
Google Gemini Mac file access test surfaces in desktop app
A hidden Google Gemini desktop setting on Mac suggests the assistant may soon read, modify, or delete files and control apps, with safeguards for sensitive acti…
Google is testing a hidden Google Gemini Mac file access option in its Gemini Desktop app that could eventually let the assistant read, create, alter, or delete files anywhere on a user's macOS computer, open applications, and browse the web, according to a report by BleepingComputer based on findings shared by TestingCatalog on X. The feature is not live yet, and Google has not confirmed the capability, but references to a new hidden setting called Additional sandbox options appear in the desktop app.
When enabled, this broad access would go beyond the folders a user has explicitly connected to Gemini. A sandbox is normally a restricted environment that limits what a program can reach, and expanding it weakens those limits. In other words, the assistant would not be limited to selected files or directories and could act on any file it can reach. A hidden dialog in the app explains that expanding these sandbox options broadens what Gemini can do and access on a Mac, and that depending on which toggle is turned on, the assistant may be allowed to take actions without asking for permission first. It could also communicate with applications such as Mail, Safari, or Messages and perform actions through them.
The report notes several unknowns. Apple is reported to be considering ways to make it more difficult for AI agents to access personal files and data on Mac, which could shape how Google ultimately rolls out the feature. AI agents are programs that can carry out multi-step tasks such as opening apps and reading files. It is also unclear when Google plans to make the full access feature available or which Gemini model will power it. Because the setting is not yet live, the exact behavior and safeguards may change before any public release.
Google is not giving the assistant unlimited control without boundaries. The design appears similar to the computer-use experience seen with Anthropic's Claude, where a person explicitly grants permission to use the computer. According to the source, Gemini would still ask for confirmation before sensitive actions such as buying products or transferring money, creating an online account, accepting legal terms on a user's behalf, or modifying sensitive personal information. This means the broad file and app control would, in principle, coexist with confirmations for high-risk steps.
The hidden setting is part of Google's broader computer-use plans for Gemini, which aim to let the assistant work across files, websites, and native applications instead of being confined to a chat window. For website owners, businesses, and IT teams, an assistant with such deep access on a work Mac raises practical permission questions: any saved login, backup file, customer list, or browser session could sit within reach of the same tool that handles everyday tasks. That makes it important to follow the principle of least privilege and to review what an assistant is allowed to touch.
Until Google releases the feature and documents its safeguards, users should treat the hidden setting as experimental and avoid enabling it on devices that hold important data. For organizations that want to review and limit how AI assistants access business endpoints, AEU-I provides security-first IT and infrastructure consulting that can help establish clear permission boundaries. The broader lesson stays the same as with any powerful automation: the more a tool can do on its own, the more carefully its permissions need to be chosen and checked.
How to Protect Yourself
- Do not enable hidden or experimental settings in Gemini until Google makes them official and explains the safeguards.
- Review which folders and apps your AI assistant can already reach, and remove any that are not necessary.
- Keep your Mac and the Gemini app updated so you receive security fixes as soon as they are available.
- Avoid giving an AI assistant the ability to delete files or act without permission on a device that stores work, customer, or website login details.
- If you manage website or customer data on a Mac, keep that data out of any assistant's reach and back it up separately.
Terms Explained
- sandbox A restricted area inside a computer where a program can run without touching the rest of your files or settings; additional sandbox options would widen those limits.
- AI agent A computer program that can carry out multi-step tasks for you, such as opening apps, reading files, or filling in forms.
- macOS The operating system that runs on Apple Mac computers.
- Gemini Desktop app Google's assistant program that runs directly on a computer rather than only inside a web browser.
- computer-use A capability that lets an AI control a computer by clicking, typing, opening programs, and looking at what is on the screen.