Rabbit launches OS3: cloud-based AI agent that can control your PC
Two and a half years after the R1 was savaged by reviewers, Rabbit is switching from hardware to software. OS3, launched on Tuesday, is a cloud-based AI agent that can control up to five of your own devices — and the entire business model…

Rabbit launches OS3: cloud-based AI agent that can control your PC
Two and a half years after the R1 was savaged by reviewers, Rabbit is switching from hardware to software. OS3, launched on Tuesday, is a cloud-based AI agent that can control up to five of your own devices — and the entire business model rests on you supplying your own API keys. But the company has not defined which actions count as "sensitive," and task content still passes through Rabbit's servers.
Rabbit Inc. is best known for the R1, the pocket-sized AI device launched with much fanfare at CES in 2024 — and which subsequently drew harsh criticism. On Tuesday, September 22–23, 2026, the company launched OS3, a personal AI agent that runs in the cloud and connects to hardware people already own. The service is already available at os3.rabbit.tech, where new users sign up from a browser and complete setup in a single conversation (SiliconANGLE, Help Net Security).
How it works
The architecture has two parts: a cloud agent at Rabbit and a local "rabbit agent" installed on the user's own machine with a single command. One account can be connected to up to five devices — Windows, Mac, and Linux PCs, cloud virtual machines, dedicated AI computers, and the r1 itself. OS3 decides on its own which device to use for each task (Help Net Security).
The agent is reached via a web portal, Telegram, iMessage, RCS, SMS, or the r1. Third-party "skills" — small extensions that give the agent new abilities — are installed by pasting a URL into the chat. The user thus needs no app store or installation process beyond the local agent.
CEO Jesse Lyu has used OS3 himself for routine work. According to TechSpot, he said he had the agent represent him in a Slack conversation with an engineer while he was unavailable — the agent identified itself as acting on Lyu's behalf and used files from his machine to answer questions (TechSpot). The anecdote is unverified, but it illustrates what the company itself sees as the product's core: an agent that acts in your name, on your devices, with your files.
Pay with API keys, not a subscription
OS3 uses a "bring-your-own-key" model. Rabbit does not charge a monthly subscription, but users must provide their own API keys from providers such as OpenAI or Anthropic — and thus pay for usage directly to the model provider. It is also possible to connect local open-source models. Rabbit promises you can switch models without losing context, memory, or skills (TechSpot).
The model shifts cost risk away from Rabbit and makes the company's revenue model unclear — for a company with 15 employees, according to Lyu himself, that may be the point: the platform is not supposed to carry the bill for infrastructure costs.
That big pivot: from R1 to software
The reversal is total. The R1 is no longer manufactured, and no R2 is planned. The next product, according to the company, is a "Cyberdeck" for "vibe coding" that will run OS3 — beyond that, details about the device are sparse. The point of the strategic shift is clear: instead of selling people a new gadget, the software is meant to work on hardware they already have (TechSpot).
It is not hard to see why. The R1 was met with great attention at CES 2024, but received bitter reviews — WIRED gave it 3 out of 10, concluding that all the "agentic" stuff simply didn't work very well (WIRED). TechSpot describes a long period of updates — roughly 50, according to their interview — without the fundamental agent problems being solved; Help Net Security describes the same period as twelve consecutive months of updates. The two sources do not entirely agree on the timeline, but the picture is the same: the hardware failed to deliver what OS3 is now supposed to deliver in software.
Privacy and security: the company's promises, and the gaps in them
Rabbit highlights several safeguards, and it is important to distinguish between what is verified and what are company claims:
- The company says the local agent does not copy, store, use, or sell the user's files — files are supposed to stay on the machine (Help Net Security).
- The company says OS3 only acts on the user's instructions and does not start tasks on its own. Sensitive actions require the user's consent and confirmation, and system-level permissions are additionally required and granted by the operating system locally. Permissions can be revoked at any time (SiliconANGLE).
But there are two significant caveats. First, Rabbit has not specified which actions actually count as "sensitive" — an obvious gap in the security narrative, as Help Net Security points out. Without a definition, the user does not know when confirmation is actually required.
Second: even though files allegedly stay on the machine, the content of tasks still passes through Rabbit's servers and on to the chosen model provider. Conversations with OS3 — and the memory the agent builds from them — sit on Rabbit's servers. Asking the agent to summarize a contract means, in practice, that the contract text is exposed to Rabbit and, for example, OpenAI or Anthropic. "Your files never leave the machine" and "the agent reads your files" are therefore not contradictions, but the former can easily give an impression that the latter dispels.
None of these privacy claims have been independently verified; they are the company's own statements as reported through the tech press.
A company with baggage
The landscape behind the launch is tangled. According to figures Lyu himself provided to TechSpot — and which have not been independently confirmed — Rabbit has shipped over 100,000 R1 units, has a return rate below 5%, and gross margins of around 45–50% on the hardware. The company is said to have raised around $60 million and has 15 employees.
That stands in contrast to last year's turmoil: a planned India launch was blocked by regulations, and several employees went on strike because they had gone months without pay. Lyu says the company has raised more capital and is now stable — but this, too, is his own account.
What remains
For now, there is no primary company documentation about OS3 — neither a press release nor product pages are included in the available sources; all coverage is secondary reporting. That means details such as availability, waitlists, or usage limits cannot be confirmed.
The big question, however, is the same one that knocked the R1 out of the game: does the agent work in practice? OS3's premise — a cloud agent that operates your PC via chat — is ambitious, and the next round of independent testing will show whether Rabbit has solved the agentic problems this time, or simply moved them from a gadget to your laptop.
Sources
- Rabbit returns with OS3, a personal AI agent that can access files and connect computers - SiliconANGLE — siliconangle.com
- Rabbit launches OS3, an agentic AI platform for desktop, Telegram, and iMessage | TechSpot — www.techspot.com
- Rabbit Is Back, This Time With an AI Agent App | WIRED — www.wired.com
- Rabbit's new OS lives in the cloud and borrows your laptop to get things done - Help Net Security — www.helpnetsecurity.com