Product1 publisher3 min readPublished
Rabbit's OS3 makes the R1 optional and runs on the user's own API key
The company known for a pocket gadget now ships a cloud agent that installs on up to five Windows, macOS or Linux machines and runs on whatever model subscription the user already pays for. Four rival agents got there first.
The Product Desk · Product desk

What happened
- Rabbit unveiled OS3 on Tuesday, a personal agent that runs in the cloud and reaches into a user's devices through the rabbit agent, which installs with a single command on up to five machines.
- Rabbit says the agent acts only on user instruction, asks for consent on sensitive actions, has system-level permissions requested by the operating system, and lets users revoke them at any time.
- SiliconANGLE places OS3 in a crowded category, naming OpenClaw, Hermes Agent, Instinct and Muse as personal agents already running on consumer devices.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- cost Bring-your-own-key puts the running cost on the person who installed it, and the announcement did not price OS3 or cap what the key can spend during overnight background work.
- decision Anyone approving this is deciding whether a cloud orchestrator gets file-level reach on as many as five endpoints, in exchange for not being locked to one model vendor.
- capability Because swapping models keeps context, memory and skills intact, a user can move the cheap tasks to a cheap model and keep a hedge against any single provider's price changes.
- constraint With the R1 optional, Rabbit is now judged on software against Anthropic's own always-on agent, and the gadget no longer gives it a distribution advantage to defend.
The install is where this lands for whoever owns the endpoints. One command per machine, up to five machines, and each one gives a cloud service a path into local files [3]. Rabbit says the agent acts only in response to user instructions and will not start tasks on its own, that sensitive actions require consent and confirmation, that system-level permissions are requested locally by the operating system, and that permissions can be revoked at any time [12]. Those are four separate promises a reviewer has to check, one at a time, on the laptop that holds customer data.
OS3 is model agnostic, but the user brings the key: an Anthropic Claude or OpenAI GPT subscription, a local model, or an aggregator account such as OpenRouter [5][6]. Rabbit says the agent swaps models without affecting context, memory or skills, so a user can send cheap tasks to cheap models [6]. The other half of bring-your-own-key is that the meter sits with the user. The agent runs in the background around the clock and contacts the user when a long task finishes [9], and every one of those tokens bills to the key on those five machines. SiliconANGLE's write-up does not include a price for OS3, a spend cap, or any usage figures [17]. Getting started requires a Rabbit account [14].
Read the install list and the hardware question is already settled. OS3 runs on local Windows, macOS and Linux machines, on cloud virtual machines, on dedicated AI machines, and on the R1, with more device types planned [13]. Six target types, one of them Rabbit's own device [16]. Rabbit is best known for a pocket AI gadget [2]. The company says the R1 is not required to run or operate OS3, though it does work with it [13].
SiliconANGLE describes a glut of personal agents already shipping, naming OpenClaw, Hermes Agent, Instinct and Muse [4], and reports Anthropic's Claude Dispatch running local agents on a user's PC while the user is elsewhere, with access to local files [10]. Five named alternatives are doing roughly this [15]. Rabbit's stated differences are model portability and skill import: paste a skill's URL from another agent and OS3 sets it up without command prompts or extra configuration [11].
"We've spent two and a half years building toward a system you don't operate, but instead just tell it the outcome," said Chief Executive and founder Jesse Lyu [7].
Two axes sort this decision for the person who has to approve it: whose credentials the agent uses, and where the work executes. OS3 sits where the user holds the key and Rabbit holds the orchestration, with execution on the user's own machines [5][3]. Claude Dispatch sits where the subscription and the runtime both belong to the model vendor [10]. The first is cheaper to walk away from. It is also quieter, because a personal key on five machines produces no central invoice, and the invoice is usually what tells an IT team a new agent exists.
The useful test before the fifth install is to name the machine in the set you would not put it on, and write down what is on that machine. If the answer is the laptop with customer files, then what is being evaluated is remote execution on an endpoint that already has your file permissions, and the consent prompt is the whole control surface between an instruction and that data [12].
What to watch
- Whether Rabbit publishes a price for OS3 or any spending cap on the user-supplied key.
- Whether Rabbit documents what a skill pasted in by URL is permitted to do on install.
- Whether Anthropic moves Claude Dispatch out of testing, putting a bundled subscription against bring-your-own-key.