Google is reportedly planning to enhance its Gemini Desktop app by introducing a ‘Full Access’ feature. This new capability could allow the AI assistant to read and manage files, control applications, and access network services on a user’s Mac, according to recent findings.
The Scope of Full Access
The feature appears to be part of a hidden ‘Additional sandbox options’ setting in the latest Gemini Desktop app version. Should this be activated, Gemini’s capabilities would expand far beyond its current conversational functions, enabling it to interact with a user’s local environment similarly to trusted desktop applications.
Specifically, these permissions could permit Gemini to access any file on a Mac, even those outside of designated folders. This potential raise in functionality has been revealed through discovered permission text, suggesting that Gemini could read, create, modify, or delete files across the system.
Apple’s Response and Security Implications
In response to these capabilities, Apple plans to enforce stricter controls over Full Disk Access in macOS, acknowledging the risk of exposing users’ private data as AI becomes more advanced. The concern is that AI agents with such extensive permissions could pose significant cybersecurity risks.
Gemini’s proposed permissions would allow it to communicate with other installed applications like Mail, Safari, and Messages, and even send and receive network data without user approval for each connection. This could significantly enhance Gemini’s ability to perform complex tasks but also increase the allure for potential attackers.
Balancing Functionality and Security
While the enhanced permissions could make Gemini more versatile in tasks like researching, organizing, and interacting with enterprise tools, they also introduce privacy concerns. A malicious entity could exploit the AI agent’s permissions to access sensitive files, open authenticated services, or extract data.
Although Google plans to maintain additional confirmation steps for sensitive actions, the potential for misuse remains. Users might still face risks from malicious web pages, compromised browser sessions, and untrusted applications. Google’s tiered permission approach aims to differentiate routine tasks from high-risk actions.
Future Outlook and Recommendations
The full-access option is currently not public, and Google has yet to make an official announcement. Speculation suggests that these capabilities might be linked to a future Gemini 4 experience, but this remains unverified.
Organizations should approach these AI-agent permissions with caution. Security teams are advised to limit access to sensitive data, enforce least-privilege controls, and monitor AI assistant interactions closely. This cautious approach will be crucial once these enhanced capabilities become available.
