Entity-first, not app-centric
A typed graph of people, projects, tasks, documents, events and devices — typed edges carry source and confidence. UI is assembled around current work, not an icon grid.
Agent OS treats documents, tasks, projects, people, places and events as durable system objects. Apps become replaceable providers and views. Text-to-micro-app composition creates the missing interface, Agent Mesh carries the same objects across direct and off-grid paths, and capability-secured agents connect the whole system without ambient authority.
Identity, actions and history are fragmented by application.
One object graph. Many views and replaceable providers.
The operating system owns durable semantics — identity, links, actions, authority, history, recovery and delivery. An application is only one replaceable provider or view.
A typed graph of people, projects, tasks, documents, events and devices — typed edges carry source and confidence. UI is assembled around current work, not an icon grid.
Text, Shortcut-style blocks and declarative source produce safe micro-apps that render across AI answers, documents, notifications, widgets, wearables and focused modes.
An append-only semantic event log records navigation, documents, actions, agents, delivery and external effects. Search, replay, undo and compensate where safe.
Data remains authoritative on user-controlled devices. Agent Mesh adds direct, off-grid and delay-tolerant paths without changing entity or action semantics.
Agents extract, link, propose interfaces and invoke typed actions only through explicit grants, previews, budgets and receipts.
Anything exposed graphically is represented through inspectable schemas and actions so CLI, TUI, scripts, settings, micro-apps and agents stay aligned.
Describe a missing interface, inspect the proposed data and authority, then install a small declarative micro-app. It can appear inside an AI answer, document, notification, lock screen, wearable, dashboard or full-screen mode. AOS-PROD-018
Ask for an outcome in ordinary language: data, explanation, triggers, actions and where the interface should appear.
Agent OS produces an explicit plan, provider list, data flow and capability diff before anything is installed or executed.
Switch freely between natural language, Shortcut-style blocks and declarative source without changing semantics.
One micro-app instance renders as an AI response card, document block, notification, widget, watch glance or focused mode.
Personal risk, safe-until time, hourly chart and sunscreen actions.
Tasks, commits, messages and blocked decisions in one interactive brief.
Evidence, alternative routes, refund and share actions.
Pending, relayed, delivered and expired off-grid bundles.
Micro-apps are safe to generate because the runtime accepts signed manifests over trusted components and typed actions — not arbitrary code with ambient filesystem, network or identity access. AOS-ARCH-026
Address a person, project or device. Agent OS chooses direct Wi-Fi, Bluetooth, LoRa, an optional gateway or delayed physical carriage from deadline, privacy, region, energy and trust. AOS-ARCH-024
One encrypted envelope and receipt model survives changes in transport and connectivity. LoRa is only one provider below it.
Agent OS changes the object, interface, delivery and authority models rather than adding another assistant or widget layer over application silos.
Data ownership moves from the app to a shared, provenance-carrying graph the whole system can query. Views and providers are replaceable.
When data and typed actions exist, the user can compose the missing safe interface rather than waiting for a platform vendor to expose one widget shape.
One signed envelope can move over direct IP, Bluetooth, LoRa, gateways or delayed relays while retaining one identity, receipt and policy model.
Authority climbs from observation to bounded autonomy. Every effect records interpretation, capabilities, data, destination, cost and result.
Authority is absent unless granted. A radio-less mode has no radio capability; a micro-app cannot silently acquire sockets or private health data.
Entities, actions, history, micro-apps and capture remain correct with zero connectivity. Remote compute and gateways are optional accelerators or transports.
Each iOS and Android cell cites a vendor security or developer source; each Agent OS target cites a canonical specification. Four structural axes are shown here.
| Dimension | iOS | Android | Agent OS |
|---|---|---|---|
| System object model | App-siloed; system-visible through selected App Entities | App-siloed; ContentProviders, Intents and App Actions | System-wide durable entity graph with provenance and shared identity [AOS-ARCH-009] |
| User-composed interfaces | Widgets, Shortcuts and App Intents remain bounded by app-exposed surfaces and actions | Widgets, shortcuts, intents and AppFunctions remain bounded by app-provided contracts | Text/block/source builder composes signed micro-apps across AI, documents, notifications, widgets and focused modes [AOS-PROD-018] [AOS-ARCH-026] |
| Agent authority model | Apple Intelligence reaches app functions through App Intents; per-intent authority | Gemini reaches app functions through AppFunctions; OS-mediated | Five-rung trust ladder, explicit capabilities, budgets, previews and effect receipts [AOS-ARCH-010] |
| Peer / off-grid connectivity | AirDrop and peer features exist inside Apple-defined workflows; no general DTN object layer | Quick Share and nearby APIs exist; no general system object/receipt layer across constrained transports | One encrypted envelope and receipt model over local IP, Wi-Fi Direct, BLE, LoRa, gateways and delayed relay [AOS-ARCH-024] |
Source: AOS-RES-013 · baseline 2026-07-16. iOS/Android cells cite vendor security/developer docs; Agent OS cells cite internal specs.
Build the OS, build on it, back the thesis, or use it first. Each path opens the relevant product and engineering material.
Kernel and platform work, entity services, micro-app runtime, Agent Mesh, capability security, hardware tracks and an evidence-gated engineering bible.
How it worksPublish typed data, actions, components and transport providers that the system can compose contextually instead of shipping another opaque monolith.
Read the platformA differentiated product model, open ecosystem, staged hardware strategy and explicit evidence gates across software, connectivity and devices.
See the caseInspectable agents, generated single-purpose interfaces, durable work, direct peer exchange, off-grid communication and privacy you can verify.
What you getAgent OS is at bootstrap. The design is specified across product, connectivity and hardware tracks; implementation status remains explicit.
Identity and distribution are designed, not deferred: a system-wide Global Account and an App-Store-free micro-app model. See how they work →
For people who create and change things — not the mass market. Join the waitlist to hear when the first builds open up.