Operating systems should work like Android currently does. Assuming all installed apps are potentially malicious and isolates each of them from the others and the OS. So even if an app is compromised there's not much it can do when it's installed.
All desktop and server operating systems currently assume the user should have "full control" making a single compromise fatal for the user or even an entire organization.