IMO, an agentic operating system should be not only about "integrating the agent everywhere" but also about providing the compartimentalization and tools to allow working safely with agents when they can reach into every part of the system. It should allow to easily extend the system safely.
I also built an agentic OS but the underlying system is very different based on a custom actor runtime with capabilities and a way to arbitrarily create and compose restricted capabilities.
The idea is that you can sculpt the OS to your needs using agents and fully restrict what they can or can't do.
The core is also I think kind of interesting because at it's core it's an actor runtime, where each program receives and sends messages, and only when processing a message they use memory. Each program has managed persistent state as well. So it's very easy to create actors that persist data and you can have millions of them without using a lot of resources.
> IMO, an agentic operating system should be not only about "integrating the agent everywhere" but also about providing the compartimentalization and tools to allow working safely with agents when they can reach into every part of the system. It should allow to easily extend the system safely.
Right, but that's also a contradiction. An "agentic" OS is most interesting to the average AI enthusiast if it can, essentially, be your executive assistant: shop for you, book travel for you, manage your agenda, sort through your emails, do your taxes, and so on - possibly including anticipating your needs before you articulate them. That requires human-equivalent access, more or less.
Most people also don't need it - really, most lives are not that complicated - but the allure of your own computerized EA is undeniable. It's your personal servant, how cool is that.
The safe and principled way to use agents is to scope permissions appropriately, restrict them to narrowly-defined tasks, etc, but that also makes the technology a lot more boring. And these silos are very difficult to build when you're interacting with third-party services anyway.
You could as well argue that vibecoding is wrong and that there are principled ways to use agents for precisely-scoped, restricted tasks. Sure, but the entire SF Bay Area is vibecoding now, and if something breaks or gets hacked, that's just the cost of business.
The question most of us will have is: what does having the agent at the OS level get you that you can't get through a user space app? "It does the work through the same operations as your keyboard and mouse" makes it sound like garden-variety computer-use rather than something more fundamental. I would expect an agent-oriented OS to be built around something like Apple's App Intents as an atomic component.
I also built an agentic OS but the underlying system is very different based on a custom actor runtime with capabilities and a way to arbitrarily create and compose restricted capabilities.
The idea is that you can sculpt the OS to your needs using agents and fully restrict what they can or can't do.
The core is also I think kind of interesting because at it's core it's an actor runtime, where each program receives and sends messages, and only when processing a message they use memory. Each program has managed persistent state as well. So it's very easy to create actors that persist data and you can have millions of them without using a lot of resources.
Right, but that's also a contradiction. An "agentic" OS is most interesting to the average AI enthusiast if it can, essentially, be your executive assistant: shop for you, book travel for you, manage your agenda, sort through your emails, do your taxes, and so on - possibly including anticipating your needs before you articulate them. That requires human-equivalent access, more or less.
Most people also don't need it - really, most lives are not that complicated - but the allure of your own computerized EA is undeniable. It's your personal servant, how cool is that.
The safe and principled way to use agents is to scope permissions appropriately, restrict them to narrowly-defined tasks, etc, but that also makes the technology a lot more boring. And these silos are very difficult to build when you're interacting with third-party services anyway.
You could as well argue that vibecoding is wrong and that there are principled ways to use agents for precisely-scoped, restricted tasks. Sure, but the entire SF Bay Area is vibecoding now, and if something breaks or gets hacked, that's just the cost of business.
Does it actually work? I don't think anyone is going to sign up for DeepGram just to test this out.