A system-wide entity graph, not app silos
AOS-ARCH-009Data ownership moves from the app to a shared, provenance-carrying graph the whole system can query. Views and providers are replaceable.
An evidence map, not a feature-scoreboard. iOS and Android cells point to vendor security or developer material; Agent OS cells point to canonical target specifications. Inferences are labelled as such.
| Dimension | iOS | Android | Agent OS |
|---|---|---|---|
| System object model | App-siloed; system-visible through selected App Entities | App-siloed; ContentProviders, Intents and App Actions | System-wide durable entity graph with provenance and shared identity [AOS-ARCH-009] |
| Action / intent APIs | App Intents expose developer-selected typed operations | Intents + App Actions / AppFunctions expose developer-selected operations | Typed action providers, common executor, receipts and compensation across every caller [AOS-ARCH-010] |
| User-composed interfaces | Widgets, Shortcuts and App Intents remain bounded by app-exposed surfaces and actions | Widgets, shortcuts, intents and AppFunctions remain bounded by app-provided contracts | Text/block/source builder composes signed micro-apps across AI, documents, notifications, widgets and focused modes [AOS-PROD-018] [AOS-ARCH-026] |
| Agent authority model | Apple Intelligence reaches app functions through App Intents; per-intent authority | Gemini reaches app functions through AppFunctions; OS-mediated | Five-rung trust ladder, explicit capabilities, budgets, previews and effect receipts [AOS-ARCH-010] |
| Global history / provenance | Per-app history; no documented system-wide semantic effect log (inference) | Per-app history; no documented system-wide semantic effect log (inference) | Append-only semantic event log with provider, agent, delivery and compensation receipts [AOS-ARCH-009] |
| Sandboxing / capabilities | App Sandbox, signed entitlements and TCC | Per-UID sandbox, SELinux and runtime permissions | Object-capabilities; authority absent unless granted; micro-app and agent quotas [AOS-ARCH-004] [AOS-ARCH-026] |
| Peer / off-grid connectivity | AirDrop and peer features exist inside Apple-defined workflows; no general DTN object layer | Quick Share and nearby APIs exist; no general system object/receipt layer across constrained transports | One encrypted envelope and receipt model over local IP, Wi-Fi Direct, BLE, LoRa, gateways and delayed relay [AOS-ARCH-024] |
| Update model | Signed System Volume and sealed platform image | A/B seamless updates and Project Mainline modules | Verified compatibility set with package provenance, rollback and recovery [AOS-ARCH-013] |
| Privacy posture | On-device processing, Private Cloud Compute and TCC/ATT | Private Compute Core and Privacy Dashboard | Local authority, field-level capability grants, declared destinations and journal exclusion [AOS-PROD-013] [AOS-ARCH-012] |
| Offline behaviour | Per-app; cloud-dependent capabilities vary by feature | Per-app; cloud-dependent capabilities vary by feature | Offline correctness for entities, actions, history and micro-apps; Mesh adds delayed peer paths [AOS-ARCH-009] [AOS-ARCH-024] |
| Extensibility | App Extensions and App Intents; core semantics remain platform-controlled | Intents, providers, App Actions and services; app package remains primary unit | Providers publish data, actions, components and transports; portable semantics remain provider-independent [AOS-PROD-003] [AOS-ARCH-005] |
| Interop / cross-device | Closed native runtime with Continuity and AirDrop | Open runtime with Quick Share and vendor ecosystems | Encrypted sync, shareable micro-app manifests and transport-neutral peer bundles [AOS-ARCH-009] [AOS-ARCH-024] |
| Identity / accounts | Apple Account, Sign in with Apple, iCloud and passkeys | Google Account, Credential Manager and passkeys | Global Account with local-first user authority and opaque per-provider identities [AOS-PROD-014] |
| Developer distribution | App Store and notarization; EU alternative marketplaces under DMA | Play, sideloading and developer verification requirements | Signed providers and micro-app packages discovered by capability and context, not a mandatory monolithic-app funnel [AOS-PROD-003] [AOS-ARCH-026] |
Source: AOS-RES-013 · baseline 2026-07-16. iOS/Android cells cite vendor security/developer docs; Agent OS cells cite internal specs.
The incumbents already have typed intents, widgets, on-device AI and nearby sharing. Agent OS makes different units primary: shared entities, user-composed micro-apps, semantic receipts and transport-neutral peer delivery.
Data ownership moves from the app to a shared, provenance-carrying graph the whole system can query. Views and providers are replaceable.
When data and typed actions exist, the user can compose the missing safe interface rather than waiting for a platform vendor to expose one widget shape.
One signed envelope can move over direct IP, Bluetooth, LoRa, gateways or delayed relays while retaining one identity, receipt and policy model.
Authority climbs from observation to bounded autonomy. Every effect records interpretation, capabilities, data, destination, cost and result.
Authority is absent unless granted. A radio-less mode has no radio capability; a micro-app cannot silently acquire sockets or private health data.
Entities, actions, history, micro-apps and capture remain correct with zero connectivity. Remote compute and gateways are optional accelerators or transports.
The text-to-micro-app builder composes declared data, actions, views and policy into one inspectable instance that can render inside AI, documents, notifications, widgets or focused modes.
Agent Mesh uses one signed envelope and receipt model across direct IP, Wi-Fi, Bluetooth, LoRa, gateways and delayed relays instead of fragmenting identity and status by transport.
For people who create and change things — not the mass market. Join the waitlist to hear when the first builds open up.