Agents need boundaries, and users want to own them
Three different projects circled the same question: who is in charge of the agent? Microsoft shipped Mxc, Microsoft Execution Containers 1.0.0, built on the line "an agent cannot be its own security authority." Talorys launched as an open-source personal agent that runs in your own Cloudflare account on the free tier. A thread on Anthropic ending Claude Code subscription use with OpenClaw (47633396) and an Ask HN on replacing Claude or GPT with local models (48542100) show the other side: people hitting rate limits and vendor rules, and trying Qwen 3.6 27B, Gemma 4 and DeepSeek V4 Flash instead.
The pattern here: control is the product. Enterprises want a sandbox the agent can't talk its way out of. Individuals want an agent that a vendor can't switch off. The commenters are also picky about words. One said "self-hosted" should mean you host it yourself, not that it runs on Cloudflare's free tier. Another asked what a Cloudflare "neuron" even is.
The counterpoint is practical. Local models are still slower than cloud ones, and one commenter said Qwen 3.6 27B feels about like Haiku 4.5. Good enough for some work, not for everything.
So what?
If you build on one vendor's agent harness or subscription, assume the terms can change overnight, as they did for OpenClaw users. Design for swappable models and a clear permission boundary that lives outside the agent. Enterprise buyers are starting to ask for exactly that.
Read these
Mxc: Microsoft Execution Containers version 1.0.0
Talorys – A self-hosted personal AI agent on Cloudflare's free tier
Tell HN: Anthropic no longer allowing Claude Code subscriptions to use OpenClaw
Ask HN: Has anyone replaced Claude/GPT with a local model for daily coding?
Five months treating bugs like patients and coding agents like a medical team