Notes on the agent-native operating system — trust, inspectability, local-first, and life after the app model.
Before flipping a repo public, hash your invention disclosures and anchor them on-chain. Defensive publication for open-source projects, done verifiably.
Bolting guardrails onto individual AI apps can't make agents trustworthy. Agent trust is a systems property — it belongs at the OS layer.
The application window assumes a human driver. When the agent drives, the right agent-native interface is a delivery window it opens, fills, and closes.
Agent work should be logged, timestamped, attributable, and replayable — inspectable AI agents are the opposite of today's write-only agent work.
A trustworthy agent runs local-first — a model on your machine — with hosted models on tap, not on the critical path. Continuous with privacy and trust.
An agent-native OS makes the agent the interface — not an app on top of a desktop. Here's what that means, and why the OS layer is where it belongs.