Yeah, but the server is most likely running the whole thing in a docker container with no permissions to do anything. Big companies security teams tend to require that when opening non-trivial third party code up to the internet.
The client on the other hand I would guess is running it's code as root, or at least something with full GPU access.