Rabbit OS3 moves its agent beyond the R1 into browsers, chats and up to five computers, making permissions and model costs the real adoption test.
Key takeaways
- OS3 is generally available as a cloud agent that connects to Windows, macOS and Linux machines.
- One account can connect up to five devices, while users bring their own model API keys.
- The product shifts Rabbit from dedicated AI hardware toward a permissioned software control layer.
What happened
Rabbit released OS3 on September 22 as a cloud-based agentic system that can coordinate work across computers, web services and the company’s R1 device. A local Rabbit agent connects Windows, macOS or Linux machines, while the main interaction can happen through a browser, Telegram, iMessage or the R1. Rabbit says one account can connect as many as five devices and route a task to the machine that has the required file or application.
Why Rabbit OS3 changes the original R1 proposition
Rabbit OS3 separates the company’s agent software from the orange handheld that made Rabbit famous. The R1 remains an access point, but it is no longer required. That matters because the original hardware pitch asked customers to carry another device. The new proposition asks them to install a local controller and grant it access to devices they already use. The addressable market becomes larger, but the trust burden also rises.
The operating model is bring your own model
Rabbit does not bundle a single mandatory foundation model. Users provide API keys for services such as OpenAI or Anthropic, or connect a local model. The company says the agent can switch models without losing its task context, memory or installed skills. This can give users more control over cost and capability, but it also makes billing, data handling and provider terms part of the setup rather than an invisible platform decision.
Permissions are now the product boundary
A cross-device agent is useful precisely because it can reach files, applications and accounts. Those same powers create the main deployment risk. Rabbit says sensitive actions require consent, local operating-system permissions remain in force and users can revoke access. The practical test is whether people can understand which machine, model and skill handled each step. Clear logs and narrow permissions will matter more than a polished chat screen.
Universal skills widen capability and supply-chain risk
OS3 can install compatible third-party agent skills from a public URL. That reduces setup friction and lets the product benefit from an ecosystem it did not build alone. It also turns skill provenance into a security question: users need to know who authored a skill, what it can access and whether its code changed. Enterprises should treat imported skills like software dependencies, with review, version control and revocation policies.
What buyers should test first
Teams evaluating Rabbit OS3 should begin with reversible tasks on a non-sensitive machine. Measure completion rate, human correction time, model charges and the number of permission prompts. Then test failure cases: an unavailable computer, a stale API key, a conflicting instruction and an attempted sensitive action. Rabbit OS3 will earn trust only if users can predict how it fails and can stop or undo work without hunting across devices.
The larger consequence
Everyone else is reporting that Rabbit launched another AI agent; we are explaining why the shift from hardware to orchestration changes the buying decision. Rabbit OS3 is not mainly a replacement operating system. It is a coordination layer spanning models, devices and skills. Its advantage will come from reliable execution across those boundaries, while its weakness will be any ambiguity about permissions, data routes or accountability.
Facts table
| Public disclosure | 22 September 2026 |
|---|---|
| Availability | General release |
| Connected devices | Up to five per account |
| Desktop support | Windows, macOS and Linux |
| Model access | User-supplied API keys or compatible local models |
Frequently asked questions
Does Rabbit OS3 require an R1?
No. Rabbit says OS3 works through the web and connected computers; the R1 is an optional access device.
Where does Rabbit OS3 run?
The service runs in the cloud and uses a local Rabbit agent to operate connected computers.
How does Rabbit OS3 access AI models?
Users bring their own provider API keys or connect compatible local models.
What should businesses evaluate first?
Permission scope, audit logs, data routing, task reliability and total model cost should be tested before sensitive deployment.
Related Lapaas Voice coverage
- Intrinsic Core opens industrial robotics stack
- Darktrace SECURE AI reaches general availability
- Claude Opus 5.5 cuts premium model cost
Verification sources: Rabbit newsroom Rabbit OS3 terms WIRED SiliconANGLE
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.



