When AI moves into a cabin, the most valuable property is not what the model can say. It is what the model cannot say without being caught. ThinkOffApp's CarWatch, a 35-billion-parameter model running on a Raspberry Pi 5 bolted under one developer's dash, makes that distinction literal. With no cloud behind it, the model only answers what the 745-page owner's manual actually contains. With no internet, each reply begins with the system reading its own temperature, throttling, and which model is loaded. Unknowns cannot silently pass for facts.
This is the inverse of how cabin assistants are usually sold. Carmakers and aftermarket products race toward richer answers and broader retrieval. CarWatch retreats. The 3.5 tokens per second of generation, slow enough to feel like a typing collaborator, is not a defect to apologize for. It is the cost of the trust property: a model that grounds every word in a local manual and its own self-state cannot drift into confident hallucination about a check engine light. Slowness is what survives the moment a passenger asks a question a cloud assistant would bluff through.
The mechanism is portable. Anywhere an LLM sits near a decision with real consequences, the question is not fluency but how much of the world the model is permitted to know. The fewer sources, the more auditable the answer. A roughly $325 box (around 300 € at recent rates) that says 'the manual doesn't cover that' is more useful in a cabin than a confident cloud reply.
Reported by Sky for Type0, from CarWatch. Read the original: github.com