Google Gemini could soon get full access to your Mac’s files, apps and the web
Google Gemini may soon gain full access to Mac files, apps, and web browsing.
Summary
Google is reportedly testing a new feature for its Gemini AI that would grant it extensive access to a user's macOS device. This 'desktop control' could allow Gemini to read, modify, or delete files, interact with apps like Mail and Safari, and perform actions without explicit permission for each instance. While safeguards are planned for sensitive actions, the move raises privacy concerns and could conflict with Apple's own data access considerations for AI agents.
Full text
Google Gemini could soon get full access to your Mac’s files, apps and the web By Mayank Parmar October 3, 2026 07:12 PM 0 Google's Gemini could soon access any file on your macOS device, open apps, browse the web, and perform actions without asking for permission every time. As spotted by TestingCatalog on X, Google is testing desktop control for Gemini, and there are references to a new hidden "Additional sandbox options" setting in the Gemini Desktop app. The feature isn't live yet, and Google hasn't confirmed it either, but when enabled, Google Gemini could read, create, modify, or even delete files anywhere on your PC. That means Gemini will have access to files outside folders you have explicitly connected to Gemini. It's unclear how the feature will play out, as Apple is considering making it difficult for AI agents to access personal files and data on Mac. According to a pop-up within Gemini Desktop, Google's AI could also communicate with apps such as Mail, Safari, or Messages and perform actions through them. "By enabling additional sandbox options, you will be able to expand what Gemini can do and access on your Mac," Google explains in the hidden interface. "Depending on which settings you enable, Gemini may be permitted to take actions without asking for your permission first." Gemini would still ask before sensitive actions Google is not giving Gemini unlimited control without any safeguards, and you can expect a Claude-like experience, where you explicitly give it permission to use your PC. Gemini would still ask for confirmation before buying products or transferring money, creating an online account, accepting legal terms on your behalf, or modifying sensitive information about you. The setting appears to be part of Google's broader computer-use plans for Gemini, where the AI would be able to work across files, websites, and native apps instead of being limited to a chat window. It's unclear when Google plans to roll out Full Access or which Gemini model will power it. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: Hackers build AI frameworks for widescale credential theftHow Anthropic plans to watermark Claude's AI-generated textAnthropic turns Claude into an AI marketplace with 2,000+ plugins and connectorsClaude Opus 5.5 uses 95% fewer em dashes, but its answers are getting longerAnthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions