← Back to posts

Desktop, Browser, or OS: Where Will the Primary Agent Live?

Each surface owns different context and control. The durable winner will preserve task identity, permissions, and state across surfaces rather than monopolize one screen.

Agents are competing across three surfaces. Desktop applications can coordinate files and software, browsers hold SaaS identities and web state, and operating systems control permissions, notifications, and devices. They may all click interfaces, but they own very different context and responsibility.

Project Mariner centers browser tasks, while OpenAI and Anthropic's computer-use systems operate across interfaces. In November 2025, Microsoft introduced Agent Workspace as an operating-system isolation layer. Together, these approaches expanded the category from a chat destination into a contest over the execution environment.

Browsers benefit from structured pages, existing accounts, and rapid deployment, but have limited access to offline files and local applications. Desktop agents can assemble a fuller workspace, while inheriting broader permissions, application variability, and a larger security radius.

An OS agent can coordinate windows, files, notifications, and hardware, giving it the strongest global state. It also demands exceptional user trust and may disintermediate third-party services. The deeper the entry point, the broader the capability and responsibility.

No single surface is likely to absorb every task. Procurement may start in a browser, document work continue on desktop, and background scheduling live at the system layer. The scarce asset is task continuity across surfaces: goals, progress, permissions, and evidence should travel together.

Product strategy should begin with a high-frequency home field. Browser products can master web state and identity isolation; desktop products can master files and multi-application delivery; OS products can master sandboxes and recovery. Claims of controlling the whole computer too early will exhaust trust.

Entry-point value should be measured through task coverage, authorization conversion, takeover, and cross-application completion, not launches alone. Preinstallation drives exposure but cannot compensate for fragile execution. Users will revoke a powerful agent that repeatedly needs repair.

The contest will become one of protocols and trust. The winning agent may not own every screen; it will own the canonical task state. It will know where work began, how it continues, and how the user can understand and reclaim control.

— End —