为智能代理设计新型操作系统,解决传统系统无法承载其动态行为的问题。
Agent Operating Systems (AOS): Integrating Agentic Control Planes into, and Beyond, Traditional Operating Systems
- 将智能体的控制平面融入或超越传统操作系统架构
- 提出调度、状态管理、权限控制等六类AOS核心职责
- 适合研究系统安全与可管理性的开发者和安全工程师
传统操作系统围绕确定性程序、明确控制流和人工启动的工作流设计,其核心抽象如进程、线程、系统调用、文件和权限假设行为有限且可预测。智能体人工智能系统则引入不同执行模型:长期运行、目标驱动的实体,具备概率推理能力,动态调用工具,并根据反馈自适应行为。尽管当前智能体可作为用户空间应用实现,但其执行特性对操作系统的调度、内存与状态管理、安全、可观测性和治理能力构成压力。本文提出智能体操作系统(AOS)概念,一种将智能体控制平面集成到现有操作系统中,或在某些模型中逐步接管部分操作系统职责的系统架构。我们明确定义了AOS,列出显式假设与非目标,并将职责结构化分解为调度器、上下文与内存管理、工具与能力注册表、策略与信任强制、可观测性与审计。分析经典操作系统抽象在智能体工作负载下的局限性,提出从用户空间运行时到分布式控制平面的集成方案,并将AOS概念映射至Linux和Windows原语。探讨安全与可靠性影响,包括智能体特有威胁模型,定义强调确定性执行、可审计性和操作者可理解性的评估标准。目标并非全面替代操作系统,而是建立一个可控制、可问责、可安全扩展的智能计算系统基础。
原文摘要 · Abstract (English)
Traditional operating systems were designed around deterministic programs, explicit control flow, and human initiated workflows. Their core abstractions processes, threads, system calls, files, and permissions assume bounded behavior and predictable interaction patterns. Agentic AI systems introduce a different execution model: long-lived, goal-directed entities that reason probabilistically, invoke tools dynamically, and adapt behavior based on feedback. While agents can be implemented as user-space applications today, their execution characteristics stress OS boundaries in scheduling, memory and state management, security, observability, and governance. This paper introduces the concept of an Agent Operating System (AOS), a systems architecture that integrates an agentic control plane into existing operating systems or, in some models, subsumes selected OS responsibilities over time. We provide a precise definition of an AOS, explicit assumptions and non-goals, and a structured decomposition of AOS responsibilities into schedulers, context and memory management, tool and capability registries, policy and trust enforcement, and observability and audit. We analyze limitations of classical OS abstractions for agent workloads, propose integration models from user-space runtimes to distributed control planes, and map AOS concepts onto Linux and Windows primitives. We present security and safety implications, including agent specific threat models, and define evaluation criteria that emphasize deterministic enforcement, auditability, and operator comprehensibility. The objective is not to replace operating systems wholesale, but to establish a rigorous systems foundation for agentic computation that remains controllable, accountable, and secure at scale.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。