🗺️ The Overview
There are dozens of "AI operating systems" — programs that organize a personal assistant. Here, you’ll learn to compare them thoughtfully, get to know the closest family (OpenClaw, GravityClaw, Hermes, Intelecto), and see what’s out there (AIOS, MemGPT, Operator) — so you can finally know which path to take.
Read from left to right: a single question ("how do I run my own AI?") branches into four categories system—and, crossing the local/cloud and lean/framework axes, converges on a recommended path: start lean, local, and with MCP only.
Learning path map
Detailed content
🧭 How to compare AI operating systems + the category map
Before looking at a specific system: the question they all answer, the 5 criteria for evaluating any of them, the 4 categories on the map, and the two axes (local vs. cloud, lean vs. framework).
Every system in this learning path tries to solve the same thing: "how do I run MY AI — with its own agent, memory, and personality — without being dependent on a closed chatbot?".
When you see the common pain point, you stop comparing names and start comparing answers to the same question. That organizes the whole map.
Your own AI, personal agent, moving beyond closed chatbots, vendor lock-in (being tied to one provider).
Five questions that apply to any system: privacy (local or cloud?), cost (fixed/free or per token?), control/auditability (do you read the code?), effort (clone something ready-made or build it?) and power (how many integrations?).
It's the yardstick you'll use for the rest of the track. Instead of "which is best?" you ask "best on which of the 5 criteria, for MY situation?".
Privacy, cost, auditability (being able to read/review the code), effort, power/integrations.
Systems fall into four groups: (a) research/kernel (AIOS, MemGPT), (b) local assistants/voice (Leon, Jan, Home Assistant), (c) dedicated hardware (Rabbit R1, Humane — poor reception) and (d) agent frameworks (LangGraph, CrewAI, MCP), where most people build.
Knowing a system's category already tells you what it's for — and which one is worth investing your time in (spoiler: frameworks).
Kernel (the core of an OS), framework (a basic structure for building), voice assistant, dedicated hardware.
The factor that most distinguishes the systems: running your machine (private, fixed cost, requires hardware) or in the cloud (powerful, convenient, pay-per-use, and your data leaves your device). Many systems let you CHOOSE per message.
It’s the course’s central trade-off. Understanding that it’s not “one or the other,” but a decision you make for each task, frees you from choosing a side out of ideology.
Local-first, cloud, privacy vs. power trade-off, choose per message.
The second axis: systems lean ("lean" — e.g., Intelecto has ~3,000 lines, no Docker) versus frameworks heavy, with lots of dependencies. The lean thesis: code you UNDERSTAND is worth more than code you clone and never read.
Bloated systems hide security risks and leave you without control. Choosing lean is a security and learning decision, not just a matter of taste.
Lean (lightweight), “less is more,” lines of code, readable code vs. cloned code.
How to cross-reference the 5 criteria and 2 axes in a mental table: for each system in the next module, you'll mark where it falls on privacy, cost, control, effort, and power.
It prepares you to read module 2.2 critically, without being swayed by the number of stars on GitHub.
Comparison table, critical reading, “stars don’t mean security.”
🏠 The family at home: OpenClaw, GravityClaw, Hermes, and Intelecto
The systems closest to our world, side by side: from the bloated, exposed "original" (OpenClaw) to the lean, secure reimplementations (GravityClaw, Intelecto, Antidote) and Hermes—ending with the security lesson that ties everything together.
The system that launched the category (Jan/2026, 250,000+ stars): a personal agent with channels, a tool loop, memory, voice, 700+ skills from the community and heartbeat (heartbeat that makes it act on its own on schedule).
It's the reference everyone copied—but also a cautionary case study: exposed web server (42.665 public instances, 93,4% without a password), 341 malicious skills, $500–5K/month, and 100 thousand+ lines no one reads.
Skill (packaged recipe), heartbeat, exposed web server, bloated code.
A lean, secure reimplementation of OpenClaw in TypeScript: Telegram only (via long polling—the bot fetches messages without opening any ports) and MCP only (the “USB for AI tools,” an open, auditable standard—defined in module 2.3). Fixed cost (~$200) or local, built “brick by brick.”
Shows in practice what changes when you trade raw power for safety and clarity: "a lean, safe, and fully understood personal agent."
Long-polling (fetch messages without exposing a server), MCP, brick by brick, fixed cost.
The “less is more” thesis taken to the extreme: ~3,000 lines of Python, no Docker, no web UI, just Telegram. Memory through SQLite FTS5/BM25 (keyword search) and personality in text files: SOUL.md (the soul), AGENTS.md and USER.
Proof that you can have a complete agent you can read all of in a weekend—cloud (OpenRouter) or local (Ollama), your choice.
Anti-framework, SQLite FTS5/BM25, SOUL.md, AGENTS.md, OpenRouter, Ollama.
A sibling of Intelecto, in an even leaner version. Generates a file .md 100% tool-agnostic (independent of the tool — runs in Codex, Gemini, Cursor) and includes a step-by-step build guide.
Shows the idea of describing your agent in plain text, which works on any host — the seed of the portability you'll see in skills (T3).
Tool-agnostic, .md output, build guide, portability across hosts.
Hermes = a self-hosted agent (one you host yourself), “one brain, many mouths”: it can switch models, has memory, personas, skills, MCP, and cron — becoming a true “AI OS.” claude-hermes-os is a local, read-only dashboard that READS Claude Code/Codex/OpenClaw/Obsidian and shows spending, 3D memory, and skills (with daily “Dream” self-improvement).
It’s the system that gives the ecosystem its name and illustrates the complete “AI OS” you’ll dissect in Track 3 (Anatomy).
Self-hosted, “one brain, multiple mouths,” cron, personas, read-only dashboard.
The family’s takeaway: the biggest failures came from exposure (open servers) and third-party skills (the 341 malicious ones from OpenClaw). The safe path = no ports + MCP only + local-first + whitelist (only your ID is served).
Security isn’t a separate chapter—it’s the criterion that determines which system you should copy. This lesson guides all your choices from here on.
Exposure, third-party skills, whitelist, MCP-only, local-first.
🌍 The world out there (AIOS, MemGPT, Operator) and the way forward
The broader context: the paper that became a system (AIOS), infinite memory (MemGPT), the LLM that runs code (Open Interpreter), assistants and hardware, MCP as the “USB for tools”—and an honest recommendation on where to start.
An academic paper (COLM 2025) that built a OS kernel for agents of AI: scheduler (decides the order of tasks), memory, and storage—making it up to 2.1x faster.
It's proof that the "LLM as an operating system" metaphor (which you saw in T1) has become a real system, not just an analogy.
Paper, kernel, scheduler, AIOS, LLM-OS.
A system of hierarchical memory (core/recall/archival) inspired by how an OS pages memory — moves what matters “closer” and archives the rest. Raised US$10 milhoes.
The key idea—giving an agent “infinite memory” despite its limited context window—is exactly the problem you’ll solve with files + SQLite in T3.
Hierarchical memory, core/recall/archival, pagination, context window.
A tool that lets the LLM run code on your machine — with your confirmation before each execution. Raw power to automate almost anything.
Shows in real time the leap from “responds” to “acts” — and why confirmation and a sandbox (isolated environment) are essential when AI interacts with your computer.
Running code, confirmation, sandbox, power vs. responsibility.
Local/voice assistants (Leon, OVOS, Jan, Home Assistant Assist) and dedicated hardware (Rabbit R1, Humane Pin) that promised to be “the AI device” — and received a lukewarm to poor reception.
The lesson is invaluable: the problem is rarely the hardware. A good assistant comes from the software (brain, memory, tools), not a new gadget.
Voice assistant, dedicated hardware, “the gadget isn’t the point.”
O MCP (Model Context Protocol, by Anthropic, Nov/2024) is a standard that connects any tool to any agent — like USB connects any peripheral to any computer.
It's the piece that makes everything fit together and the reason why "MCP only" is safer than downloading standalone skills from third parties. You'll use it throughout the course.
MCP, "the USB for tools," MCP server, open, auditable standard.
The course’s honest recommendation: start lean and local (Intellect/GravityClaw style, with Ollama), use MCP only, keep a single owner, store memory in files + SQLite — and grow as needed, understanding each building block.
It's the synthesis of the entire track and the direct bridge to T3 (the anatomy) and T4 (building). From here, you move from "comparing" to "building."
Lean + local, MCP-only, single-owner, file + SQLite memory, grow as needed.