Google appears to be developing a feature for its Gemini AI that would grant it extensive access to macOS systems, including the ability to read, modify, and delete files, interact with applications, and browse the web. This potential functionality was identified by TestingCatalog on X, which observed references to a hidden "Additional sandbox options" setting within the Gemini Desktop application.
While not yet live or officially confirmed by Google, the discovered interface suggests that enabling these sandbox options would allow Gemini to operate beyond explicitly linked folders, potentially accessing any file on a user's Mac. The AI could also communicate with native macOS applications such as Mail, Safari, or Messages to perform actions.
According to a pop-up within the Gemini Desktop app, the "Additional sandbox options" would expand Gemini's capabilities and access on a Mac. It further indicates that, depending on the enabled settings, Gemini "may be permitted to take actions without asking for your permission first."
However, the implementation is not expected to grant unlimited control without safeguards. The system is anticipated to function similarly to other AI agents, where explicit user permission is required for certain actions. Specifically, Gemini would still prompt for confirmation before sensitive operations such as purchasing products, transferring money, creating online accounts, accepting legal terms, or modifying sensitive personal information.
This development aligns with Google's broader vision for Gemini, aiming for the AI to seamlessly integrate across files, websites, and native applications, moving beyond its current limitation to a chat window. The timeline for the rollout of this "Full Access" feature and the specific Gemini model that would power it remain undisclosed. The potential for such deep system access also comes as Apple is reportedly exploring ways to restrict AI agents' access to personal files and data on macOS.






