Google appears to be preparing a major expansion of what Gemini can do on the Mac. References to a hidden "Additional sandbox options" setting in the Gemini desktop app suggest the AI assistant could soon read and modify any file on a macOS device, open and drive native apps, and browse the web without asking for permission every time, according to a BleepingComputer report citing findings by TestingCatalog.

The feature is not live yet, and Google has not confirmed it. But the strings buried in the app describe a sweeping set of capabilities. With the options enabled, Gemini could read, create, modify or even delete files anywhere on the machine — including files outside the folders a user has explicitly connected to the assistant. A pop-up within the app reportedly also describes the ability to communicate with applications such as Mail, Safari or Messages and perform actions through them. If it ships as described, this would move Gemini from a chat window into something closer to a full desktop agent; more on where this fits in the industry can be found in our AI industry coverage.

What the hidden setting says

The wording Google itself wrote is the clearest signal of intent. "By enabling additional sandbox options, you will be able to expand what Gemini can do and access on your Mac," the hidden interface explains. A second line adds: "Depending on which settings you enable, Gemini may be permitted to take actions without asking for your permission first."

That second sentence is the significant one. Today, agentic features on desktop typically pause for approval at each consequential step. The proposed setting would let users pre-authorize whole categories of actions, trading friction for capability. The setting appears to be part of Google's broader computer-use plans for Gemini, under which the assistant would work across files, websites and native apps instead of being confined to a conversation.

Safeguards around the sensitive stuff

Google is not describing unlimited control. According to the report, the company plans a Claude-style experience in which users explicitly grant the assistant permission to use their computer, and Gemini would still ask for confirmation before a set of high-stakes actions: buying products or transferring money, creating an online account, accepting legal terms on a user's behalf, or modifying sensitive personal information.

That split — blanket permission for routine actions, explicit confirmation for irreversible or financial ones — has become the de facto design pattern for computer-using agents. It acknowledges an uncomfortable truth about agentic AI: most of an agent's value comes from not asking, and most of its risk comes from exactly that.

A crowded, contested desktop

The timing is not accidental. Assistants that operate a computer are rapidly becoming the main battleground for consumer AI, with every major lab racing to move from answering questions to completing tasks. An assistant that can navigate files, applications and the web in one session can book, file, organize and purchase on a user's behalf — a categorically different product from a chatbot.

It also lands in the middle of a platform fight over who gets to say what AI agents may touch. Apple is considering making it harder for AI agents to access personal files and data on the Mac, as BleepingComputer notes, which could directly constrain how a feature like this works in practice. How Google's plans and Apple's instincts collide on macOS will shape what desktop agents can actually ship — and the same tension is playing out on Windows, where operating-system vendors are similarly weighing how much of the file system an AI assistant should be allowed to roam.

Not live, not confirmed, not final

Caution is warranted on several counts. The feature is buried, unfinished and unacknowledged; Google has said nothing publicly. It is unclear when Full Access would roll out, which Gemini model would power it, or whether the capabilities described in the strings will survive contact with security review. Hidden settings regularly change or disappear before release, and references spotted in app code are a signal of direction, not a product announcement.

Still, the direction itself is informative. Google's assistant is being built to operate computers, with graduated permissions and category-based confirmations designed in from the start. When it arrives, the practical questions for users will be concrete: which files can the assistant see, which apps can it drive, what happens to a Mac's standby battery while an agent works in the background, and how reliable the undo path is when an agent deletes the wrong thing. The answers to those questions — not the demo videos — will decide whether people hand their desktops to an AI.

---

Stay Ahead of AI

Get the latest AI news, analysis, and breakthroughs — all in one place.

Read more AI news →