Skip to main content

Rabbit OS3 works without r1, but its own terms still call it a preview

The public release brings Rabbit's agent to PCs without its handheld. Its terms describe a technical preview, cloud data flow and a Full Access permission mode.

A generic laptop displays a glowing folder within an abstract node network, with a small server on the desk behind it
TechKili · AI-generated illustration with Cloudflare FLUX
Share this article:
In this article

Rabbit released OS3 to the public on September 22, 2026, so a person can use its AI agent through a browser and a computer without buying an r1 handheld. That is the concrete shift from an invite-only beta and a product story centered on Rabbit's hardware. The dated Rabbit announcement calls OS3 a general release, and The Verge reported the standalone agent the same day. Yet Rabbit's September 22 terms still label OS3 and its local agent a technical preview and say they are not intended for production, enterprise, regulated, safety-critical or unattended use. Public access and readiness for critical work are different claims.

What runs on the computer, and what stays in the cloud

OS3 coordinates tasks in Rabbit's cloud. To work with local files or applications, the user installs and pairs a separate rabbit agent on Windows, macOS or Linux. Rabbit says one account can connect up to five devices, and its support guide says a paired machine must be awake and online while a task runs. The r1 becomes one way to reach the system, not a requirement for desktop use. This also explains why adding a computer changes the stakes: the agent may use its terminal, files, installed tools and, when needed, screen control.

"Local agent" does not mean all task data remains local. Rabbit's privacy policy says task-relevant selected file content, conversation context and tool results can be sent through Rabbit's service to the chosen model provider. Rabbit says it does not retain a copy of the original local file, while conversation turns and extracted memory are stored. Those are the company's stated handling rules, not an independent audit of its implementation. Anyone connecting work documents should review both Rabbit's policy and the chosen model provider's terms.

The permission mode matters more than the launch label

Rabbit describes two layers: operating-system permissions granted locally and OS3's own approvals for actions. Its terms distinguish Ask Every Time, Ask for New Permissions and Full Access. In Full Access, the terms say the agent may send messages, change or delete data and initiate transactions without asking again. Rabbit's press release says sensitive actions require confirmation, but that simpler assurance does not describe the full range of permission settings. Users should check the mode shown in their account rather than infer it from launch language.

This is not proof that OS3 will make a harmful change, and Rabbit has not supplied independent reliability results for the new general release. It is a reason to match permissions to the consequences of a task. A narrow trial on a computer without sensitive accounts, using Ask Every Time and a reversible job, can show whether the agent handles the workflow as expected. Keep important files backed up, watch what it proposes, and review each consequential action. For shared or regulated work, Rabbit's own preview terms are a clear reason to wait for a product and controls explicitly supported for that setting.

Sources