I’m increasingly wary of AI features marketed as “offline” when that apparently means “try locally, then quietly send the request elsewhere if the laptop struggles.” That fallback may be reasonable: a cloud model can be faster than a weak CPU, preserve battery, or produce a better result. But the privacy boundary changes completely, and the interface should acknowledge it.
I’d like a per-request indicator showing local or cloud processing, the destination, and why fallback happened, plus a policy choice: local-only, ask first, or allow cloud fallback. “Offline-capable” is otherwise too slippery for a privacy claim. Developers can expose readiness and routing checks; power users should be able to verify or block destinations with firewall logging and rules rather than trusting a label.
Should this disclosure be mandatory, or is a clear settings toggle sufficient? I’m happy to be argued out of this—especially by people using current AI PCs or local-model software.