Entity-first, not app-centric
A typed graph of people, projects, tasks, documents, events and devices — typed edges carry source and confidence. UI is assembled around current work, not an icon grid.
Agent OS owns the entities, actions, history, authority and delivery semantics that applications currently fragment. Micro-apps assemble the needed interface; Agent Mesh carries the same objects across direct, off-grid and delayed paths.
Today identity, actions, interfaces and history are fragmented by application. Agent OS keeps one object graph and lets many views, agents, micro-apps and replaceable providers operate on it.
Identity, actions and history are fragmented by application.
One object graph. Many views and replaceable providers.
A typed graph of people, projects, tasks, documents, events and devices — typed edges carry source and confidence. UI is assembled around current work, not an icon grid.
Text, Shortcut-style blocks and declarative source produce safe micro-apps that render across AI answers, documents, notifications, widgets, wearables and focused modes.
An append-only semantic event log records navigation, documents, actions, agents, delivery and external effects. Search, replay, undo and compensate where safe.
Data remains authoritative on user-controlled devices. Agent Mesh adds direct, off-grid and delay-tolerant paths without changing entity or action semantics.
Agents extract, link, propose interfaces and invoke typed actions only through explicit grants, previews, budgets and receipts.
Anything exposed graphically is represented through inspectable schemas and actions so CLI, TUI, scripts, settings, micro-apps and agents stay aligned.
Kernel policy stays minimal. Drivers, compatibility, graphics, entity services, micro-apps, connectivity policy and agents live in isolated user-space domains behind versioned contracts.
All contracts between layers are FIDL — which is what makes the emulator (Track A) and real hardware (Track B) interchangeable above the contract boundary. Most demo-brick hardware is as-is (pre-certified modules), which is why it ships years before a custom device.
Agent OS treats identity as a system-wide primitive, not a per-app afterthought. One Global Account carries your login, payments and data everywhere — across native apps and websites — while your personal data physically stays with you, not vendors. A vendor gets only an opaque UUID and the specific access you grant. AOS-PROD-014
“iCloud as it should be.”
Log into an app once and the matching website recognizes you — the same identity spans native and web, not two separate accounts.
Your data is end-to-end encrypted and lives with you. You share individual "sectors" selectively; vendors never hold the store, only the handles you grant.
A vendor sees an opaque per-user identifier and the specific access you allow — not your name, inbox, or profile. Custody stays on your side.
One system-wide way to pay every app. No per-vendor card entry, no re-authorizing a checkout you already trust.
An OS-level hub replaces OTP email and SMS: granular, revocable, rich-content, with trust tiers — every subscription visible in one place.
Pseudonymous, un-squattable identifiers. You are reachable and consistent across the system without handing anyone your real identity.
The same instinct Apple had — a unified way to pay and authorize — taken to its conclusion, without the gate.
Describe a missing interface, inspect the proposed data and authority, then install a small declarative micro-app. It can appear inside an AI answer, document, notification, lock screen, wearable, dashboard or full-screen mode. AOS-PROD-018
Ask for an outcome in ordinary language: data, explanation, triggers, actions and where the interface should appear.
Agent OS produces an explicit plan, provider list, data flow and capability diff before anything is installed or executed.
Switch freely between natural language, Shortcut-style blocks and declarative source without changing semantics.
One micro-app instance renders as an AI response card, document block, notification, widget, watch glance or focused mode.
Personal risk, safe-until time, hourly chart and sunscreen actions.
Tasks, commits, messages and blocked decisions in one interactive brief.
Evidence, alternative routes, refund and share actions.
Pending, relayed, delivered and expired off-grid bundles.
Micro-apps are safe to generate because the runtime accepts signed manifests over trusted components and typed actions — not arbitrary code with ambient filesystem, network or identity access. AOS-ARCH-026
Address a person, project or device. Agent OS chooses direct Wi-Fi, Bluetooth, LoRa, an optional gateway or delayed physical carriage from deadline, privacy, region, energy and trust. AOS-ARCH-024
One encrypted envelope and receipt model survives changes in transport and connectivity. LoRa is only one provider below it.
A person is not five contacts. A project is not a folder plus a chat plus a board plus a calendar — it is one entity, rendered as a card, table, timeline, map, micro-app or agent context.
The same typed action can be invoked from a button, micro-app, command palette, script or agent under explicit authority — with no private backdoor to state.
Storage, data, actions, rendering, radio and hardware backends can change while entity and action semantics stay stable. Foreign types stop at adapters.
Claims, experiments, risks and acceptance gates constrain implementation and every public support statement. No assumption becomes a requirement just because it appeared in a spec.
For people who create and change things — not the mass market. Join the waitlist to hear when the first builds open up.