Rabbit OS3 AI Agent Leaves the R1 Hardware Behind
Rabbit has released the Rabbit OS3 AI agent without requiring its R1 device, reversing the hardware-first strategy that originally defined the company.
OS3 runs through a browser and coordinates work across connected Windows, Mac, and Linux computers. The cloud service supplies orchestration and memory, while a locally installed Rabbit agent accesses files, software, terminals, and supported screen controls.
The shift matters because Rabbit no longer needs to persuade people to carry another device. It must instead compete with computer-using products from OpenAI, Anthropic, and a growing collection of agent platforms already living on familiar hardware.
That makes OS3 more accessible, but it also removes Rabbit’s clearest physical distinction. The company is betting that coordination across models, skills, and computers can become a product people value on its own.
The Rabbit OS3 AI Agent Moves Beyond Dedicated Hardware
OS3 turns the R1 from Rabbit’s main product into one optional doorway for reaching a broader software platform.
Rabbit made OS3 generally available on September 22, 2026, after an invite-only beta. The company describes it as an “agentic operating system,” meaning software that coordinates AI models and tools to perform tasks.
Users can access the workspace through a web browser or Telegram. Rabbit also supports its R1 handheld as a voice interface connected to the same account.
An R1 is no longer required. That detail creates the central reversal behind the launch.
Rabbit entered public view by arguing that an AI assistant deserved purpose-built hardware. The R1 offered a physical button, microphones, a camera, a small screen, and a scroll wheel for interacting with Rabbit’s software.
OS3 places the main experience on computers people already own. The company’s OS3 workspace presents the R1 as a portable access point rather than the foundation of the system.
To let OS3 act on a computer, the user installs a local program called Rabbit agent. That computer then becomes a node, which is Rabbit’s term for a machine connected to an OS3 account.
Rabbit says one account can connect up to five nodes. Those nodes can include personal computers, servers, cloud virtual machines, and an R1.
OS3 decides which connected node should handle a task. It can also move work between machines when a request needs resources stored in different places.
The approach combines cloud coordination with local execution. Conversations, instructions, memory, and model routing pass through online services, while file and software operations happen through the selected node.
Rabbit says the platform can use terminals, local files, and installed tools. For jobs that require visual interaction, its Direct Large Action Model, or DLAM, can read a screen and simulate keyboard or mouse input.
That structure allows requests to begin somewhere other than the computer performing the work. A person could send an instruction through Telegram, for example, while Rabbit agent operates software on a paired desktop.
Rabbit CEO Jesse Lyu gave one such example to Wired. He said he asks OS3 to take a weekly spreadsheet from a vendor and add its information to a master file.
The example remains a company-provided scenario, not an independent reliability test. Still, it illustrates what Rabbit wants OS3 to become: a control layer spanning communication channels, models, and local machines.
The interface supports one continuous conversation instead of presenting every task as a separate chat. Rabbit says relevant memory and context can carry forward as the user starts new work.
Each access channel keeps its own conversation thread, according to Rabbit’s documentation. Those threads draw from shared memory, even though they do not form one identical chat history.
OS3 also follows a bring-your-own-key model. Users connect an API key from a supported AI provider or configure another compatible model source.
That separates Rabbit’s orchestration layer from the model performing the reasoning. Users can change models without rebuilding their connected computers, skills, and stored context.
Rabbit’s release notes say users can add compatible skills by pasting a public URL into the conversation. A skill packages instructions, scripts, connectors, or other capabilities for an agent.
The combination is ambitious. OS3 aims to preserve context, choose a model, select a computer, install a skill, and complete work without forcing users to manage each component separately.
Yet its most important feature is simpler. People can now evaluate Rabbit’s agent without first buying Rabbit hardware.
Rabbit’s Software Pivot Rewrites the R1 Story
The launch is less a sequel to the R1 than an admission that Rabbit’s original software needed to escape the device around it.
Rabbit introduced the R1 during the early rush to create dedicated consumer AI hardware. Its pitch emphasized an assistant that would take actions instead of merely answering questions.
The device attracted attention because it rejected the standard smartphone interface. Users were supposed to state an intention while Rabbit’s software handled the necessary services behind the scenes.
Early reviews found a wide gap between that vision and the delivered product. Basic features felt unfinished, while the promised action-taking abilities were inconsistent or absent.
Wired assigned the original device a 3-out-of-10 score. Its R1 review described poor battery performance, unreliable responses, and limited reasons to use the device instead of a phone.
Those problems were especially damaging because the R1 had little room for fallback behavior. A conventional computer lets users take over when automation fails, but Rabbit’s compact interface exposed fewer manual controls.
Rabbit spent the following years expanding its software. Lyu told Wired that the company delivered roughly 50 updates during the previous year and a half.
He also pointed to a Discord community exceeding 12,000 members. According to Lyu, feedback from that group influenced Rabbit’s move toward greater openness and third-party agent support.
Those figures come from Rabbit’s chief executive and have not been independently audited. They nevertheless show how the company now frames the R1 as an evolving product rather than a completed launch.
OS3 carries that evolution onto general-purpose computers. It retains the conversational promise while gaining access to mature operating systems, existing applications, and the user’s real working files.
This is a practical retreat from hardware exclusivity. It is also a more demanding test of Rabbit’s software.
The R1 once gave the company control over the entire interaction surface. With OS3, Rabbit agent must coexist with different hardware, operating-system permissions, software versions, security settings, and model providers.
That complexity creates more ways for a task to fail. It also gives the system access to far more useful resources.
A desktop can hold project documents, development environments, spreadsheets, communication tools, and authenticated applications. An agent working there has a better chance of completing meaningful work than one confined to a small standalone device.
Rabbit is therefore trading a controlled device for a richer environment. The company gains relevance while accepting new reliability and security burdens.
The R1 is not disappearing from the platform. Owners can use it to start tasks, check work, or speak instructions into OS3 without opening another application.
However, Rabbit has stopped manufacturing the R1, according to Wired’s OS3 report. Existing inventory remains available, but the company is focusing on OS3.
Lyu also told Wired that Rabbit has no plans for an R2. Its next announced hardware project is a cyberdeck intended for AI-assisted software creation.
That sequence clarifies the new hierarchy. Rabbit is not building OS3 to sell another generation of the same handheld device.
Instead, it is building hardware around the software when a particular form factor appears useful. The agent platform now comes first.
This reversal gives Rabbit a more credible route into daily work. It also places the company in a market where distinctive industrial design matters much less.
Users no longer compare the R1 with a phone or an AI pin. They compare Rabbit OS3 with every agent capable of controlling a browser, terminal, or desktop.
The New Contest Is Agent Coordination, Not AI Hardware
Rabbit now competes on whether its coordination layer can make fragmented agent tools feel like one dependable working environment.
Computer use has become a major direction for model developers. These systems interpret a task, examine an interface, and choose actions such as clicking, typing, or running code.
Anthropic introduced computer-use capabilities that let Claude interact with standard software interfaces. OpenAI later developed a computer-using model that could operate graphical interfaces through screenshots and simulated inputs.
OpenAI described its computer-using agent as a way to handle digital tasks through the same visual controls used by people. Its Operator functionality later moved into ChatGPT agent.
These products established an important competitive baseline. A startup no longer stands out merely because its AI can click through a website.
Rabbit must distinguish OS3 through orchestration. Its argument is that models, skills, memory, access channels, and connected computers should persist as parts of one environment.
The bring-your-own-key approach reinforces that position. Rabbit does not ask users to treat one underlying model as the permanent center of their work.
A user can select a supported cloud model, route through another provider, or connect a locally hosted option. Rabbit’s value must therefore come from everything surrounding that model.
That design reduces dependence on any single model vendor. It also means Rabbit does not control every component affecting speed, cost, privacy, or task quality.
A failed request might originate in the model, a third-party skill, a local permission, Rabbit’s orchestration, or the target application. Diagnosing those failures could become difficult for ordinary users.
OS3 attempts to hide much of that complexity. Users describe an outcome, while the system selects the resources needed to pursue it.
The best case resembles a portable working context. A person could retain connected machines, preferred tools, reusable skills, and accumulated memory while changing the underlying model.
That portability addresses a real weakness in standalone AI products. Users often rebuild instructions and connections whenever they move to another assistant or begin a new chat.
OS3 instead treats context as part of Rabbit’s layer. The model becomes replaceable, while the surrounding work environment stays intact.
This approach also pressures established model providers in a narrow but meaningful way. It reduces their ability to lock users into one interface through accumulated context.
However, large providers already offer agents, connectors, memory, coding tools, and background task execution. Rabbit must move faster without matching their infrastructure budgets.
Its multi-node design offers one possible distinction. A request could use an office workstation, a home computer, and a server under the same account.
That is broader than a browser agent operating inside a temporary virtual computer. It lets the agent work where the user’s tools and files already exist.
The benefit also expands the trust boundary. Connecting several machines gives one orchestration service access to more environments, permissions, and sensitive contexts.
Rabbit’s skill system adds another competitive dimension. Skills can make an agent useful for specialized workflows without requiring Rabbit to develop every integration itself.
The idea resembles reusable procedures in other agent platforms. A skill might describe how to process files, invoke a command-line tool, or coordinate several services.
Rabbit says OS3 can inspect and install compatible skills from public URLs. That convenience reduces setup work, but it exposes users to code and instructions produced by outside parties.
For knowledge workers, the appeal lies in moving beyond isolated answers. An agent could gather material, operate local software, and assemble a finished output using one ongoing context.
People already designing an AI workflow may recognize the underlying goal. The system should preserve context and complete repeatable work without constant manual transfers.
Rabbit’s challenge is proving that its broader coordination adds more value than complexity. A universal control surface sounds attractive until users must troubleshoot every layer beneath it.
The company also needs a reason for people to entrust that coordination to Rabbit. Model vendors, operating-system makers, and established productivity platforms can all pursue similar experiences.
OS3 gives Rabbit an answer to the failed hardware-only framing. It does not give the company a protected market.
Local Access Makes Trust the Hardest OS3 Feature
The Rabbit AI agent becomes more useful when it reaches local files and applications, but those permissions make every error more consequential.
Rabbit says the local agent does not automatically copy an entire computer into the cloud. It accesses resources needed for a requested task through the paired node.
That distinction is important, but it does not make the system fully local. OS3 remains a hybrid service that relies on cloud coordination and model processing.
When a request needs reasoning, relevant instructions and content can pass through Rabbit’s servers to the selected model provider. The provider then handles that information under its own terms.
Rabbit stores conversations and memory information on its systems. Users therefore need to consider Rabbit’s policies alongside those of every model, skill, and external service they connect.
The company’s device-control terms provide a more restrained picture than its product page. They describe OS3 and Rabbit agent as experimental software that can produce unintended results.
The terms say the service is not intended for production, regulated, safety-critical, compliance-sensitive, or unattended mission-critical work. Users remain responsible for supervising its actions.
OS3 can read files, move the mouse, type, open applications, browse websites, install tools, and complete transactions. Those capabilities create value because they let an agent act beyond a chat window.
They also give mistakes a physical effect on data and accounts. A hallucinated answer is inconvenient, but a mistaken command can modify files or change a system.
Rabbit says operating systems present their own permission dialogs when the local agent needs sensitive capabilities. Users approve those permissions on each machine.
The service also pauses for some actions it considers consequential or difficult to reverse. Users can interrupt tasks and retain final control over important operations.
Those safeguards depend on correct risk classification. An apparently ordinary action can still reveal confidential information, send an incorrect message, or introduce a compromised dependency.
Rabbit explicitly warns about prompt injection, which occurs when malicious content tries to redirect an agent’s behavior. A webpage, document, email, or downloaded skill can contain such instructions.
This risk becomes harder when an agent operates across several contexts. It may read an untrusted page while also holding access to local files, authenticated accounts, and reusable memory.
Third-party skills create an additional software supply-chain problem. A convenient installation link can conceal scripts, dependencies, or instructions that deserve independent review.
Rabbit tells users to inspect a skill’s audit summary and verify its security. That expectation sits uneasily beside the product promise of installing capabilities without technical expertise.
A nontechnical user may understand that a skill requests file access without recognizing the implications of a dependency or command. Easy installation does not guarantee informed consent.
The company’s history increases the importance of this issue. In 2024, outside researchers reported exposed service keys associated with the R1 software.
Rabbit later said it rotated affected keys and investigated the incident. The episode does not prove that OS3 is insecure, but it gives prospective users a reason to demand transparent controls.
Independent testing must determine whether OS3 isolates tasks, limits permissions, records actions, and stops reliably. Marketing demonstrations cannot answer those questions.
Reliability needs similar scrutiny. The system must correctly interpret requests, select the appropriate node, invoke compatible tools, and verify that the requested outcome actually occurred.
A task can appear complete even when an agent changed the wrong file or worked with outdated information. Persistent memory may then carry that error into later conversations.
Model switching creates another uncertainty. OS3 promises to preserve the user’s environment when the selected model changes, but different models can interpret the same skill differently.
Their tool-use behavior, context handling, and caution levels can vary. A workflow that succeeds with one provider may fail or require more supervision with another.
Bring-your-own-key also shifts operational responsibility toward the user. People must manage credentials, monitor provider usage, and understand which service receives their data.
Rabbit supplies the interface and routing layer, but it cannot guarantee the behavior of every connected provider. That limits how consistently OS3 can present itself as one coherent system.
The responsible way to evaluate OS3 is through low-risk, reversible work. Users can begin with duplicate files, disposable environments, and tasks whose results are easy to inspect.
Sensitive documents, financial activity, account administration, and production systems demand stronger evidence. Rabbit’s own terms advise against treating the preview as unattended infrastructure.
The central question is not whether OS3 can complete an impressive demonstration. It is whether people can predict its boundaries when a task becomes ambiguous.
For a computer-controlling agent, understandable failure is a feature. Users need clear records showing what the system accessed, which model decided, and what each node changed.
Until independent testing addresses those points, Rabbit’s claims should remain claims. OS3 expands what the company’s software can touch before it establishes how safely that access scales.
Three Signals Will Show Whether Rabbit’s Pivot Works
OS3 will succeed only if real usage proves that Rabbit’s software can outlast the novelty that once surrounded its hardware.
The first signal is independent task reliability. Reviewers need to test repeatable workflows across Windows, macOS, and Linux rather than rely on demonstrations selected by Rabbit.
Useful tests should include spreadsheets, file organization, coding, browser work, and communication tools. They should measure completion quality, recovery from errors, and required supervision.
Strong results would support Rabbit’s claim that OS3 coordinates complex work across different machines. Frequent interventions would weaken the case for adding another agent layer.
The most revealing tasks will be ordinary and repetitive. A system that reliably completes routine work offers more lasting value than one successful, highly staged example.
The second signal is how Rabbit responds to security scrutiny. Researchers will examine local permissions, network behavior, skill installation, memory controls, and data sent to model providers.
Clear audit trails and narrowly scoped permissions would strengthen the platform’s credibility. Serious vulnerabilities or confusing controls would revive concerns created during the R1 era.
Rabbit should also explain how it reviews third-party skills and responds when a shared skill becomes malicious. Removing one package after an incident is not enough.
Users need dependable revocation, dependency visibility, and records of what installed code accessed. These controls become essential when OS3 spans several connected computers.
The third signal is whether people continue using OS3 without buying Rabbit hardware. This is the decisive test of the software pivot.
R1 owners form a natural early audience, but they cannot establish broader demand. Rabbit needs users who arrive for the agent platform itself.
Continued adoption would show that its model-neutral memory, skills, and multi-node coordination solve a problem that larger providers have not solved cleanly.
Weak adoption would suggest that OS3 mainly extends the life of an existing enthusiast community. In that case, removing the hardware requirement would broaden access without creating a durable category.
Rabbit’s upcoming cyberdeck will offer supporting evidence, but it should not become the main measure. The central promise of OS3 is that users can start with devices they already own.
A new machine can showcase the platform without proving that the platform needs special hardware. Rabbit must avoid recreating the same dependency it has just removed.
The Rabbit OS3 AI agent is therefore a more credible product direction than another immediate R1 successor. It puts the software in environments where meaningful work already happens.
It also places Rabbit against competitors with mature models, established distribution, and existing relationships with computer users. Accessibility alone will not secure a lasting position.
The strongest version of Rabbit’s argument is not that hardware was a mistake. It is that an AI agent should preserve context and coordinate work across whichever hardware makes sense.
Whether OS3 delivers that experience remains an open, testable question. Readers considering the platform should watch independent reliability tests, security findings, and sustained use beyond the R1 community.
Would you let one agent coordinate several computers today? Start by identifying one reversible task, the files it requires, and every service that would receive its data.
Then compare the saved effort with the supervision the workflow demands. If the Rabbit AI agent consistently finishes that task while keeping its actions understandable, Rabbit’s pivot has substance.
If users spend more time monitoring, correcting, and securing it than the task originally required, OS3 will repeat the R1’s central problem in software form.



