What others miss

Local & open-weight models

When the model runs on the laptop, there is no request leaving the machine, and nothing for a gateway to inspect. The agent still reads files, runs commands, and calls tools. Certiv governs it anyway, because Certiv is not on the wire.

In short

Agents running against local or open-weight models operate outside every network-based control an enterprise owns, because they generate no traffic to inspect. Certiv enforces policy from the endpoint, in the execution path of the agent, so a locally-run model is governed by exactly the same rules as a hosted one.

Four reasons the network never sees it

No API call to intercept

A hosted model produces network traffic a gateway can inspect. A model running on the laptop produces none. There is no request leaving the machine, so there is nothing for a gateway, proxy, or CASB to see.

No key to govern

Controls built around API key custody and model routing have nothing to attach to. The weights are already on disk.

Works offline

An agent running against a local model keeps working on a plane, on a home network, or on a machine that never reaches your egress path.

Indistinguishable at the process layer

EDR sees a process consuming CPU. It cannot tell an autonomous agent reasoning about your codebase from any other local program.

The control point has to be where the agent is

This is the whole argument for endpoint-native enforcement, and local models are its clearest case. Every control that works by inspecting traffic inherits the same limit: it governs what it can see, and it can only see what routes through it.

Certiv sits in the execution path instead. Each model request and tool call is intercepted and evaluated against enterprise policy with full session context, then allowed, blocked, redirected, or escalated to a human before it executes, and every decision is recorded as audit evidence. Coverage never depends on traffic crossing a proxy.

Straight Answers

What Teams Ask About Local Models

Expand to view common questions.

Why are local models a security problem?
Not because the models are inherently unsafe, but because the controls most organizations bought are structurally blind to them. Gateways, proxies, and CASB all work by inspecting traffic. A model running on the endpoint generates no traffic to inspect, so an agent using one operates entirely outside those controls while still reading files, running shell commands, and calling tools.
How does Certiv govern an agent using a local model?
Identically to one using a hosted model. Certiv sits on the endpoint, in the execution path of every agent. Each model request and tool call is intercepted and evaluated against enterprise policy with full session context, then allowed, blocked, redirected, or escalated to a human before it executes. Because enforcement is endpoint-native, it covers hosted models, local models, and shadow agents equally.
Should we just ban open-weight models?
That is rarely realistic and usually counterproductive. Open-weight models are how many teams keep sensitive data in-house, control cost, and work without a network dependency. The goal is not to stop them running but to make their actions subject to the same policy as everything else, which requires a control point on the endpoint rather than on the wire.
Which local models and runtimes does this cover?
Coverage is not per-model. Scout observes AI agent activity regardless of which platform or framework those agents run on, and the Policy Engine evaluates the actions an agent takes rather than the model behind it. An agent using an open-weight model is governed by the same policies as one using a hosted frontier model.

See Certiv on Your Own Endpoints

Deploy in minutes. See every agent, then control what happens next.

Book a Demo