The Agentic OS



What will the future look like?

The basic structure is the brain. Everyone will have a single monorepo of all their information called the brain.

Each person will have a superintelligent agent to do things for them. These agents will communicate 24/7 with other agents.

The agents will have a variety of work - short-running tasks like "order food and groceries" and long-running open-ended tasks like "make me healthy".

Your friend's agent and yours will communicate daily, in the background. Your brain will be guarded by a firewall.

The firewall will process signed requests from other agents for information, interpret them in context of a policy prompt inside an isolated context, and then grant a temporary, revocable view of the permitted information. The firewall may also prompt the user to approve/deny. The view contains paths into the brain. Before information is transmitted out, the firewall applies an optional outgoing policy prompt, which can rewrite the information e.g. to disclose only summaries, rather than source material. All access is logged.

With a working firewall, the next task is to scale up the brain and its threads. Users will have a thread for every area of life:




Each thread will be granted scope over a different part of the brain. Each thread may consist of one to many agents, each a different model (GPT-5.6, Qwen, Kimi), each a different provider (locally-hosted, cloud). Each thread will have attached context (brain). Each thread will have history (conversation messages). Each thread will have communications with other agents.

It is important that we develop a uniform personal AI runtime for developers to deploy threads and agents to, so that people can focus on writing prompts.

The runtime will allow people to define agents, transient jobs, long-running threads, models, model providers. It will orchestrate spinning up agents, conversations, threads. Users will be able to open and attach to any agent, ad-hoc create new agents to supervise and drive clusters of others. It will be possible to send messages to many agents at once. It will include the ability to live update the permissions/scopes of agents, as they are running. When new models are released, the model is downloaded, defined, instrumented, and like "hot reload", agent threads are swapped out to run on the new model with the same context. Users will not notice the change - their "steering device" (the CLI harness, probably) will simply retain the same long-lived connection.

This might work like an operating system for intelligence-ware. Users can install an "insurance renegotiation agent", a "healthcare peptide agent", a "therapy agent".

Why agents? A business might assign one agent per client/customer. Each agent can attend to their exact needs and deeply personalise their service offering. But why would the customer want to be interacting with an agent? It is dull work, answering questions. The client would have an agent too.

At a certain point, the customer might be comparing two businesses for their services. In order to get the best deal, could they have the three agents (business A, business B, and the customer's personal agent) in a group chat? Maybe your friend is also a customer of this business - your agent can reach out to their agent and ask questions about their rates/gossip.

This is all possible today, but it is constrained by ergonomics. I have a brain (Obsidian inside Dropbox). I have multiple persistent agents (Claude Code, Codex) on my main PC. I DO NOT HAVE a way to easily switch between providers (OpenAI, Anthropic), I DO NOT have a way to retain my conversation history, I DO NOT have a way to easily "install" agents like apps BUT WHILE ALSO retaining my data's confidentiality. I built an AI dietician/doctor by building a custom diet/nutrition/journalling app that I exposed via MCP. HOW CAN I share this information with my doctor's GP office, automatically? How can I spin up another agent, "deep research for my health", while ensuring it doesn't leak random other data? How can I get my own agent to talk to my friend's agent, 24/7, without leaking my data? Where do those conversations go, do they get retained? How can I log-in to my agent cluster, attach to any agent, whether it be claude, codex, or local qwen, and supervise it without doing lots of custom stuff?