explainx.ai0k
TrendingAI News TodayPathwaysSkills
Pricing
explainx.ai

Upskill in AI — 16 free pathways, live workshops & bootcamps, and 50+ courses from practitioners. Plus the skills, tools, and MCP servers to practice on.

follow us

follow on google

Add explainx.ai as a preferred source

corporate training

support@explainx.ai

get started

Find your pathTake Free Evaluation

community

Join the community

learn

mind: share how you thinkpathways — start freeworkshopsbootcampscoursescompare Explainxcertificationsmock testsexplainx universitycorporate traininglearn skills & mcp

discover

skillsmcp serversexplainx mcptoolsmdx readeragentsllmsdesignsdictionarypeopleagi trackerfelony benchranks

company

aboutvisionmissionteaminstructorsteach on explainxpartnershipscommunityhackathonscareers

content

daily AI newsstate of AI — live resultsblogreleasespromptsgeneratorsresource libraryfor LLMsexplainx.ai kids

solutions

all solutionsdeveloper upskillingmarketing upskillingproduct manager upskillingleadership upskilling

newsletter · weekly

Get AI news, tools, and insights in your inbox.

supportcontactprivacytermsdata rightshow we create contentsubmission guidelines

© 2026 AISOLO Technologies Pvt Ltd

explainx.ai

On this page

  • TL;DR
  • What Underdog actually is
  • What "private" means (and what it does not)
  • How Underdog differs from Muse, Dots, and OpenClaw
  • Who can access it
  • a16z, Anthropic, and the funding headline (without writing a fundraising post)
  • What people are asking
  • Honest limitations
  • Builder checklist: should you try it this week?
  • Related reading
← Back to blog

explainx / blog

Underdog Private Personal AI: On-Device Privacy Architecture Explained

Personal AI, Local AI, Privacy, Apple Silicon, AI Agents

Underdog runs personal AI on your Mac — local models, Secure Enclave vaults, no cloud LLM. How "private" differs from Muse and Dots.

Oct 3, 2026·13 min read·Yash Thakker
add explainx.ai
go deep
Underdog Private Personal AI: On-Device Privacy Architecture Explained

Personal agents hit a fork this week that builders should actually care about: where the intelligence runs. Meta's Muse and OpenAI's Dots put a capable agent in a remote computer you do not own. Conway Research's Underdog takes the opposite bet — a personal AI that runs on the Mac you already paid for, with models under 4GB, offline use, and a hard line that your inbox and meeting audio are not shipped to a cloud LLM for processing.

On October 2, 2026, Andreessen Horowitz published that it is leading Conway Research's first funding round. Feed headlines immediately mashed that with "Anthropic" because founder Sigil Wen was an early Claude tester. That is a relationship, not a co-lead. The shippable product is the story: a free, invite-only Mac beta with local email, calendar, notes, dictation, and browser errands behind human approval. If you already track the personal-agent stack on explainx.ai — Muse's Sentinel VM, Dots at DevDay, OpenClaw — Underdog is the clearest consumer-facing "local by default" alternative in that comparison set.

TL;DR

table · 2 cols
QuestionAnswer
What shipped?Underdog — Conway Research's on-device personal AI for Apple silicon Macs
What does "private" mean?Local inference + on-device memory/transcripts; vault keys in Secure Enclave — not a remote enclave, not a VPC
Who can use it?Invite-only beta; Mac with Apple silicon today; other OS builds waitlisted
Cost?Positioned as free (your hardware does the work); no seats/servers to rent
vs Muse / Dots?Those are cloud agents with frontier models; Underdog keeps AI processing on-device
vs OpenClaw?OpenClaw is open-source self-host; Underdog is a polished consumer app with its own models
a16z / Anthropic?a16z led the first round; Anthropic is founder lore (early Claude tester), not listed as investor
Why builders careA real product path for personal context without sending mail/notes to a cloud LLM

Local personal AI workflow on a Mac — on-device models and private memory

What Underdog actually is

Underdog is Conway Research's first product. Conway describes itself as a frontier lab building efficient models, inference engines, and personal AI for devices people already own. The public thesis is blunt: most AI will run on the device, not in a data center, and "today's frontier intelligence reaches your devices in six months" (their "Underdog's Law").

The product site's claim set is specific enough to evaluate:

  • 100% local AI for summaries, drafts, and answers — content is not sent to a cloud AI service for processing
  • Under 4GB on disk for the local model package
  • Direct mail sync with Gmail and Outlook (provider sync is not the same as uploading mail to an LLM API)
  • Meeting notes and dictation transcribed on device
  • Browser errands (flights, reservations, groceries, subscription cancels) with explicit approval before book/buy/cancel
  • Calendar connected to Google Calendar and Outlook Calendar
  • Inspectable memory you can see, edit, or delete in Settings
  • Per-account AES-256-GCM vaults with keys in Apple Keychain, secured by the Secure Enclave

That is a product architecture, not a pitch deck slide. Husky — Conway's model-specific inference engine for the Woof 4B weights — is already live in the Mac app according to their September 20, 2026 technical writeup, with published decode numbers against MLX on M5 Max hardware.

What "private" means (and what it does not)

When a feed says "private personal AI," three different architectures get collapsed into one word. Separate them before you pick a stack.

Local on-device (Underdog's claim)

Inference runs on your Mac's Apple silicon. Recordings, notes, transcripts, and saved memories stay on the machine. Vault encryption keys are intended to never leave the device, with Secure Enclave backing via Keychain. You can use the assistant offline for the AI parts that do not need the network.

Network still exists for the jobs that require it: syncing mail with your provider, sending a message you approved, loading a booking site in the browser automation path. Privacy here means your content is not the training or inference payload of a third-party cloud LLM, not that the Mac never opens a socket.

Remote confidential enclave / confidential VM

This is the "even the vendor cannot read your VM" direction Meta has talked about for a future Muse Confidential VM — cryptographic isolation in a remote machine. Underdog is not that. It does not need to be: the machine is yours. The trade-off is different — you trust your laptop's OS and disk encryption instead of a cloud TEE.

Vendor VPC / cloud PC (Muse, Dots)

Muse runs a per-user Secure VM with a Sentinel permission broker. Dots gives each agent a cloud computer and browser. Both can be "private" relative to other tenants and can be strong on credential isolation — while still running inference and agent state in infrastructure you do not physically control. That is a different trust model from Underdog's "the model file lives under 4GB on your SSD."

explainx.ai's read: if your threat model is "I do not want my doctor's appointment transcript inside a frontier lab's training or ops pipeline," local inference is the matching architecture. If your threat model is "I need a 24/7 agent smarter than a 4B on-device model while I'm offline from my laptop," Muse/Dots still win on capability and always-on compute.

How Underdog differs from Muse, Dots, and OpenClaw

Name the products; keep the links on explainx.ai's own coverage.

table · 5 cols
DimensionUnderdogMuseDotsOpenClaw
Where intelligence runsYour Mac (Apple silicon)Per-user cloud Secure VMCloud PC per agentYour machine / VPS (self-host)
Model ownershipConway's on-device models (e.g. Woof)Muse Spark familyGPT-6 AstraBring your own model/API
Default privacy storyLocal processing + Secure Enclave vaultsSentinel + credential surrogationHosted agent + pluginsYou configure storage and keys
Always-on when laptop closedNo (device must run)YesYesOnly if your host is up
Access todayInvite-only Mac betaConsumer app / plansPro / Business Premium rolloutOpen source install
Cost modelFree (hardware pays)Free tier + paid plansBundled with eligible plansSoftware free; you pay compute

For the broader five-way hosted-vs-self-hosted map, see Dots vs Grok Bot vs Muse vs OpenClaw vs Hermes. Underdog sits closer to the self-hosted privacy column than to Muse/Dots — but it is a closed consumer app with first-party models, not an MIT gateway you wire to Claude or a local llama.cpp server.

If you are evaluating Muse specifically for safety and ads tension, pair this post with Is Meta Muse safe?. If you want the DIY local path without Conway's app, building a personal AI system on a local workflow and OpenClaw's guide remain the open stacks. For raw local inference horsepower on a high-memory Mac this week, DwarfStar ds4 is a different tool: it runs large open models you choose, not a personal-life agent product.

Who can access it

Availability as of October 3, 2026, from the product FAQ:

  1. Mac with Apple silicon — downloadable today inside an invite-only beta that "gets better every day."
  2. iPhone, iPad, Windows, Android, Linux — not shipping yet; waitlist collects one email per platform when a build is ready.
  3. Pricing — marketed as free forever for the Mac product because your computer does the inference. Treat that as a product promise, not a perpetual legal covenant; early-stage pricing can change, but there is no published seat or token meter today.

Practical implication for teams: you cannot put Underdog on a Linux CI box or a Windows laptop yet. The privacy architecture is tied to Apple silicon and Apple's Keychain/Secure Enclave story. That is a feature for Mac-heavy individuals and a hard constraint for heterogeneous fleets.

a16z, Anthropic, and the funding headline (without writing a fundraising post)

a16z's October 2, 2026 note — by Chris Dixon, Gabriel Vasquez, and Elizabeth Harkavy — says the firm is leading Conway Research's first round and partnering with Sigil Wen as he builds Underdog. Round size and valuation were not disclosed in that post. Secondary coverage has also named other investors; treat those as press reports unless Conway confirms them.

Anthropic is not described as a backer in a16z's announcement. The Anthropic mention in the founder narrative is that Anthropic cofounder Ben Mann invited Wen to become one of the earliest testers of what became Claude. That is interesting biography. It is not "Anthropic funded Underdog." If a feed headline said both names as backers, correct it: a16z led; Anthropic appears as early-access relationship lore.

The product motivation a16z and Wen both emphasize is personal: years ago, a bug in a popular email app exposed privileged mail stored on the app's servers. Underdog's design — direct provider sync plus local AI processing — is the architectural reaction to that class of failure.

What this means for what you build

Funding does not change your stack by itself. The product does. If Conway has capital and a shipped Mac beta with local mail/notes paths, builders should update a few decisions:

  • Personal-context prototypes can target a local agent surface instead of defaulting to "upload the inbox to a cloud agent." That matters for health, legal, tax, and HR side projects where sending transcripts to a frontier API is a non-starter.
  • Approval-gated browser automation is now a consumer pattern (Underdog) as well as a security pattern (Muse Sentinel / Dots plugins). If you are building agent UX, assume users will expect a confirm step before book/buy/cancel — Underdog makes that the default story.
  • On-device model + MSI (model-specific inference) is a competitive lane. Husky's pitch is not "another MLX wrapper"; it is compile-time specialization for one model. If you ship Apple silicon apps, specialized engines may beat general runtimes on the edit-heavy workloads personal agents actually do.
  • Do not wait for Anthropic to "bless" this category. The Claude connection here is historical. Capability competition is Muse Spark / GPT-6 Astra in the cloud versus small local models that stay yours.
  • Platform lock remains real. Designing only for Secure Enclave + Apple silicon means your privacy win is Mac-shaped until the waitlisted builds land. Hybrid designs (local for sensitive notes, cloud for hard reasoning) will stay common — see the same split in local personal AI workflows.
Weekly digest3.5k readers

Catch up on AI

Curated AI updates on agents, skills, and MCP — delivered to your inbox. Unsubscribe anytime.

What people are asking

Is Underdog "as smart as" Muse or Dots?

No, not on hard open-ended reasoning. Underdog's own positioning admits the model may not top leaderboards. The bet is loyalty and locality: a small model that sees your real context on your disk without that context becoming a cloud prompt. For coding agents and research, you will still reach for frontier APIs or a larger local runtime. For inbox triage, meeting notes, and dictation, a fast 4B on M-series hardware can be enough if latency and privacy dominate.

Does mail ever leave my Mac?

Mail syncs with Gmail or Outlook the way a normal mail client does. AI drafts and summaries are claimed to run locally. Messages you send go to recipients. That is ordinary client networking, not "your vault was uploaded to Conway's GPU cluster" — but it also means a compromised mail provider or a phishing site you approved still sits outside Underdog's vault story. Local AI is not a substitute for provider security.

Can I run it fully offline?

AI processing that only needs local weights can run without wifi, per Conway and the Husky writeup. Anything that needs live mail sync, calendar sync, or a live booking site still needs the network. Offline is a mode, not a lifestyle, unless you already downloaded what you need.

How does this compare to OpenClaw for developers?

OpenClaw is the open gateway: you pick models, channels, and hosting. Underdog is opinionated consumer software with Conway's models and Husky baked in. Developers who want MCP-style extensibility and self-host control still want OpenClaw (or Hermes). Individuals who want "install the Mac app and keep meeting audio local" are the Underdog audience. The five-way comparison post already frames hosted vs self-hosted; add Underdog as a third column — hosted locally by the vendor's app, not by you compiling a gateway.

Is the Secure Enclave claim enough?

It is a strong Apple-platform story for key storage. It is not a formal third-party audit published in the materials reviewed for this post, and it does not stop malware running as your user from reading decrypted material the app has in memory. Treat it as better than "API key in a plaintext config," not as a TEE proof against a rooted machine. For agent sandbox failures in the cloud camp, reread Muse's Sentinel design and the safety verdict — different failure modes, same lesson: architecture beats marketing adjectives.

Honest limitations

  • Invite-only beta — download exists, but access is gated; do not plan a team rollout on "it is free on the website."
  • Apple silicon only today — no Windows/Linux agent laptop story yet.
  • Small model ceiling — local privacy does not create Opus-class reasoning on a 4B.
  • Browser automation still needs judgment — approval gates help; they do not stop you from approving a bad action.
  • Funding opacity — first-round leadership is public; check size, dilution, and commercial terms yourself if you are investing, not building.
  • Anthropic headline inflation — correct it when you cite the story; relationships are not term sheets.

Builder checklist: should you try it this week?

  1. You are on an Apple silicon Mac and can get an invite.
  2. Your pain is personal context (mail, meetings, dictation) more than hard coding agents.
  3. You refuse to put that context into Muse/Dots-class cloud agents for now.
  4. You accept a smaller model and Mac-only availability.
  5. You still keep a frontier coding agent (Claude Code, Codex, etc.) for work that needs it.

If (2) and (3) are false, stay on Dots or Muse and use this post only as a privacy-architecture reference. If you want open-source control, start with OpenClaw.

Related reading

  • Meta Muse personal agent + Sentinel VM security
  • OpenAI Dots always-on agents at DevDay 2026
  • What is OpenClaw? Personal AI assistant guide
  • Dots vs Grok Bot vs Muse vs OpenClaw vs Hermes
  • Is Meta Muse safe? Honest verdict
  • Build a personal AI system on a local workflow
  • DwarfStar ds4 local inference on Mac
  • Official: Underdog product site, Conway Research, a16z announcement, Husky inference notes

Details on Underdog's beta access, model sizes, Husky benchmarks, and Conway's funding are accurate as of October 3, 2026. Invite gates, platform availability, and pricing promises can change without notice — verify on the official product site before you commit a workflow.

Update — October 3, 2026: Related: Apple's Full Disk Access changes for AI agents, and ChatGPT Finances for Free and Go users for the cloud-connector side of personal data.

Spotted something out of date? Let us know.
Yash Thakker

Written by

Yash Thakker

Yash is an AI expert with over 300K learners. Join his workshops →

View Yash Thakker in People in AI →

Related posts

Sep 1, 2026

Perplexity Mac Hybrid Compute: Local Models for Sensitive Agent Steps

Aravind Srinivas announced hybrid compute for every Perplexity Mac app user on September 1, 2026: Computer orchestrates local Apple Silicon models for sensitive agent steps while cloud handles the rest. Perplexity open-sourced a ~600M Qwen3 PII classifier on Hugging Face and published PII-TRACE research — explainx.ai breaks down routing, privacy limits, and how it compares to DGX Spark local demos.

Oct 3, 2026

Apple to Tighten Mac Full Disk Access for AI Agents After Meta Muse Messages Dispute

After an Inc columnist said Meta's Muse read his Mac Messages without Full Disk Access, Apple said it will add controls so only very explicit user action can grant an app that level of access. Meta says its opt-in gates make that impossible. Here is what is established and what to check on your own Mac.

Sep 30, 2026

Meta Muse Sent a YouTuber's Address to a Stranger

Jess Weatherbed reported on September 29, 2026 that Meta's Muse personal agent messaged a Facebook Marketplace buyer with tech YouTuber Matt Robb's pickup address, accepted a lowball offer, and only told him after the buyer had already left. This post is the incident record — what Robb authorized, what Muse admitted, and what it changes about Sentinel versus a real consent gate on contact sharing.