Rabbit released OS3 on September 22 as a browser-based agent system that can use a person’s own models and computers. An r1 is now optional: the same Rabbit account can be reached on the web, through paired messaging channels or through the handheld device.
That shifts the decision away from buying dedicated hardware. The questions become which model to connect, what computer access to grant and where task data goes.
The big change
- What changed: Rabbit has separated its agent system from the r1. A browser can be the main workspace, while an optional local worker gives the cloud service access to approved files, tools and commands on connected computers.
- Why it matters: The price of entry is no longer a hardware purchase. Cost and control instead sit across three places: Rabbit’s interface and memory, the model account behind a bring-your-own-key connection, and the permissions granted on each computer.
- What to watch: Rabbit advises against production and enterprise deployment. Its technical-preview warning needs reading alongside the launch announcement.
The r1 is now one way into OS3
Rabbit’s OS3 explainer says the full workspace runs in a browser and does not require an r1. Telegram and the r1 are additional channels into the same account. Their conversations remain separate, while drawing on shared memory and relevant context.
The company calls OS3 generally available, and its September 22 announcement says users can start from the website. Rabbit also says its local agent can connect Windows, Mac or Linux computers. Those are access and architecture claims, not evidence that every operating system, application or third-party skill works equally well.
The earlier Rabbit Intern is no longer a standalone public product. Existing creations remain, with specialist capabilities continuing within OS3.
The computer worker is local, but OS3 is not offline
Rabbit’s local agent works mainly through the terminal, using supported files, tools and commands. Each connected computer is a node; projects can span several.
Rabbit’s detailed FAQ describes a hybrid system: cloud coordination, requests to the selected model provider and local execution. Its terms require internet access; disconnected nodes cannot receive work.
Operating-system permissions and OS3 approvals are separate. OS3 can ask each time, remember permissions or grant Full Access without further confirmation. Users remain responsible for supervising consequential actions.
Rabbit OS3 uses BYOK, so model usage still costs money
Bring your own key means connecting a supported provider’s API key or endpoint. Rabbit’s support page says OS3 is free; model usage is billed by the provider, and compatibility can change.
Provider changes are manual, not automatic for each task. Rabbit’s product page says memory, skills and computer connections survive a switch. It does not establish that Rabbit memory is portable to another agent product.
Rabbit’s privacy policy says it stores encrypted BYOK credentials and routes input to the chosen model provider. The terms warn that tasks can trigger repeated model calls, so token prices alone do not establish task cost.
General release and technical preview are both true
The September 22 terms call OS3 a technical preview, advising against production, enterprise, regulated, safety-critical or unattended use. They also license authorized internal business use. That is deployment guidance, not a blanket commercial-use ban.
Local files are not simply confined to the computer. Rabbit’s privacy policy says that when a task needs a file, the relevant content passes through Rabbit’s servers and goes to the connected model provider. Rabbit says it does not keep a copy of the file itself, but it does store conversations, task records and memory used for continuity.
An optional first-run workspace scan is narrower: if selected, it can inspect recent file names, paths, modification metadata and installed applications, but the policy says it does not open file contents. That distinction is useful because the scan and a later task have different data paths.
Removing the hardware purchase makes OS3 easier to try. It leaves the more consequential decisions about model billing, computer access and data processing with the user.



