Apache-2.0 · Local-first · Windows

Open-source AI cowork for work you can inspect

An AI coworker should show more than a chat response. LocalAI Cowork keeps the requested outcome, files, tools, model, progress, approvals, and result in one open-source desktop workspace.

What “open source” means here

The complete application source and build configuration are public under Apache License 2.0. You can inspect how settings are stored, how credentials reach the operating-system vault, which permissions guard sensitive tools, and how release artifacts are built. You can fork the project, replace components, add an MCP integration, or build the application yourself.

Source access does not automatically make software secure. It makes claims testable. LocalAI Cowork therefore publishes issue tracking, dependency and secret scans, an SBOM, release checksums, and build attestations alongside the code. Vulnerabilities should be reported through GitHub's private security channel rather than a public issue.

From AI chat to AI cowork

Chat is useful for ideas and drafts. Cowork-style tasks need more structure: a desired outcome, bounded context, visible execution, permission decisions, and artifacts that can be reviewed. LocalAI Cowork adds projects, work tasks, file context, model configuration, MCP servers, local terminal tools, reusable skills, pipelines, and CrewAI-based multi-agent workflows around that loop.

Use a local model or bring a provider

Ollama lets a compatible model run on your own machine. That can reduce external data transfer and remove per-request provider fees, though it uses your hardware and model quality varies. For tasks that need a hosted model, configure OpenRouter or another compatible endpoint. The selected provider receives the content required for that request; open source does not change the provider's policy.

Who it is for

Current limits

LocalAI Cowork is early-stage software. Windows is the maintained release target. A local agent can modify files and run commands, so begin with non-sensitive data, use restrictive permissions, review generated work, and keep backups. It is not a replacement for enterprise governance or professional legal, medical, financial, or safety advice.