cyberivy
Holo4H CompanyComputer UseAI AgentsOpen WeightsHugging FaceMCPAgent Security

Holo4 opens computer control to local AI agents

September 28, 2026

Eine stilisierte Computeroberfläche mit mehreren schwebenden Fenstern und einem zentralen Holo4-Symbol

H Company releases Holo4 with open weights for screens, code, MCP, and APIs. The models are more inspectable than closed agents, but their benchmarks need context.

What this is about

H Company released the Holo4 model family on September 28, 2026. It is designed to operate software through more than one interface: depending on the task, it can click and type, execute code, or call MCP and API tools. The weights are available on Hugging Face in several formats. That makes the release relevant to developers who want to run, inspect, or adapt computer-use systems themselves.

Holo4 comes as a dense 27-billion-parameter model and a mixture-of-experts model with 35 billion total parameters and 3 billion active parameters. Holotron4 Nano is also part of the release. The main news is not one top score, but the combination of open weights, several interaction modes, and published execution traces.

What Holo4 actually does

A Holo4 agent can interpret screen content and produce mouse or keyboard actions. When an application offers better interfaces, the same model can use code, MCP, or APIs instead. H Company says it trained the models with supervised and reinforcement learning across interactive environments. An internal Agentic Task Factory reportedly produced about 10,000 tasks from documentation.

On OSWorld 2.0, H Company reports 61.7 percent for Holo4-27B. In the same comparison, it lists Claude Opus 5.5 at 81.8 percent. Holo4-35B-A3B reaches 30.9 percent. These figures come from different releases, subsets, and harnesses, so they are not a clean head-to-head comparison. A useful transparency measure is that H Company provides trajectories from public benchmark runs for replay and download.

Why it matters

Computer-use agents are difficult to audit. A final score can show whether a task succeeded, but not reliably reveal which intermediate decisions were unsafe. Open weights and trajectories let researchers and security teams inspect failures more closely. That matters when agents can access files, signed-in browser sessions, or business systems.

The release also gives smaller providers an alternative to fully closed services. BF16, FP8, NVFP4, and 4-bit GGUF variants support different deployment choices. Yet open does not automatically mean cheap or suitable for every local machine. A 27B model still requires substantial compute, and long tasks can consume many calls and tokens.

In plain language

Imagine a craftsperson who knows more than one tool. Before a job, they choose between a screwdriver, a drill, or direct access to a control panel. Holo4 is meant to switch similarly between screens, code, and interfaces. Its published trajectories are like a work log: you can inspect every attempted step, not only the finished shelf.

A practical example

A mid-sized company wants to check 120 supplier invoices each morning in a legacy desktop application. An agent reads the screen, retrieves structured data through an API, compares amounts with a script, and sends ten unclear cases to people. Before production, the team tests 500 historical invoices in an isolated environment.

If the agent handles 460 correctly, escalates 25 appropriately, and misclassifies 15, the important work is not the polished demo. The team must analyze those 15 failures, limit permissions, and ensure that payments are never approved automatically. Holo4 provides technical building blocks, not a finished control system.

Scope and limits

First, the central performance claims come from the vendor. Published trajectories do not replace independent replication on identical tasks and hardware. Second, screen agents can fail when interfaces change, pop-ups appear, or content is misleading. Third, open weights do not solve security by themselves: sandboxing, least privilege, logging, and human approval remain necessary.

Holo4 therefore does not prove that general office work can now run reliably without supervision. H Company's examples are ambitious, but they also show very high call and token counts. Adopters should measure success, cost, and unintended actions in their own workflows.

SEO & GEO keywords

Holo4, H Company, computer use, AI agents, open weights, Hugging Face, OSWorld 2.0, MCP, GUI automation, local AI, agent security

💡 In plain English

Holo4 is an open model family that can operate software through screens, code, and interfaces. Developers can inspect its weights and example runs, but still need to isolate the agent and limit its permissions.

Key Takeaways

  • →Holo4-27B and Holo4-35B-A3B are available with open weights in several formats.
  • →The models can combine GUI actions, code, MCP, and APIs within one workflow.
  • →H Company publishes trajectories from public benchmark runs for inspection.
  • →The reported 61.7 percent OSWorld score for Holo4-27B is not a fully independent comparison.
  • →Sandboxing, least privilege, and human approval remain necessary in real deployments.

FAQ

Is Holo4 open source?

Model weights and several variants are available on Hugging Face. Developers should still check the specific license shown on each model card before use.

Can Holo4 operate software without an API?

Yes. It is designed for mouse and keyboard actions in graphical interfaces and can also use code, MCP, or APIs.

Will Holo4 run on any laptop?

No. Even quantized versions of a 27B model require substantial compute and memory, and practical speed depends heavily on hardware and context length.

Are the benchmark results independently confirmed?

The release includes inspectable trajectories, but central figures come from H Company. Independent replication remains important.

Sources & Context