workmy whyaboutget in touch
The PICPositionsThe perimeterState of the buildThe boundaryThe costThe comparisonRecordRefusalsUnresolvedThe roomContact

Private
Inferencing
Core (The PIC)

In development ยท working core, proposed expansion

Private Inferencing Core is my attempt to make machine intelligence personally owned infrastructure.

Instead of sending every memory, conversation and working process into corporate systems, I am building a local layer through which models, files and personal agents operate under my control.

It is partly technical and partly political: where should intelligence live, who should own the memory it produces, and how much independence is possible when our tools depend on remote institutions?

Mac Studio on a black desk stand, the machine at the centre of the core

Positions

Seven positions on where intelligence should live

Written over a year, mostly after something broke. They are the argument the rest of this page is evidence for.

  1. 01

    Intelligence should have an address.

    A model that runs somewhere I can point at is a different object from one that runs somewhere I cannot. Location decides who can revoke it, read it, or change it while I am asleep.

  2. 02

    Memory is the asset. The model is a consumable.

    Weights get cheaper every quarter. The record of what I have read, written, decided and abandoned does not. That record belongs on a disk in a room I pay for.

  3. 03

    Nobody sells you sovereignty.

    You pay for it monthly, in electricity, disk, and the hour a week an update takes back. The bill is the proof. A position you are not paying for is a preference.

  4. 04

    Use the frontier. Do not live on it.

    The largest models are genuinely better at some things. They are used deliberately, for named tasks, with the least context that will do. Local is the default; remote is the argued exception.

  5. 05

    A system that cannot refuse is an exposure.

    Capability is the cheap part. The slow engineering is the list of things the machine will not do, enforced in the architecture rather than in my intentions.

  6. 06

    The real interface is the dependency.

    Pricing pages, terms and deprecation notices shape my working life more than any button. Building locally drags that interface somewhere I can see it.

  7. 07

    This is not a retreat from the network.

    I am not building a bunker. I am building a position to negotiate from. Refusing to be a tenant is not refusing the world.

The perimeter

One line, drawn on purpose

Inside the line, machines I own on a network I control. Outside it, everything rented. The interesting part is the gate: what crosses is decided per question, the least context goes out, and every answer that comes back is marked as having been outside. There is no standing connection.

System perimeter diagram A dashed boundary encloses my devices, the agent nodes, the orchestration council, the inferencing core and the memory store. Outside the boundary sit frontier models and subscriptions, rented and revocable. The only crossing is the gate: the least context goes out, the answer returns marked as remote, and there is no standing connection. PERIMETER · UNDER MY CONTROL MY DEVICES desk, laptop, phone, studio AGENT NODES headless laptops, background work THE COUNCIL · ORCHESTRATION one voice, models swappable, routing and policy INFERENCING CORE · MAC STUDIO one machine, on a desk, unified memory MEMORY STORE files, mail, calendar, everything Grant has been told OUTSIDE · RENTED, REVOCABLE FRONTIER MODELS on purpose, never resident SUBSCRIPTIONS someone else’s terms THE GATE least context out answer returns, marked remote no standing connection Intelligence with an address in the house.

The perimeter. Nothing crosses the line by default; the gate is the only door, and it opens one question at a time.

State of the build

Working, testing, proposed

Separated so you can see how much of this is a machine and how much is still an argument.

Working

Central machine
Mac Studio, M4 MaxChosen for unified memory, where the model and the work share one pool: a platform that runs to 128 GB on this chip, with the ceiling deliberately above the build. Exceptionally cool and quiet for its class; a machine you can work beside gets used.
Local model runtimes
Open weight models, standard runtimesRun deliberately below their ceiling while the system around them matures. Nothing is streamed in to answer an ordinary question.
Private network
Ethernet on the desk, Tailscale off itWired between machines that sit together; a private overlay for everything else. My devices reach the core from anywhere without the core being exposed to anyone.
Memory store
Private indexThe index and retrieval layer over my own files, mail and calendar. The boundary it enforces is described on the next card.
Resident system
Grant 3.0The daily briefing, planning and learning system runs here. This is the machine Grant lives on. See Grant 3.0 →

Testing

Agent nodes
Headless laptops, lids shutOlder hardware doing unglamorous background work so the central machine stays free. The least impressive part, and possibly the most honest.
The Council
Hand assembled harnessA council of models presenting as one voice. Its purpose is replaceability: models swap as they change or deprecate, without changing the interface or the sovereign parts underneath.
Conversational layer
In developmentShared with Grant 3.0. Speaking is the interface I actually use.
Autonomy
BetaAs a daily assistant it is stable. As an autonomous harness, reasoning inside its own structures unwatched, it is not finished; that is what holds back a public demonstration.

Proposed

Expansion
Multi machine, multi GPUTo run larger models locally and hold more than one model resident at once. Compute access is expected to step up significantly; the architecture is built for that.
Additional sites
A second locationRedundancy, and a test of whether the argument survives being in more than one building.
Status
Proposed means proposedNone of this is claimed as built, costed or committed. It is written so the difference between what exists and what I want stays visible.

The boundary

What stays here, and what is allowed to leave

The sovereignty claim is only as good as this list. It is enforced in the routing layer rather than in my habits.

Never leaves the building

  • Files, notes, drafts and unfinished work
  • Calendar, reminders and mail
  • The memory store, which is to say everything Grant has ever been told
  • The index built over all of the above
  • Voice recordings and their transcripts
  • Anything identifying a person who did not consent to be in a remote system

May leave, under conditions

  • Isolated questions with the person cut out of them
  • Public documents I did not write
  • Code fragments, stripped of identifiers
  • Work that is going to be published anyway

Three rules govern the gate. Send the least that will answer the question. Never send two fragments that would identify me if recombined. Mark every answer that came from outside, at the moment it arrives.

The test is whether the exchange is fair: some things are worth sending out because what comes back is worth more than what went. Most are not.

The cost of the position

Sovereignty has a wattage

The honest constraints are physical: power, heat, space and money. You cannot argue with a thermal limit and you cannot subscribe your way past it. These are the actual figures, on a student budget.

6 W
At idle. Whole machine, published
145 W
At maximum. Whole machine, published
495 BTU/h
Heat at maximum. The thermal budget, literally
£3.81
Electricity a month. Modelled, see assumptions
128 GB
Unified memory ceiling of the platform
7 dBA
Apple’s published operating sound level

The monthly figure is modelled, not metered: twenty hours a day at idle and four hours a day averaging 90 W, against the July to September 2026 price cap unit rate of 26.11p per kWh; 14.6 kWh a month. The assumptions are written down rather than the conclusion, because a project about not being lied to by systems should not round in its own favour.

The comparison

The same work, on the other architecture

A model has to live somewhere fast. Here that is unified memory, shared between processor and graphics. On the usual alternative it is a graphics card, and you buy the memory by buying the card.

What is on the desk

Mac Studio, M4 Max

Memory the model can live inup to 128 GB unified
Maximum, whole machine145 W
Heat at maximum495 BTU/h
At idle6 W
Mains plugsone
Operating sound level7 dBA published

What it would otherwise take

Workstation, RTX PRO 6000 Blackwell

Memory the model can live in96 GB GDDR7
Maximum, graphics card alone600 W
Heat, graphics card alone2,047 BTU/h
Processor beside it, rated350 W
Card and processor together950 W
Before board, memory, fans, disksyes

Not a claim that the Mac is faster; on raw compute it is not. It is a claim about watts per gigabyte of resident model, and that ratio is most of the reason this project exists at all.

Figures: Mac Studio (2025) M4 Max tech specs, memory and acoustics, Apple, support.apple.com/en-us/122211; power and thermals, support.apple.com/en-us/102027. RTX PRO 6000 Blackwell maximum power, NVIDIA. Threadripper PRO 9995WX rated 350 W, AMD. Unit rate 26.11p per kWh, Ofgem cap, Jul–Sep 2026. Retrieved August 2026.

Record

How it got here

Including the versions that did not survive.

Summer 2025
Training with royal butlers, preparing to serve a Saudi Arabian family in London. The post was short-lived; the question stayed. Could service at that standard be rendered by a system, and what would be lost?
2024 · 2025
Grant 1.0, built as a gift. Grant 2.0, character joined to study tools. Both dependent on remote services; by the end, the dependency had become the problem.
Late June 2026
The system designed, in Canada. The decision to stop renting and start owning is made away from home.
July 2026
Built over a month. The Council takes shape: models underneath replaceable without the thing on top changing.
Late July 2026
A Mac Studio bought from the Apple Store, by some margin of luck the last in the country during a global memory shortage. The machine that makes independence possible was itself in short supply, which is exactly the kind of dependency this project is about.
Late July 2026
Development begins at a desk in an empty LSBU studio. Every day worked there so far has been worked alone.
August 2026, now
The dossier arrives every morning, on hardware I own. Agent nodes in testing. Autonomy in beta. The expansion on paper.

The butler training is the origin of the character, documented on the Grant 3.0 page. It sits here because it is why the system takes this form: not a chatbot, but something closer to a member of staff who knows the household and does not discuss it outside.

Refusals

What the system will not do

Any system can be made to do more. The part that took time was deciding what it would not do, and enforcing that in the architecture rather than in my manners.

  • It does not upload my files in order to search them. Retrieval happens on the machine that holds the files.
  • It does not keep a record I cannot read, export or delete in full, in one action.
  • It does not contribute my material to anybody else’s training set.
  • It does not require an active subscription in order to start.
  • It does not send identifying context outward, and I can see exactly what left.
  • It does not present a remote answer as a local one.
  • It does not run a model I cannot replace. Nothing assumes one supplier still exists next year.

Unresolved

What I cannot yet answer

The questions the project has produced rather than solved. They are why it belongs in a studio rather than only in a workshop.

  1. Does owning the machine change the politics, or only move the dependency up the stack, to weights I did not train and a grid I do not control?
  2. The models are downloaded minds. What does sovereignty mean when the intelligence is someone else’s artefact and only the housing is mine?
  3. At what point does maintaining independence cost more attention than it returns?
  4. Is this a practice or a privilege? A politics that only works at this price is not much of a politics.
  5. If it works perfectly it is invisible. Does this only become legible as art at the moment it fails?
  6. I have built a system that refuses on my behalf. Who audits the refusals, and what happens on the day I quietly relax one?

The room

Objects, in the order you would meet them

Mac Studio, the machine at the centre of the core

The machine

A Mac Studio with an M4 Max, chosen for unified memory: the model and the work sit in the same pool, so a large model runs on one desk instead of in a rack.

It is also, for its class, remarkably cool and remarkably quiet. A machine you can live beside gets used.

Owned, not rented: frontier models where necessary, sovereign models where possible

Owned, not rented

Frontier models where they are genuinely better. Sovereign models wherever they are good enough. One machine holding the whole of it together.

Rented capability sits at the top of the stack, where it can be removed without the floor giving way.

Placeholder: the agent nodes, photograph to follow

The nodes

Headless laptops running background work so the central machine stays free.

Old hardware, kept in service. The least impressive part of the system and possibly the most honest one.

Placeholder: the machine in the room, photograph to follow

The room

Power, heat, space and money, in a room I pay for. This is what machine intelligence looks like when nobody is renting it to you.

It is warmer than you would expect; that heat is the running cost of the position made physical.

See more

Fuller documentation, video, writing and build logs, is on its way.

ask me

Scroll sideways →

Contact

bennett harris

Systems Artist

Working across objects, infrastructure and machine intelligence.

For collaboration, commissions or conversation me@bawh.io download portfolio

A working portfolio for institutions and accelerators.