'Local' Solves Where Your Data Goes. It Doesn't Solve What Your Agent Does
Local models (Gemma 4, GLM-5.2, Qwen 3.6) now enable on-prem agents, but 'local' only ensures data sovereignty, not safety. Prompt injection remains an architectural flaw (85% success rates, OWASP #1), and indirect injection from local files becomes harder to detect inside the trusted perimeter. Privilege escalation and provenance failures also survive the move, making local agents safe only for bounded, trusted-input tasks.