AFAIK, cisco tunnels all traffic back to their controller.
There's an HREAP feature (which has since been renamed to something else) That causes an AP to *not* tunnel *any* traffic.
Warning: HREAP also disables most features of the controller.
(I.E. dynamic VLAN assignment, etc. goes out the window)
I did not dig too deeply on this w/ Meru gear.
The reseller I dealt with was unable to answer such questions despite being a highly rated reseller and describing another customer situation where that capability would have been advantageous.