Google appears to be developing a feature that would let its Gemini AI assistant operate far beyond the confines of a chat window on macOS, potentially gaining the ability to read, create, modify, or delete files anywhere on a user’s Mac.
The discovery comes from researcher TestingCatalog, who spotted references to a hidden “Additional sandbox options” setting inside the Gemini Desktop app. The feature is not yet live and Google has not officially confirmed it, but code strings point to a significant expansion of what the assistant can do on a user’s machine.
According to text found within a pop-up in the Gemini Desktop interface, enabling the additional sandbox options would let Gemini “expand what Gemini can do and access on your Mac.” Critically, the interface warns that “depending on which settings you enable, Gemini may be permitted to take actions without asking for your permission first.”
Beyond connected folders
Currently, Gemini’s file access is limited to folders users explicitly connect. The new setting would remove that boundary, allowing the AI to reach files outside those approved locations. The feature would reportedly also let Gemini interact directly with native macOS apps such as Mail, Safari, and Messages, performing actions through them rather than just reading their content.
Guardrails still in place, for now
Despite the broad access implied by the setting, Google appears to be preserving some safeguards. Based on the interface text, Gemini would still require explicit user confirmation before taking high-risk actions, including purchasing products, transferring money, creating online accounts, agreeing to legal terms on a user’s behalf, or modifying sensitive personal information. That approach would mirror permission models used by other AI agents that ask for approval before sensitive operations while automating lower-risk tasks freely.
The timing is notable given that Apple is reportedly considering restrictions that would make it harder for AI agents to access personal files and data on Mac, suggesting potential friction between platform-level privacy controls and third-party AI agents seeking deep system access.
What this means for security teams
No rollout date or supported Gemini model has been confirmed. Still, the discovery signals Google’s broader push toward “computer-use” AI agents capable of acting across files, websites, and native applications rather than staying confined to a chat interface. For security teams, any future rollout of unrestricted file and app access for an AI agent warrants close attention to permission scoping, audit logging, and endpoint policy controls before enabling such features in managed environments.
