The PC-IA is establishing itself as the benchmark for desktops. Lenovo’s catalog already lists more than 80 Copilot+ PC models. For a PC to earn this label, it must meet a number of hardware requirements, notably a microprocessor or SoC equipped with an NPU. This AI-acceleration chip is specifically designed for AI. The minimum power required is 40 TOPS (trillion operations per second). Additionally, the machine must be equipped with 16 GB of DDR5 RAM and 256 GB of SSD or UFS storage.
Be careful not to confuse this label, originally developed by Microsoft for PC manufacturers, with Microsoft 365’s Copilot assistant. Copilot does not require a Copilot+-labeled AI PC to operate. Windows 11, as well as all applications, can benefit from the gains provided by this hardware acceleration to run more efficiently. The AI APIs in Windows 11 are open, and developers can freely leverage the NPU in their applications.
A Secure-by-design Platform
Beyond this raw power, the Copilot+ platform delivers security gains that Yann Le Rhun, Chief Technology Officer of Lenovo France, regards as significant: “The Copilot+ PCs constitute a secure-by-design platform, integrating security from hardware and software design. They rely on trusted components like TPM 2.0, advanced encryption mechanisms, and hardware isolation features to protect sensitive data and embedded AI models. It is thus a meaningful advance in security.” Frédéric Oster, Partner Account Manager at Microsoft, adds: “The Copilot+ PC is directly derived from Windows 11 which requires TPM 2.0, but we have added a complementary requirement with the Pluton chip. Whether AMD, Intel, or Qualcomm PCs, all must have this Pluton chip which adds an extra layer of security, with a chip entirely dedicated to encryption and the protection of the workstation.”
With Windows Hello for authentication, Secure Boot, or memory isolation, many technologies are integrated into Windows 11 to locally secure the hardware. Lenovo has augmented these security features with an additional layer across all ThinkPads, as well as smartphones and tablets via the ThinkShield offering. This covers hardware security with a secure BIOS and boot, the detection of malicious peripherals, and the software facet with ThinkShield Hardware Defense, the security of identities and data, as well as controls throughout Lenovo’s industrial supply chain to ensure advanced traceability of components.
The NPU, an ally in data security
The other electronic component required in all Copilot+ PCs is the famous NPU, the Neural Processing Unit. It is a key element of the architecture, as it ensures users have access to AI power that is extraordinarily significant (minimum 40 TOPS), but above all with a controlled power consumption around 5 W. “We are now delivering on our Copilot+ PCs a battery life that was impossible to achieve on the x86 platform. This gain is largely due to the presence of the NPU,” explains Yann Le Rhun.
Beyond the convenience of very fast responses, assistants leveraging the NPU can now process user questions and documents entirely locally, with no risk of confidential data exfiltration to any LLM provider. The data leakage issue, particularly critical in unauthorized use cases—the so-called Shadow AI—is addressed purely at the hardware level: all AI processing is performed locally, especially when the user handles confidential documents or simply when there is no secure Internet access.
Moreover, Lenovo is a signatory of the European AI Pact, reaffirming its commitment to developing reliable AI systems in line with international safety and ethics standards; Lenovo Qira, Lenovo’s ambient AI solution, aligns with these guidelines. It is possible to benefit from Lenovo Qira’s capabilities in a fully offline mode and have the assurance that no data leaves the company during interaction with the AI (Lenovo Qira will be available on eligible PCs). Lenovo has pledged not to collect any data via its AI. “When you cut/paste in Windows, you don’t have to worry that the data is transmitted to the Cloud and accessible to a third party. With AI running locally, the user will have the same assurance that no data leaves their device,” illustrates Frédéric Oster.
A safer and more virtuous use of AI
In addition to this digital assistant function, the NPU can host a wide range of AI models. Any app developer can load an inference and run it on the end-user’s device to extend the capabilities of their application. Besides faster response times, this approach reduces network transfers and avoids relying on hyper-powerful server GPUs in the Cloud. Running ultra-specialized SLMs locally rather than calling a giant LLM in the Cloud helps reduce AI’s environmental footprint and improve the company’s CSR profile.
The NPU can also be used to enhance the device’s active security. Security solution providers of the EDR (Endpoint Detection and Response) type are beginning to leverage the device’s NPU to run their attack-detection models locally. McAfee, a leader in cybersecurity, has made announcements in this regard, and if their software agents previously ran on the CPU to power these IA tasks, the NPU reduces the device’s power consumption and thus extends its battery life. Similarly, the available power enables vendors to run much more ambitious AI models and detect the most complex attacks without overwhelming the CPU and compromising the device’s autonomy.
Unveiled less than two years ago, Copilot+ is still in the adoption phase for businesses, and solution vendors will intensify their use of this new platform, notes Frédéric Oster: “When the Copilot+ PC fleet becomes dominant, more and more vendors will leverage the NPU, because developers will see value in exploiting this new capability.” Security vendors will all follow this trend, fueling a multi-layer protection that will further increase the security of client devices. Getting equipped with Copilot+ PCs today is a way to prepare for the future and to benefit from the gains of generative and agentic AI while ensuring data security.