cadence?

Layer 2A · OrchestrationInfrastructure OrchestrationSpend-Earned Tiers, No Customer Plane

GPU scheduling, quotas, RBAC, fair-share scheduling, utilization optimization

Vendor-Provided

NVIDIA-Provided

No NVIDIA Layer 2A Dependency

Scheduling across the serving fleet is Perplexity's own operation and never surfaces to a customer. The only piece of that machinery the public can touch is an open-source transfer library, which is communication rather than orchestration.

Gap Analysis

Capacity arrives without being asked for, and there is no surface on which to have an opinion about it. The API runs six usage tiers earned by cumulative lifetime spend, from Tier 0 at zero through Tier 5 at five thousand dollars, kept permanently with no downgrade. Rate limits are per endpoint and per tier: the Agent API scales from one query per second at Tier 0 to thirty-three at Tier 5, the Search API is flat at fifty query units per second for everyone, and embeddings run from eighty-five to three hundred thirty-five. A leaky bucket permits bursts. Above Tier 5 the path is a request form. On the application side, Enterprise organizations on annual agreements get credit limits per group, custom roles, identity-synced groups and usage analytics. None of that is a customer plane. The architect cannot reserve capacity, cannot set a programmatic spend cap, cannot prioritize one workload against another, and cannot see utilization. Allocation is a function of what the account has historically spent, which is the vendor's fair-share policy applied to the customer without the customer's participation. The call matches OpenAI's metered consumption and Anthropic's token quotas, and this apparatus is thinner than both. Neither peer exposes a scheduling plane either, and both document capacity paths this row does not: there is no provisioned throughput, no priority tier, no reserved capacity, and no customer-set spend cap anywhere in the API documentation. Databricks ships generally available spend caps in its gateway. Here the buyer cannot cap their own bill through the interface.

Borrowed Judgment

Total and invisible. Every scheduling, prioritization and capacity decision is the vendor's, expressed to the customer as a rate limit and a tier. The tier system encodes a durable judgment about who deserves throughput, based on purchase history rather than workload, and the customer has no instrument for arguing with it.

Working Notes

Credit limits, tiers, roles and usage analytics are named here as sub-threshold platform administration rather than scored capability, matching how the peers' metering apparatus was treated. Watch-list, August 2026: the Router API is in private preview and distributes traffic across deployments on observed error rates, capacity and latency, with automatic failover. That is the vendor's reliability engineering rather than a customer plane, and it stays unscored on both counts. Also dated: the Sonar API is marked deprecated with a documented migration to the Agent API. Fact question: does an enterprise API agreement add reserved capacity, provisioned throughput or contractual spend caps? A negotiated commitment is a contract term rather than a customer-administered plane and would not move the cell.

Layer 2B · RuntimeApplication Runtime & ExecutionBrokered Serving, Hosted and Local Runtimes

Model serving, agent execution, inference APIs, distributed inference

Vendor-Provided

Model Access via the OpenAI-Compatible InterfaceDelegated

Generally available. First-party models and brokered frontier models from OpenAI, Anthropic, Google and xAI, consumed through an interface an existing OpenAI client reaches with a base-URL change. Under the inference-interface standards rule, model access through a genuine multi-vendor standard is Delegated, and a proprietary serving implementation behind it is Delegated for that interface. The residual switching cost is prompt and evaluation recalibration, graduated by how much application logic lives in deterministic code outside the model.

Agent API Platform Surface (Hosted Tools, Sandbox, Presets, Skills, State)Ceded

Generally available. Everything accumulated beyond the interface: hosted search and fetch and finance tools, the container sandbox, effort presets, the built-in skills catalog, wide research, background mode and conversation state. These are the vendor's opinions about how a run should behave, they have no portable form, and an application built against them does not lift to another platform.

Perplexity Computer (Hosted Agent Runtime)Ceded

Generally available. The hosted agent: subagents, connector-backed tool use, code execution, artifact production and scheduled runs. Runtime altitude, the same call the instrument makes for Codex and Claude Code. The orchestration, tool scoping and depth policy are proprietary and do not lift out.

Remote MCP Servers as Agent API ToolsDelegated

Generally available. The inbound path: a customer's own protocol server attaches to a run and the model invokes its tools. The Model Context Protocol is a genuine multi-vendor standard now stewarded outside any single vendor, so tool integrations written against it run against other vendors' runtimes without rebuilding.

Custom Functions (Client-Side Execution)Retained

Generally available. Functions declared by schema and executed in the customer's own process, on the customer's own infrastructure. The business logic, the validation code and the execution environment never leave the enterprise, which is the seam where deterministic code outside the model does its work.

Portable Computer (Local Agent Harness)Ceded

Generally available August 25, 2026, Linux first, on customer-owned NVIDIA hardware. The harness around the model: orchestration, tool scoping, depth limits and the approval flow. Self-deployable is not Retained. None of it lifts to another platform and there is no outbound interface that would let another system drive it. The weights it serves are scored separately, because they do lift.

Locally-Served Open Weights (Portable Computer)Retained

The open-weight Qwen checkpoints Portable Computer serves, run under a published inference engine on hardware the enterprise owns. Bench work established that the serving configuration runs standalone with no vendor application present, which is the open-substrate path to Retained and the same treatment open-weight models receive on the OpenAI row. The limit is stated rather than assumed: what was demonstrated is that the serving stack runs without the application, not that the checkpoint stays licensed and usable after a subscription lapses.

pplx-garden / TransferEngine (MIT)Retained

Open source under MIT and running in Perplexity's own production serving. A point-to-point communication library for disaggregated inference reaching 400Gbps across NVIDIA ConnectX-7 and AWS Elastic Fabric Adapter, with a mixture-of-experts dispatch kernel alongside it. The enterprise can operate it with no vendor present and take it anywhere, which is the open-substrate path to Retained, on the precedent that scored open-weight models at the runtime layer.

NVIDIA-Provided

Transmitted NVIDIA Dependency at the Local Runtime

This is the row's one real NVIDIA entry and it is customer-facing. Portable Computer requires NVIDIA hardware with at least 24GB of memory, from GeForce RTX cards through RTX Pro workstation parts to DGX Spark, and shipped August 25, 2026 in partnership with NVIDIA. An enterprise adopting the local product buys NVIDIA silicon to run it. Everything else on this row transmits no NVIDIA exposure at all.

Gap Analysis

The Agent API is generally available and speaks the OpenAI Responses interface: point an existing OpenAI client at the Perplexity endpoint with a Perplexity key and response creation routes through unchanged. Through it a customer reaches Perplexity's own models by preset and third-party frontier models by name, including OpenAI, Anthropic, Google and xAI. Built-in tools cover web search, URL fetch, finance search, people search, and a sandbox that runs code in an isolated container. Remote protocol servers attach as tools, custom functions execute on the client side, and the surface carries skills, wide research, background mode, structured output, files, conversation state and model fallback. Perplexity Computer is the hosted agent on that runtime, with subagents, a large connector estate and scheduled runs, and its protocol server makes it drivable by an external agent. Portable Computer shipped August 25, 2026 as a local runtime on customer hardware, Linux first, running open-weight Qwen checkpoints under a patched inference engine with an operating-system-enforced sandbox. The whose-paper rule carries the model access. A customer deploys frontier models from four vendors on Perplexity's paper with Perplexity's support, and that counts in full, exactly as every original equipment manufacturer scores strong at Layer 0 on NVIDIA silicon. Ownership is the authority axis's question, not the capability axis's. Add a generally available agent runtime with sandboxed execution, a hosted agent with a real connector estate, a local runtime on hardware the customer owns, and the transfer library running the vendor's own production fleet, and this stands with the OpenAI and Anthropic strongs. It is broader on model access than either and thinner on first-party frontier capability, and both halves belong in the reading. Scope gate named rather than hidden: the local runtime is two days old at publication, Linux only, with Windows announced for September and no macOS plan, and it requires a paid subscription. It does not carry the cell on its own, and the cell does not rest on it.

Borrowed Judgment

Mixed, and the mix is the finding. Real exits exist and they are load-bearing: model access through a standard interface that other vendors implement, protocol servers the customer writes and hosts, tool functions that execute in the customer's own process, and an MIT-licensed transfer library the customer can operate with no vendor present. What does not lift out is everything shaped like a platform. The hosted tool surface, presets, skills and conversation state are the vendor's opinions and hold no portable form. Both agent runtimes, hosted and local, are proprietary harnesses with no outbound interface to drive them. Running the local one on hardware you own gives operational control, not authority. The weights underneath the local harness are the exception and they are scored as their own Retained component, because the local serving stack was shown to run standalone with no vendor application present.

Working Notes

Watch-list, August 2026: the Router API is in private preview, hosting open-weight models including DeepSeek, Kimi, GLM and Nemotron behind chat completions, Responses and Messages endpoints, with health-based failover across deployments. At general availability it lands here as serving rather than at 2C, because the caller still names the model. Also dated: the Sonar API is deprecated with a documented migration to the Agent API. The local runtime's memory floor is stated as 24GB in some coverage and 32GB in other coverage; the requirement is recorded as NVIDIA hardware with at least 24GB and the ambiguity is named rather than resolved. Interface ruling recorded on this row: the Responses interface qualifies under the inference-interface standards rule. Enumeration on August 27, 2026 returned independent implementers beyond Perplexity: vLLM serves the responses endpoints, Azure OpenAI serves them through its v1 generally available API, and the Open Responses specification (April 24, 2026) defines the interface for multi-provider use. The frontier model family released against it accepts only that endpoint and rejects chat completions, so the interface is displacing the ratified one rather than sitting beside it.

Layer 2C · ReasoningAgentic Infrastructure — The Reasoning PlaneProduct Controls, Not a Reasoning Plane

Policy-driven placement and resource coordination — the Autonomy Layer

Vendor-Provided

NVIDIA-Provided

No NVIDIA Layer 2C Dependency

Nothing NVIDIA supplies governs an agent here. The near-empty column continues.

Gap Analysis

This row ships more first-party agent control than either peer and still lands on gap, which makes the reasoning worth stating carefully. Comet Enterprise puts administrative control over what the assistant may do inside the browser, deployable silently through mobile device management across macOS and Windows, with hundreds of browser policies behind it. Organization settings carry a model and provider permission, retention policy, enforced incognito mode and audit configuration. Custom roles give granular permissions, identity-synced groups carry membership, and credit limits apply per group. Audit logs claim end-to-end capture across user input, agent steps and answers, delivered in real time to a webhook. Compare that to OpenAI, whose 2C cell records that the governance job belongs to Microsoft's control planes, and to Anthropic, whose answer is interception hooks and validators the customer writes. Three rules decide the cell and they agree. The GA-gate cuts both ways: general availability of the wrong function moves nothing, and function fit is judged against the layer's purpose line rather than the feature's name. Everything above governs Perplexity's agents inside Perplexity's clients. None of it is a plane the enterprise points at its own agent estate, which is what lifted Databricks into the moderate cohort, where agents, tools and protocol servers register as governed assets including the customer's own. Browser policy over the vendor's assistant is endpoint management wearing the layer's vocabulary. Routing is not reasoning handles the placement half. There is no live per-request placement anywhere in the generally available surface. The routing that exists distributes traffic across deployments of a model the caller already named, on error rates, capacity and latency, and it is in private preview besides. That is single-variable reliability engineering and a fixed-function slice of multi-variable policy placement even after it ships. The determinism rule covers the rest. On the API side the governance surface is the caller's own code: the developer enables tools per request, an administrator scopes connectors once at the group level, and everything beyond that is whatever the enterprise writes for itself. Audit logging speaks only to the record, after the fact. A record of what an agent did is never a control over what it may do, so no expansion of the logging surface moves this cell.

Borrowed Judgment

None at the layer's architectural function, and that is a finding rather than a compliment. The enterprise inherits nothing here because nothing is offered here, so the responsibility for registering, scoping, constraining and validating an agent estate stays with the enterprise, discharged today by other vendors' control planes or by code the customer writes. What the enterprise does inherit, inside the vendor's own clients, is the vendor's judgment about which actions are safe, expressed as product settings it can toggle but cannot author.

Working Notes

Watch-list, August 2026: the Router API is in private preview and lands at 2B at general availability rather than here. The CrowdStrike Falcon integration for Comet Enterprise is announced as opt-in with no general availability date stated in the release. The audit log's record shape is undocumented. Corroborating evidence, Layer2C Labs Lab 019, 'Local-first is not control-first' (August 26, 2026, https://labs.layer2c.com/labs/local-not-control): a seven-part acceptance test for programmable governance, subject, capability, scope, condition, duration, authority and record, run against the local product's sandbox-exit gate, where none of the seven could be represented. The lab tested the local product rather than the estate this cell grades, and its acceptance test is lab-derived rather than canon, so the cell is graded on the instrument's own rules and the lab is cited as evidence. Fact question: does any enterprise agreement expose a policy object at organization level that binds a rule to a subject and a capability with a scope and a duration, and survives the session? Everything found configures a product. Nothing encodes a standing decision.

Layer 3 (+1) · ApplicationsAI Application Layer — The Value PlaneFirst-Party Value Plane: Answers, Browser, Agent

AI-powered business capabilities — business logic, workflow automation

Vendor-Provided

Perplexity Enterprise (Answer Engine, Spaces, Internal Knowledge Search, Verticals)Ceded

Generally available on Enterprise Pro and Enterprise Max seats. The answer engine with shared workspaces, internal knowledge search across connected sources, and vertical surfaces spanning discovery, finance, health, patents and academic research. The accumulated asset is the organization's working context, and it has no export that reconstitutes it anywhere else.

Comet and Comet Enterprise (AI Browser)Ceded

Generally available, free for individuals since March 2026, with an enterprise edition adding managed deployment, browser policy and administrative control over agent actions. The assistant operates inside the user's authenticated sessions, which is reach no connector inventory records. The browser, its policies and the assistant's behavior are entirely the vendor's and lift nowhere.

Perplexity Computer (Agentic Knowledge Work)Ceded

Generally available. The agent as an application: artifacts, subagents, scheduled work, document and media production, and action across a connector estate exceeding four hundred services. Application altitude, distinct from the runtime scored at 2B. What accumulates is task definitions, connected accounts and the delegation pattern of the organization.

Portable Computer (Local-First Application)Ceded

Generally available August 25, 2026 on customer hardware. The application is always the caller and never the callee: no public interface, no command line that drives it, nothing to embed, so the workflow cannot be composed into anything the enterprise already runs. Local execution moves where the work happens. It does not change who holds the application.

Computer MCP Server and Bring-Your-Own ConnectorDelegated

Generally available. The outbound seam, and the one place the client relationship inverts: an external protocol client sends work to Computer, handles its questions and approval checkpoints, and receives results, while customers wire internal systems in over the same open protocol without waiting for an official integration. Written against a genuine multi-vendor standard, so the integration survives a change of vendor.

Customer-Authored Inline SkillsRetained

Instructions the customer writes and sends with the request, up to 65,536 bytes, so the artifact lives in the customer's own repository and travels anywhere. Thin by construction, and the cell says what it is not: no files, no dependencies, no sandbox mounts, no reusable library, and never returned in the response. This is a system prompt you keep, not a portable skill format.

NVIDIA-Provided

No NVIDIA Layer 3 Dependency

The application estate is software. The hardware requirement rides on the local runtime and is carried at 2B.

Gap Analysis

This is the widest first-party application estate of the three model-vendor rows, and it includes one surface neither peer has. Perplexity Enterprise carries the answer engine, shared Spaces, Internal Knowledge Search and a vertical menu spanning discovery, finance, health, patents and academic research. Finance is the deep one, with a market heatmap, an earnings hub, a natural-language screener, linked portfolio tracking, price alerts and automated tasks, and the company states more than three quarters of paying users touch it. Comet is a full browser with an assistant in it, free since March 2026, with Comet Enterprise adding managed deployment and administrative control over agent actions. Computer is the agentic surface: artifacts, subagents, scheduled tasks, document and media production, task management across the common engineering and knowledge-work tools, and deployment of what it builds. Portable Computer puts a version of that on hardware the customer owns. Pegged against OpenAI's assistant-altitude estate and Anthropic's enterprise, coding and agentic applications, this stands with both. It is ahead on surface diversity given the browser and the verticals, and behind on developer-application depth, since there is no first-party coding agent at the altitude of Codex or Claude Code. The browser deserves naming rather than tucking into a component. An assistant living inside the browser inherits every authenticated session the user already has. No connector, no authorization grant, no administrative approval, and no line in anyone's integration inventory. The reach is the user's own reach, and the enterprise's visibility into it is whatever the vendor chooses to log.

Borrowed Judgment

High and compounding, with two narrow exceptions that are worth architecting around. Four of the six components are the vendor's applications, and what accumulates inside them is the record of how the enterprise works: spaces, connected sources, saved context, task definitions, and the habits of delegation, per user, per day. Swapping the model underneath moves none of it. The exceptions are real. The protocol server makes the estate callable from outside, so the workflow can be composed into something the enterprise already runs. Customer-authored skills are text the customer holds. Everything else assumes the enterprise comes to the application rather than the application coming to the enterprise.

Working Notes

Platform mutability, dated: Perplexity Tasks was replaced by Scheduled Tasks inside Computer, and the Sonar API is deprecated in favor of the Agent API. The primitives persist while the wrappers turn over on a schedule, the same finding the OpenAI row carries, and it is an architecture caution rather than a capability deduction. The finance usage figure is vendor-stated. Skills general availability is inferred from production documentation rather than an explicit designation.

Summary Finding

Perplexity sells judgment, not infrastructure, and it prices that judgment per call. The row reads gap at Layer 0, 1A, 1C, 2A and 2C, moderate at 1B, and strong at 2B and Layer 3. That shape puts it in the same cohort as OpenAI and Anthropic, with one difference that matters. Those two sell intelligence and let you assemble around it. This one sells an assembled opinion about how the work should go. Presets that decide how much effort a run deserves. A classifier that decides how much searching a question needs. A ranking that decides what counts as an answer. The mechanisms underneath are largely other people's, from the frontier models it brokers to the open weights it hosts to the web itself.

The two customer-facing surfaces point in opposite directions, and the row turns on that. Where Perplexity is the served component, at retrieval and inference, an enterprise can build on it. The Search API returns raw ranked results for your own pipeline, the Agent API answers an OpenAI client with a base-URL change, and Computer takes work from an external agent over the Model Context Protocol. Where Perplexity is the client, at data movement, there is nothing to build on. Its 400 connectors exist so the agent can reach into systems that already hold the data, and a run ends with a person reading an answer or the same agent writing back through another connector. No stage another system consumes, no destination, no artifact that outlives the run. The data never moves. The decision does.

Layer 1B is the cell that explains the rest. Perplexity exposes its own production web index as a generally available API, past 300 billion pages by its own account, with content extraction, domain and language filters, and a published evaluation framework beside it. On its own terms that capability is strong. It scores moderate because of where the surface sits. There is no index the customer administers, no vector store, and no hybrid retrieval over the enterprise's own corpus, so an architect cannot build what peers building on AWS, Databricks, Palantir or VAST can build. Nothing here is deficient. The primitive is exposed above the altitude where the building happens, and the instrument grades capability against the market rather than against the vendor's own ambitions.

At 2C the row ships more first-party agent control than either peer and still lands on gap. Comet Enterprise governs what the assistant may do, mobile device management pushes it silently, CrowdStrike Falcon watches the data movement, custom roles and SCIM carry identity, and audit logs claim capture across agent steps. All of it governs Perplexity's agents inside Perplexity's clients. None of it is a plane the enterprise points at its own agent estate, and a log of what an agent did is never a control over what it may do. Live per-request placement is absent here as it is nearly everywhere, and the routing that does exist distributes traffic across deployments of a model the caller already named.

The capture is decoupled and the doors are all on one side. You can bring your model, your client, your agent, your own protocol server, and Perplexity documents every one of those paths. What has no door is the value: the index, the ranking, the embedding space, the answer. The browser is the sharpest version. An assistant living in Comet inherits every session the user is already signed into, with no connector, no authorization grant, and no line in anyone's integration inventory. The local product inverts the usual reading and is worth understanding precisely. The weights are portable, and the lab that tested it reproduced the local stack standalone with no vendor application present. The harness around them is not portable, and it exposes nothing that would let another system drive it.

The buyer's trade: the best web retrieval sold anywhere, a genuine agent runtime hosted and local, four vendors' frontier models on one invoice, and an application estate that reaches into the browser. In exchange, the data plane stays entirely the enterprise's problem, the reasoning plane stays the enterprise's problem, capacity arrives as a function of lifetime spend with no way to reserve it or cap it, and the judgment the buyer accumulates has no exit. The exits that do exist are real, and they are all day-one architecture decisions. Keep the application logic in deterministic code outside the model. Drive Computer over the protocol rather than living inside it. Hold your skills in your own repository. Take the default path instead and what compounds is somebody else's opinion, arriving as an answer, with the reasoning behind it unavailable for review.

4+1 Layer AI Infrastructure Model · Vendor Assessment Series · The Advisor Bench LLC · thectoadvisor.com